WGU D217 REVIEW TIPS QUESTIONS AND ANSWERS
SURE A+
✔✔The growth of commercial software development is driven in part by - ✔✔Four
factors have contributed to the growth of the commercial software market: (1) the
relatively low cost of general commercial software as compared to customized software;
(2) the emergence of industry-specific vendors who target their software to the needs of
particular types of businesses; (3) a growing demand from businesses that are too small
to afford in-house systems' development staff; and (4) the trend toward downsizing
organizational units and the move toward distributed data processing has made the
commercial software option appealing to larger organizations.
✔✔Which ethical principle states that the benefit from a decision must outweigh the
risks, and that there is no alternative decision that provides the same or greater benefit
with less risk? - ✔✔The ethical principle that states the benefit from a decision must
outweigh the risks is proportionality. Proportionality in the business context is similar to
the view first posited by the Utilitarians that an ethical act is one that brings the greatest
benefit to the most people.
✔✔Individuals who acquire some level of skill and knowledge in the field of computer
ethics are involved in which level of computer ethics? - ✔✔Individuals who acquire
some level of skill in the field of computer ethics are involved in para computer ethics. A
researcher has defined three levels of computer ethics: Para, pop, and theoretical para
computer ethics involves taking a real interest in computer ethics cases and acquiring
some level of skill and knowledge in the field. All systems professionals need to reach
this level of competency so they can do their jobs effectively.
✔✔Which of the following is a part of the COSO framework? - ✔✔Segregation of duties
is a key part of the COSO framework. Segregation of duties can take many forms,
depending on the specific duties to be controlled. Examples include: The authorization
for a transaction is separate from the processing of the transaction; responsibility for the
custody of assets should be separate from the record-keeping responsibility; and the
, organization should be structured so that a successful fraud requires collusion between
two or more individuals with incompatible responsibilities.
✔✔A sequential file backup technique is called - ✔✔A sequential file backup technique
is called grandfather-father-son. One of the most common ways of controlling backups
is to employ a three-copy system known as grandfather-father-son. When a new backup
copy is made, it becomes the son, the son (now second most recent) becomes the
father, the father (now the third most recent) becomes the grandfather and the
grandfather (the oldest retained copy) will be returned to the data center for reuse.
✔✔An accounting system that maintains an adequate audit trail is implementing which
internal control procedure? - ✔✔Adequate audit trails use accounting records as an
internal control procedure. The accounting records of an organization consist of source
documents, journals, and ledgers. These records capture the economic essence of
transactions and provide an audit trail of economic events. The audit trail enables the
auditor to trace any transaction through all phases of its processing from the initiation of
the event to the financial statements.
✔✔Tests of controls include - ✔✔Tests of controls include completing questionnaires.
The Sarbanes-Oxley Act requires that management certify that the financial statements
are correct. In order to ensure that the financial statements are, in fact correct,
accounting processes and information systems will be built with checks, balances and
controls. Auditors will use questionnaires to guide their approach to testing the controls
in the system. Questions include topics such as "Is fraud awareness training carried
out?" and "Do particularly critical or sensitive activities require two levels of authority?"
✔✔Control risk is - ✔✔Control risk is the likelihood that the control structure is flawed
because controls are either absent or inadequate to prevent or detect errors in the
accounts. Auditors assess the level of control risk by performing tests of internal
controls. An auditor could create test transactions, including some with incorrect total
values, which are processed by the application in a test run. The results of the test will
indicate that price extension errors are not detected and are being incorrectly posted to
the AR file.
✔✔Which is the most critical segregation of duties in the centralized IT function? -
✔✔The most critical segregation of duties in the centralized IT function is systems
development and computer operations. Access to the data center must be very carefully
controlled to comply with SOX. This includes both physical and electronic access. Once
the system is turned over to operations, developers lose their access to the live system.
Should an error occur, the developers will diagnose the error in their development copy
or in a test system. When the error is corrected, the update will be turned over to
operations for installation.
✔✔Segregation of duties in the computer-based information system includes -
✔✔Segregation of duties in the computer-based information system includes separating
SURE A+
✔✔The growth of commercial software development is driven in part by - ✔✔Four
factors have contributed to the growth of the commercial software market: (1) the
relatively low cost of general commercial software as compared to customized software;
(2) the emergence of industry-specific vendors who target their software to the needs of
particular types of businesses; (3) a growing demand from businesses that are too small
to afford in-house systems' development staff; and (4) the trend toward downsizing
organizational units and the move toward distributed data processing has made the
commercial software option appealing to larger organizations.
✔✔Which ethical principle states that the benefit from a decision must outweigh the
risks, and that there is no alternative decision that provides the same or greater benefit
with less risk? - ✔✔The ethical principle that states the benefit from a decision must
outweigh the risks is proportionality. Proportionality in the business context is similar to
the view first posited by the Utilitarians that an ethical act is one that brings the greatest
benefit to the most people.
✔✔Individuals who acquire some level of skill and knowledge in the field of computer
ethics are involved in which level of computer ethics? - ✔✔Individuals who acquire
some level of skill in the field of computer ethics are involved in para computer ethics. A
researcher has defined three levels of computer ethics: Para, pop, and theoretical para
computer ethics involves taking a real interest in computer ethics cases and acquiring
some level of skill and knowledge in the field. All systems professionals need to reach
this level of competency so they can do their jobs effectively.
✔✔Which of the following is a part of the COSO framework? - ✔✔Segregation of duties
is a key part of the COSO framework. Segregation of duties can take many forms,
depending on the specific duties to be controlled. Examples include: The authorization
for a transaction is separate from the processing of the transaction; responsibility for the
custody of assets should be separate from the record-keeping responsibility; and the
, organization should be structured so that a successful fraud requires collusion between
two or more individuals with incompatible responsibilities.
✔✔A sequential file backup technique is called - ✔✔A sequential file backup technique
is called grandfather-father-son. One of the most common ways of controlling backups
is to employ a three-copy system known as grandfather-father-son. When a new backup
copy is made, it becomes the son, the son (now second most recent) becomes the
father, the father (now the third most recent) becomes the grandfather and the
grandfather (the oldest retained copy) will be returned to the data center for reuse.
✔✔An accounting system that maintains an adequate audit trail is implementing which
internal control procedure? - ✔✔Adequate audit trails use accounting records as an
internal control procedure. The accounting records of an organization consist of source
documents, journals, and ledgers. These records capture the economic essence of
transactions and provide an audit trail of economic events. The audit trail enables the
auditor to trace any transaction through all phases of its processing from the initiation of
the event to the financial statements.
✔✔Tests of controls include - ✔✔Tests of controls include completing questionnaires.
The Sarbanes-Oxley Act requires that management certify that the financial statements
are correct. In order to ensure that the financial statements are, in fact correct,
accounting processes and information systems will be built with checks, balances and
controls. Auditors will use questionnaires to guide their approach to testing the controls
in the system. Questions include topics such as "Is fraud awareness training carried
out?" and "Do particularly critical or sensitive activities require two levels of authority?"
✔✔Control risk is - ✔✔Control risk is the likelihood that the control structure is flawed
because controls are either absent or inadequate to prevent or detect errors in the
accounts. Auditors assess the level of control risk by performing tests of internal
controls. An auditor could create test transactions, including some with incorrect total
values, which are processed by the application in a test run. The results of the test will
indicate that price extension errors are not detected and are being incorrectly posted to
the AR file.
✔✔Which is the most critical segregation of duties in the centralized IT function? -
✔✔The most critical segregation of duties in the centralized IT function is systems
development and computer operations. Access to the data center must be very carefully
controlled to comply with SOX. This includes both physical and electronic access. Once
the system is turned over to operations, developers lose their access to the live system.
Should an error occur, the developers will diagnose the error in their development copy
or in a test system. When the error is corrected, the update will be turned over to
operations for installation.
✔✔Segregation of duties in the computer-based information system includes -
✔✔Segregation of duties in the computer-based information system includes separating