ARM 400 COMPREHENSIVE QUESTIONS AND
ANSWERS SET A+
✔✔Management controls - ✔✔A system of specified standards or objectives against
which an organizations management measures performance (coordinate resource
allocation, motivate performance, and measure outcomes.)
✔✔Preventive Controls - ✔✔Controls designed to prevent errors or inconsistencies.
✔✔Detective Controls - ✔✔Controls designed to detect errors or inconsistencies after
they have occurred
✔✔Organizational objectives are supported by internal controls by - ✔✔safeguarding
and protecting assets, ensuring legal and regulatory compliance, improving internal/
external reporting reliability and preserving shareholders interest
✔✔Transactional objectives are supported by internal controls by - ✔✔Promoting
operational efficiency and effectiveness, ensuring adherence to policies and
procedures, guaranteeing accurate record keeping
✔✔Examples of preventive controls - ✔✔approval and authorizations, segregation of
duties
✔✔Examples of Detective Controls - ✔✔Reconciliations (compares different sets of
data, investigating any differences and taking corrective action as warranted ex.
reviewing financial reports with receipts)
✔✔5 Coso Internal Controls (aka Coso Cube) - ✔✔Control Environment, Risk
assessment, control activities, Information/communication & Monitoring activities
✔✔Objectives addressed by Coso Cude - ✔✔Operation, Reporting & Compliance
, ✔✔ISO 9000 - ✔✔focuses on quality management including assurances regarding
regulatory compliance
✔✔ISO 9001 - ✔✔framework for organizations that purchase large amounts of
materials for us in manufacturing. Includes steps of the process, material inspections
and corrective actions if necessary
✔✔Auditing Standards No. 5 (AS 5) - ✔✔A standard issued by the Public Company
Accounting Oversight Board (PCAOB) that applies when an auditor is engaged to audit
managements assessment of the effectiveness of internal control over financial
reporting
✔✔ISO/IEC (International Electrotechnical Commission) 27000 - ✔✔Focuses on
information security management standards. Sets standards to evaluate risk and
implement controls that protect information risks such as IP or financial records
✔✔Institute for Internal Auditors (IIA) Standards - ✔✔Standards to ensures auditors
responsibilities are met
✔✔Attributes Standards - ✔✔A standard defining the attributes of organizations and
individuals performing internal auditing
✔✔Performance Standard - ✔✔A standard defining the nature of internal auditing and
providing quality criteria against which the performance of these services can be
measured
✔✔Risk Based Auditing - ✔✔auditing that prioritizes the use of an organizations limited
internal audit resources in the areas that pose the greatest risk to an organization
✔✔Entity- Level Controls - ✔✔The second level of a top-down review of internal
controls that helps ensure that management directives relative to the entire entity are in
place and are being carried out
✔✔5 components of Internal Control - ✔✔Control environment, risk assessment, control
activities, information & communication, monitoring activates
✔✔AS 5 Objectives - ✔✔Focus internal control audits on the most important matters,
eliminate unnecessary audit procedures, match the audit scope to the size and risk
model of the enterprise, & offer simplified implementation guidance from prior standards
✔✔Risk based auditing - ✔✔Auditing that prioritizes the use of an organizations limited
internal audit resources in the areas that pose the greatest risk to the organization
ANSWERS SET A+
✔✔Management controls - ✔✔A system of specified standards or objectives against
which an organizations management measures performance (coordinate resource
allocation, motivate performance, and measure outcomes.)
✔✔Preventive Controls - ✔✔Controls designed to prevent errors or inconsistencies.
✔✔Detective Controls - ✔✔Controls designed to detect errors or inconsistencies after
they have occurred
✔✔Organizational objectives are supported by internal controls by - ✔✔safeguarding
and protecting assets, ensuring legal and regulatory compliance, improving internal/
external reporting reliability and preserving shareholders interest
✔✔Transactional objectives are supported by internal controls by - ✔✔Promoting
operational efficiency and effectiveness, ensuring adherence to policies and
procedures, guaranteeing accurate record keeping
✔✔Examples of preventive controls - ✔✔approval and authorizations, segregation of
duties
✔✔Examples of Detective Controls - ✔✔Reconciliations (compares different sets of
data, investigating any differences and taking corrective action as warranted ex.
reviewing financial reports with receipts)
✔✔5 Coso Internal Controls (aka Coso Cube) - ✔✔Control Environment, Risk
assessment, control activities, Information/communication & Monitoring activities
✔✔Objectives addressed by Coso Cude - ✔✔Operation, Reporting & Compliance
, ✔✔ISO 9000 - ✔✔focuses on quality management including assurances regarding
regulatory compliance
✔✔ISO 9001 - ✔✔framework for organizations that purchase large amounts of
materials for us in manufacturing. Includes steps of the process, material inspections
and corrective actions if necessary
✔✔Auditing Standards No. 5 (AS 5) - ✔✔A standard issued by the Public Company
Accounting Oversight Board (PCAOB) that applies when an auditor is engaged to audit
managements assessment of the effectiveness of internal control over financial
reporting
✔✔ISO/IEC (International Electrotechnical Commission) 27000 - ✔✔Focuses on
information security management standards. Sets standards to evaluate risk and
implement controls that protect information risks such as IP or financial records
✔✔Institute for Internal Auditors (IIA) Standards - ✔✔Standards to ensures auditors
responsibilities are met
✔✔Attributes Standards - ✔✔A standard defining the attributes of organizations and
individuals performing internal auditing
✔✔Performance Standard - ✔✔A standard defining the nature of internal auditing and
providing quality criteria against which the performance of these services can be
measured
✔✔Risk Based Auditing - ✔✔auditing that prioritizes the use of an organizations limited
internal audit resources in the areas that pose the greatest risk to an organization
✔✔Entity- Level Controls - ✔✔The second level of a top-down review of internal
controls that helps ensure that management directives relative to the entire entity are in
place and are being carried out
✔✔5 components of Internal Control - ✔✔Control environment, risk assessment, control
activities, information & communication, monitoring activates
✔✔AS 5 Objectives - ✔✔Focus internal control audits on the most important matters,
eliminate unnecessary audit procedures, match the audit scope to the size and risk
model of the enterprise, & offer simplified implementation guidance from prior standards
✔✔Risk based auditing - ✔✔Auditing that prioritizes the use of an organizations limited
internal audit resources in the areas that pose the greatest risk to the organization