CISA EXAMS SET FULL SOLUTION
QUESTIONS AND CORRECT ANSWERS
●● An audit charter should:
A.
be dynamic and change to coincide with the changing nature of
technology and the audit profession.
B.
clearly state audit objectives for, and the delegation of, authority to the
maintenance and review of internal controls.
C.
document the audit procedures designed to achieve the planned audit
objectives.
D.
outline the overall authority, scope and responsibilities of the audit
function.
Answer: A. The audit charter should not be subject to changes in
technology and should not significantly change over time. The charter
should be approved at the highest level of management.
,B. An audit charter will state the authority and reporting requirements
for the audit but not the details of maintenance of internal controls.
C. An audit charter would not be at a detailed level and, therefore, would
not include specific audit objectives or procedures.
CORRECT D. An audit charter should state management's objectives for
and delegation of authority to IS auditors.
●● The PRIMARY advantage of a continuous audit approach is that it:
Select an answer:
A.
does not require an IS auditor to collect evidence on system reliability
while processing is taking place.
B.
allows the IS auditor to review and follow up on audit issues in a timely
manner.
C.
places the responsibility for enforcement and monitoring of controls on
the security department instead of audit.
,D.
simplifies the extraction and correlation of data from multiple and
complex systems.
Answer: A. The continuous audit approach often does require an IS
auditor to collect evidence on system reliability while processing is
taking place.
CORRECT B. Continuous audit allows audit and response to audit
issues in a timely manner because audit findings are gathered in near
real time.
C. Responsibility for enforcement and monitoring of controls is
primarily the responsibility of management.
D. The use of continuous audit is not based on the complexity or number
of systems being monitored.
●● A PRIMARY benefit derived for an organization employing control
self-assessment (CSA) techniques is that it:
Select an answer:
A.
can identify high-risk areas that might need a detailed review later.
, B.
allows IS auditors to independently assess risk.
C.
can be used as a replacement for traditional audits.
D.
allows management to relinquish responsibility for control.
Answer: CORRECT A. Control self-assessment (CSA) is predicated on
the review of high-risk areas that either need immediate attention or may
require a more thorough review at a later date.
B. CSA requires the involvement of IS auditors and line management.
What occurs is that the internal audit function shifts some of the control
monitoring responsibilities to the functional areas.
C. CSA is not a replacement for traditional audits. CSA is not intended
to replace audit's responsibilities, but to enhance them.
D. CSA does not allow management to relinquish its responsibility for
control.
QUESTIONS AND CORRECT ANSWERS
●● An audit charter should:
A.
be dynamic and change to coincide with the changing nature of
technology and the audit profession.
B.
clearly state audit objectives for, and the delegation of, authority to the
maintenance and review of internal controls.
C.
document the audit procedures designed to achieve the planned audit
objectives.
D.
outline the overall authority, scope and responsibilities of the audit
function.
Answer: A. The audit charter should not be subject to changes in
technology and should not significantly change over time. The charter
should be approved at the highest level of management.
,B. An audit charter will state the authority and reporting requirements
for the audit but not the details of maintenance of internal controls.
C. An audit charter would not be at a detailed level and, therefore, would
not include specific audit objectives or procedures.
CORRECT D. An audit charter should state management's objectives for
and delegation of authority to IS auditors.
●● The PRIMARY advantage of a continuous audit approach is that it:
Select an answer:
A.
does not require an IS auditor to collect evidence on system reliability
while processing is taking place.
B.
allows the IS auditor to review and follow up on audit issues in a timely
manner.
C.
places the responsibility for enforcement and monitoring of controls on
the security department instead of audit.
,D.
simplifies the extraction and correlation of data from multiple and
complex systems.
Answer: A. The continuous audit approach often does require an IS
auditor to collect evidence on system reliability while processing is
taking place.
CORRECT B. Continuous audit allows audit and response to audit
issues in a timely manner because audit findings are gathered in near
real time.
C. Responsibility for enforcement and monitoring of controls is
primarily the responsibility of management.
D. The use of continuous audit is not based on the complexity or number
of systems being monitored.
●● A PRIMARY benefit derived for an organization employing control
self-assessment (CSA) techniques is that it:
Select an answer:
A.
can identify high-risk areas that might need a detailed review later.
, B.
allows IS auditors to independently assess risk.
C.
can be used as a replacement for traditional audits.
D.
allows management to relinquish responsibility for control.
Answer: CORRECT A. Control self-assessment (CSA) is predicated on
the review of high-risk areas that either need immediate attention or may
require a more thorough review at a later date.
B. CSA requires the involvement of IS auditors and line management.
What occurs is that the internal audit function shifts some of the control
monitoring responsibilities to the functional areas.
C. CSA is not a replacement for traditional audits. CSA is not intended
to replace audit's responsibilities, but to enhance them.
D. CSA does not allow management to relinquish its responsibility for
control.