AIS Test 2 - Chapter 11
According to COSO, which of the following components of the enterprise risk management
addresses an entity's integrity and ethical values? - ANS Internal environment.
In a computerized environment, internal controls can be categorized into which of the following?
- ANS General contrails and application controls.
Controls in the information technology area are classified into preventive, detective, and
corrective categories. Which of the following is preventive control? - ANS Access control
software.
Which of the following best describes what is meant by corporate governance? - ANS The
organizational structure and responsibilities of the executive team and board of directors of a
corporation.
Which of the following items is one of the eight components of COSO's enterprise risk
management framework? - ANS Monitoring
In the event identification component of the COSO ERM framework, management must classify
events into which of the following? - ANS Risks and rewards.
An entity's ongoing monitoring activities often include: - ANS Periodic audits by the audit
committee.
The overall attitude and awareness of a firm's top management and board of directors
concerning the importance of internal control is often reflected in its: - ANS Control
environment.
According to COSO, which of the following is not a component of internal control? - ANS
Control risk.
Obtaining an understanding of an internal control involves evaluating the design of the control
and determining whether the control has been: - ANS Implemented.
A customer intended to order 100 units of a product A, but incorrectly ordered nonexistent
product B. Which of the following controls most likely would detect this error? - ANS Validity
check.
The ISO 27000 Series of standards are designed to address which of the following? - ANS
Information security issues.
According to COSO, which of the following components of the enterprise risk management
addresses an entity's integrity and ethical values? - ANS Internal environment.
In a computerized environment, internal controls can be categorized into which of the following?
- ANS General contrails and application controls.
Controls in the information technology area are classified into preventive, detective, and
corrective categories. Which of the following is preventive control? - ANS Access control
software.
Which of the following best describes what is meant by corporate governance? - ANS The
organizational structure and responsibilities of the executive team and board of directors of a
corporation.
Which of the following items is one of the eight components of COSO's enterprise risk
management framework? - ANS Monitoring
In the event identification component of the COSO ERM framework, management must classify
events into which of the following? - ANS Risks and rewards.
An entity's ongoing monitoring activities often include: - ANS Periodic audits by the audit
committee.
The overall attitude and awareness of a firm's top management and board of directors
concerning the importance of internal control is often reflected in its: - ANS Control
environment.
According to COSO, which of the following is not a component of internal control? - ANS
Control risk.
Obtaining an understanding of an internal control involves evaluating the design of the control
and determining whether the control has been: - ANS Implemented.
A customer intended to order 100 units of a product A, but incorrectly ordered nonexistent
product B. Which of the following controls most likely would detect this error? - ANS Validity
check.
The ISO 27000 Series of standards are designed to address which of the following? - ANS
Information security issues.