, IT Auditing 4th Ed—Test Bank, Chapter 1
sd sd sd sd sd sd
Chapter 1—Auditing and Internal Control
sd sd sd sd
TRUE/FALSE
1. Corporate management (including the CEO) must certify monthly and annually their organization‟s
sd sd sd sd sd sd sd sd sd sd sd
internal controls over financial reporting.
sd sd sd sd sd
ANS: s d F PTS: s d s d 1
2. Both the SEC and the PCAOB require management to use the COBIT framework for assessing
sd sd sd sd sd sd sd sd sd sd sd sd sd sd
internal control adequacy.
sd sd sd
ANS: s d F PTS: s d s d 1
3. Both the SEC and the PCAOB require management to use the COSO framework for assessing
sd sd sd sd sd sd sd sd sd sd sd sd sd sd
internal control adequacy.
sd sd sd
ANS: s d F PTS: s d s d 1
4. A qualified opinion on management‟s assessment of internal controls over the financial reporting system
sd sd sd sd sd sd sd sd sd sd sd sd sd
necessitates a qualified opinion on the financial statements?
sd sd sd sd sd sd sd sd
ANS: s d F PTS: s d s d 1
5. The same internal control objectives apply to manual and computer-based information systems.
sd sd sd sd sd sd sd sd sd sd sd
ANS: s d T PTS: s d s d 1
6. The external auditor is responsible for establishing and maintaining the internal control system.
sd sd sd sd sd sd sd sd sd sd sd sd
ANS: s d F PTS: s d s d 1
7. Segregation of duties is an example of an internal control procedure.
sd sd sd sd sd sd sd sd sd sd
ANS: s d T PTS: s d s d 1
8. Preventive controls are passive techniques designed to reduce fraud.
sd sd sd sd sd sd sd sd
ANS: s d T PTS: s d s d 1
9. A key modifying assumption in internal control is that the internal control system is the responsibility
s d sd sd sd sd sd sd sd sd sd sd sd sd sd sd
of management.
sd sd
ANS: s d T PTS: s d s d 1
© sd2016 sdCengage sdLearning®. s d May sdnot sdbe sdscanned, sdcopied sdor sdduplicated sdor sdposted sdto sda sdpublicly sdaccessible sdwebsite, sdin sdwhole sdor sdin sdpart, sdexcept sdfor sduse
sdas sdpermitted sdin sda s d license sddistributed sdwith sda sdcertain sdproduct sdor sdservice sdor sdotherwise sdon sda sdpassword-protected sdwebsite sdor sdschool-approved sdlearning
management system for classroom use.
, IT Auditing 4th Ed—Test Bank, Chapter 1
sd sd sd sd sd sd
10. While the Sarbanes-Oxley Act prohibits auditors from providing non-accounting services to their audit
sd sd sd sd sd sd sd sd sd sd sd sd
clients, they are not prohibited from performing such services for non-audit clients or privately held
sd sd sd sd sd sd sd sd sd sd sd sd sd sd sd
companies.
sd
ANS: s d T PTS: s d s d 1
11. The Sarbanes-Oxley Act requires the audit committee to hire and oversee the external auditors.
sd sd sd sd sd sd sd sd sd sd sd sd sd
ANS: s d T PTS: s d s d 1
12. Section 404 requires that corporate management (including the CEO) certify their organization‟s internal
sd sd sd sd sd sd sd sd sd sd sd sd
controls on a quarterly and annual basis.
sd sd sd sd sd sd sd
ANS: s d F PTS: s d s d 1
13. Section 302 requires the management of public companies to assess and formally report on
sd sd sd sd sd sd sd sd sd sd sd sd sd
the effectiveness of their organization‟s internal controls.
sd sd sd sd sd sd sd
ANS: s d F PTS: s d s d 1
14. Application controls apply to a wide range of exposures that threaten the integrity of all
sd sd sd sd sd sd sd sd sd sd sd sd sd sd
programs processed within the computer environment.
sd sd sd sd sd sd
ANS: s d F PTS: s d s d 1
15. Advisory services is an emerging field that goes beyond the auditor‟s traditional attestation function.
sd sd sd sd sd sd sd sd sd sd sd sd sd
ANS: s d T PTS: s d s d 1
16. An IT auditor expresses an opinion on the fairness of the financial statements.
sd sd sd sd sd sd sd sd sd sd sd sd
ANS: s d F PTS: s d s d 1
17. External auditing is an independent appraisal function established within an organization to examine
sd sd sd sd sd sd sd sd sd sd sd sd
and evaluate its activities as a service to the organization.
sd sd sd sd sd sd sd sd sd sd
ANS: s d F PTS: s d s d 1
18. External auditors can cooperate with and use evidence gathered by internal audit departments that
sd sd sd sd sd sd sd sd sd sd sd sd sd
are organizationally independent and that report to the Audit Committee of the Board of Directors.
sd sd sd sd sd sd sd sd sd sd sd sd sd sd sd
© sd2016 sdCengage sdLearning®. s d May sdnot sdbe sdscanned, sdcopied sdor sdduplicated sdor sdposted sdto sda sdpublicly sdaccessible sdwebsite, sdin sdwhole sdor sdin sdpart, sdexcept sdfor sduse
sdas sdpermitted sdin sda s d license sddistributed sdwith sda sdcertain sdproduct sdor sdservice sdor sdotherwise sdon sda sdpassword-protected sdwebsite sdor sdschool-approved sdlearning
management system for classroom use.
, IT Auditing 4th Ed—Test Bank, Chapter 1
sd sd sd sd sd sd
ANS: s d T PTS: s d s d 1
19. Tests of controls determine whether the database contents fairly reflect the organization's transactions.
sd sd sd sd sd sd sd sd sd sd sd sd
ANS: s d F PTS: s d s d 1
20. Audit risk is the probability that the auditor will render an unqualified opinion on financial statements
sd sd sd sd sd sd sd sd sd sd sd sd sd sd sd
that are materially misstated.
sd sd sd sd
ANS: s d T PTS: s d s d 1
21. A strong internal control system will reduce the amount of substantive testing that must be performed.
sd sd sd sd sd sd sd sd sd sd sd sd sd sd sd
ANS: s d T PTS: s d s d 1
22. Substantive testing techniques provide information about the accuracy and completeness of
sd sd sd sd sd sd sd sd sd sd
an application's processes.
sd sd sd
ANS: s d F PTS: s d s d 1
MULTIPLE CHOICE sd
1. The concept of reasonable assurance suggests that
sd sd sd sd sd sd
a. the cost of an internal control should be less than the benefit it provides
sd sd sd sd sd sd sd sd sd sd sd sd sd
b. a well-designed system of internal controls will detect all fraudulent activity
sd sd sd sd sd sd sd sd sd sd
c. the objectives achieved by an internal control system vary depending on the data
sd sd sd sd sd sd sd sd sd sd sd sd
processing method
sd sd
d. the effectiveness of internal controls is a function of the industry environment
sd sd sd sd sd sd sd sd sd sd sd
sd ANS: A s d PTS: s d 1
2. Which of the following is not a limitation of the internal control system?
sd sd sd sd sd sd sd sd sd sd sd sd
a. errors are made due to employee fatigue sd sd sd sd sd sd
b. fraud occurs because of collusion between two employees
sd sd sd sd sd sd sd
c. the industry is inherently risky sd sd sd sd
d. management instructs the bookkeeper to make fraudulent journal entries sd sd sd sd sd sd sd sd
sd ANS: C s d PTS: s d 1
3. The most cost-effective type of internal control is
sd sd sd sd sd sd sd
a. preventive control sd
b. accounting control sd
© sd2016 sdCengage sdLearning®. s d May sdnot sdbe sdscanned, sdcopied sdor sdduplicated sdor sdposted sdto sda sdpublicly sdaccessible sdwebsite, sdin sdwhole sdor sdin sdpart, sdexcept sdfor sduse
sdas sdpermitted sdin sda s d license sddistributed sdwith sda sdcertain sdproduct sdor sdservice sdor sdotherwise sdon sda sdpassword-protected sdwebsite sdor sdschool-approved sdlearning
management system for classroom use.
sd sd sd sd sd sd
Chapter 1—Auditing and Internal Control
sd sd sd sd
TRUE/FALSE
1. Corporate management (including the CEO) must certify monthly and annually their organization‟s
sd sd sd sd sd sd sd sd sd sd sd
internal controls over financial reporting.
sd sd sd sd sd
ANS: s d F PTS: s d s d 1
2. Both the SEC and the PCAOB require management to use the COBIT framework for assessing
sd sd sd sd sd sd sd sd sd sd sd sd sd sd
internal control adequacy.
sd sd sd
ANS: s d F PTS: s d s d 1
3. Both the SEC and the PCAOB require management to use the COSO framework for assessing
sd sd sd sd sd sd sd sd sd sd sd sd sd sd
internal control adequacy.
sd sd sd
ANS: s d F PTS: s d s d 1
4. A qualified opinion on management‟s assessment of internal controls over the financial reporting system
sd sd sd sd sd sd sd sd sd sd sd sd sd
necessitates a qualified opinion on the financial statements?
sd sd sd sd sd sd sd sd
ANS: s d F PTS: s d s d 1
5. The same internal control objectives apply to manual and computer-based information systems.
sd sd sd sd sd sd sd sd sd sd sd
ANS: s d T PTS: s d s d 1
6. The external auditor is responsible for establishing and maintaining the internal control system.
sd sd sd sd sd sd sd sd sd sd sd sd
ANS: s d F PTS: s d s d 1
7. Segregation of duties is an example of an internal control procedure.
sd sd sd sd sd sd sd sd sd sd
ANS: s d T PTS: s d s d 1
8. Preventive controls are passive techniques designed to reduce fraud.
sd sd sd sd sd sd sd sd
ANS: s d T PTS: s d s d 1
9. A key modifying assumption in internal control is that the internal control system is the responsibility
s d sd sd sd sd sd sd sd sd sd sd sd sd sd sd
of management.
sd sd
ANS: s d T PTS: s d s d 1
© sd2016 sdCengage sdLearning®. s d May sdnot sdbe sdscanned, sdcopied sdor sdduplicated sdor sdposted sdto sda sdpublicly sdaccessible sdwebsite, sdin sdwhole sdor sdin sdpart, sdexcept sdfor sduse
sdas sdpermitted sdin sda s d license sddistributed sdwith sda sdcertain sdproduct sdor sdservice sdor sdotherwise sdon sda sdpassword-protected sdwebsite sdor sdschool-approved sdlearning
management system for classroom use.
, IT Auditing 4th Ed—Test Bank, Chapter 1
sd sd sd sd sd sd
10. While the Sarbanes-Oxley Act prohibits auditors from providing non-accounting services to their audit
sd sd sd sd sd sd sd sd sd sd sd sd
clients, they are not prohibited from performing such services for non-audit clients or privately held
sd sd sd sd sd sd sd sd sd sd sd sd sd sd sd
companies.
sd
ANS: s d T PTS: s d s d 1
11. The Sarbanes-Oxley Act requires the audit committee to hire and oversee the external auditors.
sd sd sd sd sd sd sd sd sd sd sd sd sd
ANS: s d T PTS: s d s d 1
12. Section 404 requires that corporate management (including the CEO) certify their organization‟s internal
sd sd sd sd sd sd sd sd sd sd sd sd
controls on a quarterly and annual basis.
sd sd sd sd sd sd sd
ANS: s d F PTS: s d s d 1
13. Section 302 requires the management of public companies to assess and formally report on
sd sd sd sd sd sd sd sd sd sd sd sd sd
the effectiveness of their organization‟s internal controls.
sd sd sd sd sd sd sd
ANS: s d F PTS: s d s d 1
14. Application controls apply to a wide range of exposures that threaten the integrity of all
sd sd sd sd sd sd sd sd sd sd sd sd sd sd
programs processed within the computer environment.
sd sd sd sd sd sd
ANS: s d F PTS: s d s d 1
15. Advisory services is an emerging field that goes beyond the auditor‟s traditional attestation function.
sd sd sd sd sd sd sd sd sd sd sd sd sd
ANS: s d T PTS: s d s d 1
16. An IT auditor expresses an opinion on the fairness of the financial statements.
sd sd sd sd sd sd sd sd sd sd sd sd
ANS: s d F PTS: s d s d 1
17. External auditing is an independent appraisal function established within an organization to examine
sd sd sd sd sd sd sd sd sd sd sd sd
and evaluate its activities as a service to the organization.
sd sd sd sd sd sd sd sd sd sd
ANS: s d F PTS: s d s d 1
18. External auditors can cooperate with and use evidence gathered by internal audit departments that
sd sd sd sd sd sd sd sd sd sd sd sd sd
are organizationally independent and that report to the Audit Committee of the Board of Directors.
sd sd sd sd sd sd sd sd sd sd sd sd sd sd sd
© sd2016 sdCengage sdLearning®. s d May sdnot sdbe sdscanned, sdcopied sdor sdduplicated sdor sdposted sdto sda sdpublicly sdaccessible sdwebsite, sdin sdwhole sdor sdin sdpart, sdexcept sdfor sduse
sdas sdpermitted sdin sda s d license sddistributed sdwith sda sdcertain sdproduct sdor sdservice sdor sdotherwise sdon sda sdpassword-protected sdwebsite sdor sdschool-approved sdlearning
management system for classroom use.
, IT Auditing 4th Ed—Test Bank, Chapter 1
sd sd sd sd sd sd
ANS: s d T PTS: s d s d 1
19. Tests of controls determine whether the database contents fairly reflect the organization's transactions.
sd sd sd sd sd sd sd sd sd sd sd sd
ANS: s d F PTS: s d s d 1
20. Audit risk is the probability that the auditor will render an unqualified opinion on financial statements
sd sd sd sd sd sd sd sd sd sd sd sd sd sd sd
that are materially misstated.
sd sd sd sd
ANS: s d T PTS: s d s d 1
21. A strong internal control system will reduce the amount of substantive testing that must be performed.
sd sd sd sd sd sd sd sd sd sd sd sd sd sd sd
ANS: s d T PTS: s d s d 1
22. Substantive testing techniques provide information about the accuracy and completeness of
sd sd sd sd sd sd sd sd sd sd
an application's processes.
sd sd sd
ANS: s d F PTS: s d s d 1
MULTIPLE CHOICE sd
1. The concept of reasonable assurance suggests that
sd sd sd sd sd sd
a. the cost of an internal control should be less than the benefit it provides
sd sd sd sd sd sd sd sd sd sd sd sd sd
b. a well-designed system of internal controls will detect all fraudulent activity
sd sd sd sd sd sd sd sd sd sd
c. the objectives achieved by an internal control system vary depending on the data
sd sd sd sd sd sd sd sd sd sd sd sd
processing method
sd sd
d. the effectiveness of internal controls is a function of the industry environment
sd sd sd sd sd sd sd sd sd sd sd
sd ANS: A s d PTS: s d 1
2. Which of the following is not a limitation of the internal control system?
sd sd sd sd sd sd sd sd sd sd sd sd
a. errors are made due to employee fatigue sd sd sd sd sd sd
b. fraud occurs because of collusion between two employees
sd sd sd sd sd sd sd
c. the industry is inherently risky sd sd sd sd
d. management instructs the bookkeeper to make fraudulent journal entries sd sd sd sd sd sd sd sd
sd ANS: C s d PTS: s d 1
3. The most cost-effective type of internal control is
sd sd sd sd sd sd sd
a. preventive control sd
b. accounting control sd
© sd2016 sdCengage sdLearning®. s d May sdnot sdbe sdscanned, sdcopied sdor sdduplicated sdor sdposted sdto sda sdpublicly sdaccessible sdwebsite, sdin sdwhole sdor sdin sdpart, sdexcept sdfor sduse
sdas sdpermitted sdin sda s d license sddistributed sdwith sda sdcertain sdproduct sdor sdservice sdor sdotherwise sdon sda sdpassword-protected sdwebsite sdor sdschool-approved sdlearning
management system for classroom use.