The Ultimate WGU D561 Objective
Assessment Prep: Information
Systems for Accounting & Control
Questions With Correct Answers
[Graded A+]
Q1: Which COSO component establishes the organization's ethical values and
"tone at the top"?
• A) Risk Assessment
• B) Control Activities
• C) Control Environment ✓
• D) Monitoring Activities
Q2: What are the five components of the COSO Internal Control Framework?
• A) Planning, Organizing, Staffing, Directing, Controlling
• B) Control Environment, Risk Assessment, Control Activities, Information
& Communication, Monitoring ✓
• C) Preventive, Detective, Corrective, Compensating, Monitoring
• D) Authorization, Recording, Custody, Reconciliation, Review
Q3: A company implements mandatory ethics training for all employees. This is
an example of which COSO component?
• A) Risk Assessment
• B) Control Environment ✓
• C) Control Activities
• D) Monitoring
Q4: Management identifies that a new competitor entering the market could
impact sales. This is an example of which COSO component?
• A) Risk Assessment ✓
• B) Control Environment
• C) Information & Communication
• D) Monitoring
,Q5: Approvals required for all purchases over $5,000 is an example of which
COSO component?
• A) Risk Assessment
• B) Control Environment
• C) Control Activities ✓
• D) Monitoring
Q6: A company's internal audit department conducts quarterly reviews of the
purchasing process. This is which COSO component?
• A) Risk Assessment
• B) Control Activities
• C) Information & Communication
• D) Monitoring ✓
Q7: Which COSO component ensures that relevant information is identified,
captured, and communicated in a timely manner?
• A) Risk Assessment
• B) Control Environment
• C) Information & Communication ✓
• D) Monitoring
Q8: A company requires that no single employee can both authorize a purchase
and approve payment. This control addresses which COSO component?
• A) Risk Assessment
• B) Control Environment
• C) Control Activities ✓
• D) Monitoring
Q9: Which is NOT a component of the COSO framework?
• A) Control Environment
• B) Risk Assessment
• C) Financial Reporting ✓
• D) Monitoring
Q10: The COSO framework defines internal control as a process designed to
provide:
• A) Absolute assurance of achieving objectives
• B) Reasonable assurance of achieving objectives ✓
• C) Guaranteed prevention of all fraud
• D) Complete elimination of all risks
,Q11: Management philosophy and operating style are part of which COSO
component?
• A) Control Environment ✓
• B) Risk Assessment
• C) Control Activities
• D) Monitoring
Q12: A whistleblower hotline is primarily associated with which COSO
component?
• A) Risk Assessment
• B) Information & Communication ✓
• C) Control Activities
• D) Monitoring
Q13: Periodic performance reviews and exception reporting are examples of
which COSO component?
• A) Risk Assessment
• B) Control Environment
• C) Control Activities
• D) Monitoring ✓
Q14: The board of directors' independence from management is part of which
COSO component?
• A) Control Environment ✓
• B) Risk Assessment
• C) Information & Communication
• D) Monitoring
Q15: Which COSO component involves establishing policies and procedures to
mitigate identified risks?
• A) Risk Assessment
• B) Control Activities ✓
• C) Information & Communication
• D) Monitoring
Control Types (Preventive, Detective, Corrective)
, Q16: Requiring dual signatures on checks is what type of control?
• A) Preventive ✓
• B) Detective
• C) Corrective
• D) Compensating
Q17: A bank reconciliation is classified as which type of control?
• A) Preventive
• B) Detective ✓
• C) Corrective
• D) Directive
Q18: Restoring data from a backup after a system failure is what type of
control?
• A) Preventive
• B) Detective
• C) Corrective ✓
• D) Monitoring
Q19: Requiring user IDs and passwords for system access is a:
• A) Preventive control ✓
• B) Detective control
• C) Corrective control
• D) Monitoring control
Q20: Reviewing system access logs for unauthorized activity is a:
• A) Preventive
• B) Detective ✓
• C) Corrective
• D) Directive
Q21: An automated backup system that allows recovery of lost data is a:
• A) Preventive
• B) Detective
• C) Corrective ✓
• D) Monitoring
Q22: Segregation of duties is primarily which type of control?
• A) Preventive ✓
Assessment Prep: Information
Systems for Accounting & Control
Questions With Correct Answers
[Graded A+]
Q1: Which COSO component establishes the organization's ethical values and
"tone at the top"?
• A) Risk Assessment
• B) Control Activities
• C) Control Environment ✓
• D) Monitoring Activities
Q2: What are the five components of the COSO Internal Control Framework?
• A) Planning, Organizing, Staffing, Directing, Controlling
• B) Control Environment, Risk Assessment, Control Activities, Information
& Communication, Monitoring ✓
• C) Preventive, Detective, Corrective, Compensating, Monitoring
• D) Authorization, Recording, Custody, Reconciliation, Review
Q3: A company implements mandatory ethics training for all employees. This is
an example of which COSO component?
• A) Risk Assessment
• B) Control Environment ✓
• C) Control Activities
• D) Monitoring
Q4: Management identifies that a new competitor entering the market could
impact sales. This is an example of which COSO component?
• A) Risk Assessment ✓
• B) Control Environment
• C) Information & Communication
• D) Monitoring
,Q5: Approvals required for all purchases over $5,000 is an example of which
COSO component?
• A) Risk Assessment
• B) Control Environment
• C) Control Activities ✓
• D) Monitoring
Q6: A company's internal audit department conducts quarterly reviews of the
purchasing process. This is which COSO component?
• A) Risk Assessment
• B) Control Activities
• C) Information & Communication
• D) Monitoring ✓
Q7: Which COSO component ensures that relevant information is identified,
captured, and communicated in a timely manner?
• A) Risk Assessment
• B) Control Environment
• C) Information & Communication ✓
• D) Monitoring
Q8: A company requires that no single employee can both authorize a purchase
and approve payment. This control addresses which COSO component?
• A) Risk Assessment
• B) Control Environment
• C) Control Activities ✓
• D) Monitoring
Q9: Which is NOT a component of the COSO framework?
• A) Control Environment
• B) Risk Assessment
• C) Financial Reporting ✓
• D) Monitoring
Q10: The COSO framework defines internal control as a process designed to
provide:
• A) Absolute assurance of achieving objectives
• B) Reasonable assurance of achieving objectives ✓
• C) Guaranteed prevention of all fraud
• D) Complete elimination of all risks
,Q11: Management philosophy and operating style are part of which COSO
component?
• A) Control Environment ✓
• B) Risk Assessment
• C) Control Activities
• D) Monitoring
Q12: A whistleblower hotline is primarily associated with which COSO
component?
• A) Risk Assessment
• B) Information & Communication ✓
• C) Control Activities
• D) Monitoring
Q13: Periodic performance reviews and exception reporting are examples of
which COSO component?
• A) Risk Assessment
• B) Control Environment
• C) Control Activities
• D) Monitoring ✓
Q14: The board of directors' independence from management is part of which
COSO component?
• A) Control Environment ✓
• B) Risk Assessment
• C) Information & Communication
• D) Monitoring
Q15: Which COSO component involves establishing policies and procedures to
mitigate identified risks?
• A) Risk Assessment
• B) Control Activities ✓
• C) Information & Communication
• D) Monitoring
Control Types (Preventive, Detective, Corrective)
, Q16: Requiring dual signatures on checks is what type of control?
• A) Preventive ✓
• B) Detective
• C) Corrective
• D) Compensating
Q17: A bank reconciliation is classified as which type of control?
• A) Preventive
• B) Detective ✓
• C) Corrective
• D) Directive
Q18: Restoring data from a backup after a system failure is what type of
control?
• A) Preventive
• B) Detective
• C) Corrective ✓
• D) Monitoring
Q19: Requiring user IDs and passwords for system access is a:
• A) Preventive control ✓
• B) Detective control
• C) Corrective control
• D) Monitoring control
Q20: Reviewing system access logs for unauthorized activity is a:
• A) Preventive
• B) Detective ✓
• C) Corrective
• D) Directive
Q21: An automated backup system that allows recovery of lost data is a:
• A) Preventive
• B) Detective
• C) Corrective ✓
• D) Monitoring
Q22: Segregation of duties is primarily which type of control?
• A) Preventive ✓