Minnesota Uniform CPA Examination –
Discipline Section: Information Systems
and Controls Exam Practice Questions
And Correct Answers (Verified Answers)
Plus Rationales 2026 Q&A | Instant
Download Pdf
1. Which of the following is the primary objective of an information
system control?
A. Increase employee compensation
B. Reduce office space requirements
C. Ensure confidentiality, integrity, and availability of information
D. Eliminate all business risks
Answer: C
,Rationale: Information system controls are designed to protect
information assets by ensuring confidentiality, integrity, and availability
(CIA).
2. Which control is designed to prevent unauthorized access to a
system?
A. Backup procedures
B. Audit logs
C. User authentication controls
D. Exception reports
Answer: C
Rationale: Authentication controls verify user identities before granting
access to systems and data.
3. Segregation of duties is primarily intended to:
A. Increase employee productivity
B. Reduce software costs
C. Improve system speed
D. Reduce the risk of fraud and errors
Answer: D
,Rationale: Segregation of duties prevents one individual from controlling
all aspects of a transaction, reducing fraud opportunities.
4. Which of the following is an example of a preventive control?
A. Reconciliation report
B. Internal audit review
C. Error log analysis
D. Password requirements
Answer: D
Rationale: Password requirements help prevent unauthorized access
before an incident occurs.
5. A firewall is primarily used to:
A. Encrypt files
B. Back up data
C. Control network traffic entering and leaving a system
D. Create audit trails
Answer: C
Rationale: Firewalls monitor and control incoming and outgoing network
traffic based on security rules.
6. Which type of control detects errors after they occur?
, A. Preventive control
B. Directive control
C. Compensating control
D. Detective control
Answer: D
Rationale: Detective controls identify errors or irregularities after they
have occurred.
7. An audit trail is most useful for:
A. Preventing all errors
B. Tracing transactions from initiation to completion
C. Increasing processing speed
D. Eliminating the need for documentation
Answer: B
Rationale: Audit trails provide evidence allowing auditors to follow
transactions through the system.
8. Which of the following best describes encryption?
A. Data deletion process
B. Data backup process
Discipline Section: Information Systems
and Controls Exam Practice Questions
And Correct Answers (Verified Answers)
Plus Rationales 2026 Q&A | Instant
Download Pdf
1. Which of the following is the primary objective of an information
system control?
A. Increase employee compensation
B. Reduce office space requirements
C. Ensure confidentiality, integrity, and availability of information
D. Eliminate all business risks
Answer: C
,Rationale: Information system controls are designed to protect
information assets by ensuring confidentiality, integrity, and availability
(CIA).
2. Which control is designed to prevent unauthorized access to a
system?
A. Backup procedures
B. Audit logs
C. User authentication controls
D. Exception reports
Answer: C
Rationale: Authentication controls verify user identities before granting
access to systems and data.
3. Segregation of duties is primarily intended to:
A. Increase employee productivity
B. Reduce software costs
C. Improve system speed
D. Reduce the risk of fraud and errors
Answer: D
,Rationale: Segregation of duties prevents one individual from controlling
all aspects of a transaction, reducing fraud opportunities.
4. Which of the following is an example of a preventive control?
A. Reconciliation report
B. Internal audit review
C. Error log analysis
D. Password requirements
Answer: D
Rationale: Password requirements help prevent unauthorized access
before an incident occurs.
5. A firewall is primarily used to:
A. Encrypt files
B. Back up data
C. Control network traffic entering and leaving a system
D. Create audit trails
Answer: C
Rationale: Firewalls monitor and control incoming and outgoing network
traffic based on security rules.
6. Which type of control detects errors after they occur?
, A. Preventive control
B. Directive control
C. Compensating control
D. Detective control
Answer: D
Rationale: Detective controls identify errors or irregularities after they
have occurred.
7. An audit trail is most useful for:
A. Preventing all errors
B. Tracing transactions from initiation to completion
C. Increasing processing speed
D. Eliminating the need for documentation
Answer: B
Rationale: Audit trails provide evidence allowing auditors to follow
transactions through the system.
8. Which of the following best describes encryption?
A. Data deletion process
B. Data backup process