WGU D217 QUESTIONS AND ANSWERS SURE A+
✔✔completing questionnaires - ✔✔Tests of controls include
✔✔the likelihood that the control structure is flawed because controls are either absent
of inadequate to prevent or detect errors in the accounts. - ✔✔Control risk is
✔✔systems development from computer operations, - ✔✔Which is the most critical
segregation of duties in the centralized IT function?
✔✔separating the programmer from the computer operator. - ✔✔Segregation of duties
in the computer-based information system includes
✔✔allows programmers access to make unauthorized changes to applications during
execution. - ✔✔System development is separated from data processing activities
because failure to do so
✔✔because of flaws in the operating system that are exploited either accidently or
intentionally. - ✔✔Operating system control objectives may not be achieved
✔✔the computer's control program. - ✔✔The operating system is
✔✔a hardware flaw that causes the system to crash. - ✔✔Which of the following is
considered an unintentional threat to the integrity of the operating system?
✔✔individuals who browse the operating system to identify and exploit security flaws. -
✔✔Which of the following is considered an intentional threat to the integrity of the
operating system?
✔✔the reusable password - ✔✔The most common method of password control is
, ✔✔The application does not need to be removed from service and tested directly. -
✔✔Which of the following is true about the black box approach to auditing computer
applications?
✔✔verify that individuals or programs are valid - ✔✔Access tests
✔✔creating two master files. - ✔✔Testing the three-way match involves
✔✔The test data technique requires extensive computer expertise on the part of the
auditor. - ✔✔Which of the following is an advantage of the test data technique?
✔✔is used to reprocess the same transactions that the production application
previously processed. - ✔✔Parallel simulation
✔✔Reasonable assurance - ✔✔An organization's internal controls have been deemed
effective by management and external audits for the last five years. A proposal is made
to upgrade the enterprise resource planning (ERP) system at a significant cost. The
proposal mentions slightly increased IT controls to better detect errors. Which modifying
assumption would keep management from implementing the upgrade?
✔✔risk assessment - ✔✔Which component of the Committee of Sponsoring
Organizations of the Treadway Commission (COSO) framework is being considered
when an auditor is comparing a company's organization chart to the prior year's chart to
identify new personnel who are responsible for internal controls?
✔✔Honesty - ✔✔What is one of the four areas that ethical issues in business can be
divided into?
✔✔Database management fraud - ✔✔A disgruntled employee places a logic bomb to
erase an organization's supplier list. Which type of fraud does this scenario reflect?
✔✔Data collection - ✔✔Which access point is the most common for committing
computer fraud?
✔✔All financial accounts with material implications for financial reporting. -
✔✔According to the Public Company Accounting Oversight Board (PCAOB) Standard
No. 5, auditors need to understand transaction flows, including the controls pertaining to
how transactions are initiated, authorized, recorded, and reported. Which accounts are
affected by this requirement?
✔✔The internal audit department documents this evidence. - ✔✔Management is
required to provide external auditors with documented evidence of functioning controls
related to selected material accounts in a report on control effectiveness. How is this
evidence obtained?
✔✔completing questionnaires - ✔✔Tests of controls include
✔✔the likelihood that the control structure is flawed because controls are either absent
of inadequate to prevent or detect errors in the accounts. - ✔✔Control risk is
✔✔systems development from computer operations, - ✔✔Which is the most critical
segregation of duties in the centralized IT function?
✔✔separating the programmer from the computer operator. - ✔✔Segregation of duties
in the computer-based information system includes
✔✔allows programmers access to make unauthorized changes to applications during
execution. - ✔✔System development is separated from data processing activities
because failure to do so
✔✔because of flaws in the operating system that are exploited either accidently or
intentionally. - ✔✔Operating system control objectives may not be achieved
✔✔the computer's control program. - ✔✔The operating system is
✔✔a hardware flaw that causes the system to crash. - ✔✔Which of the following is
considered an unintentional threat to the integrity of the operating system?
✔✔individuals who browse the operating system to identify and exploit security flaws. -
✔✔Which of the following is considered an intentional threat to the integrity of the
operating system?
✔✔the reusable password - ✔✔The most common method of password control is
, ✔✔The application does not need to be removed from service and tested directly. -
✔✔Which of the following is true about the black box approach to auditing computer
applications?
✔✔verify that individuals or programs are valid - ✔✔Access tests
✔✔creating two master files. - ✔✔Testing the three-way match involves
✔✔The test data technique requires extensive computer expertise on the part of the
auditor. - ✔✔Which of the following is an advantage of the test data technique?
✔✔is used to reprocess the same transactions that the production application
previously processed. - ✔✔Parallel simulation
✔✔Reasonable assurance - ✔✔An organization's internal controls have been deemed
effective by management and external audits for the last five years. A proposal is made
to upgrade the enterprise resource planning (ERP) system at a significant cost. The
proposal mentions slightly increased IT controls to better detect errors. Which modifying
assumption would keep management from implementing the upgrade?
✔✔risk assessment - ✔✔Which component of the Committee of Sponsoring
Organizations of the Treadway Commission (COSO) framework is being considered
when an auditor is comparing a company's organization chart to the prior year's chart to
identify new personnel who are responsible for internal controls?
✔✔Honesty - ✔✔What is one of the four areas that ethical issues in business can be
divided into?
✔✔Database management fraud - ✔✔A disgruntled employee places a logic bomb to
erase an organization's supplier list. Which type of fraud does this scenario reflect?
✔✔Data collection - ✔✔Which access point is the most common for committing
computer fraud?
✔✔All financial accounts with material implications for financial reporting. -
✔✔According to the Public Company Accounting Oversight Board (PCAOB) Standard
No. 5, auditors need to understand transaction flows, including the controls pertaining to
how transactions are initiated, authorized, recorded, and reported. Which accounts are
affected by this requirement?
✔✔The internal audit department documents this evidence. - ✔✔Management is
required to provide external auditors with documented evidence of functioning controls
related to selected material accounts in a report on control effectiveness. How is this
evidence obtained?