TRUE/FALSE
1. Corporate management (including the CEO) must certify monthly and annually their organization’s
internal controls over financial reporting.
ANS: F PTS: 1
2. Both the SEC and the PCAOB require management to use the COBIT framework for assessing internal
control adequacy.
ANS: F PTS: 1
3. Both the SEC and the PCAOB require management to use the COSO framework for assessing internal
control adequacy.
ANS: F PTS: 1
4. A qualified opinion on management’s assessment of internal controls over the financial reporting system
necessitates a qualified opinion on the financial statements?
ANS: F PTS: 1
5. The same internal control objectives apply to manual and computer-based information systems.
ANS: T PTS: 1
6. The external auditor is responsible for establishing and maintaining the internal control system.
ANS: F PTS: 1
7. Segregation of duties is an example of an internal control procedure.
ANS: T PTS: 1
8. Preventive controls are passive techniques designed to reduce fraud.
ANS: T PTS: 1
9. A key modifying assumption in internal control is that the internal control system is the responsibility of
,management.
ANS: T PTS: 1
, IT Auditing 4th Ed—Test Bank, Chapter 1
10. While the Sarbanes-Oxley Act prohibits auditors from providing non-accounting services to their audit
clients, they are not prohibited from performing such services for non-audit clients or privately held
companies.
ANS: T PTS: 1
11. The Sarbanes-Oxley Act requires the audit committee to hire and oversee the external auditors.
ANS: T PTS: 1
12. Section 404 requires that corporate management (including the CEO) certify their organization’s internal
controls on a quarterly and annual basis.
ANS: F PTS: 1
13. Section 302 requires the management of public companies to assess and formally report on the
effectiveness of their organization’s internal controls.
ANS: F PTS: 1
14. Application controls apply to a wide range of exposures that threaten the integrity of all programs
processed within the computer environment.
ANS: F PTS: 1
15. Advisory services is an emerging field that goes beyond the auditor’s traditional attestation function.
ANS: T PTS: 1
16. An IT auditor expresses an opinion on the fairness of the financial statements.
ANS: F PTS: 1
17. External auditing is an independent appraisal function established within an organization to examine and
evaluate its activities as a service to the organization.
ANS: F PTS: 1
18. External auditors can cooperate with and use evidence gathered by internal audit departments that are
organizationally independent and that report to the Audit Committee of the Board of Directors.
© 2016 Cengage Learning®. May not be scanned, copied or duplicated or posted to a publicly accessible website, in whole or in part, except for use as permitted in a
license distributed with a certain product or service or otherwise on a password-protected website or school-approved learning management system for classroom use.