, IT Auditing 4th Ed—Test Bank, Chapter
r1 r1 r1 r1 r1
1
Chapter 1—Auditing and Internal Control
r1 r1 r1 r1
TRUE/FALSE
1. Corporate management (including the CEO) must certify monthly and annually their
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
organization‟s internal controls over financial reporting.
r1 r1 r1 r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
2. Both the SEC and the PCAOB require management to use the COBIT framework for assessing
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
internal control adequacy.
r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
3. Both the SEC and the PCAOB require management to use the COSO framework for assessing
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
internal control adequacy.
r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
4. A qualified opinion on management‟s assessment of internal controls over the financial reporting
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
system necessitates a qualified opinion on the financial statements?
r1 r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
5. The same internal control objectives apply to manual and computer-based information systems.
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 T PTS: r 1 r 1 1
6. The external auditor is responsible for establishing and maintaining the internal control system.
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
7. Segregation of duties is an example of an internal control procedure.
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 T PTS: r 1 r 1 1
8. Preventive controls are passive techniques designed to reduce fraud.
r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 T PTS: r 1 r 1 1
9. A key modifying assumption in internal control is that the internal control system is the
r 1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
responsibility of management.
r1 r1 r1
ANS: r 1 T PTS: r 1 r 1 1
© r12016 r1Cengage r1Learning®. r 1 May r1not r1be r1scanned, r1copied r1or r1duplicated r1or r1posted r1to r1a r1publicly r1accessible r1website, r1in r1whole r1or r1in r1part, r1except
r1for r1use r1as r1permitted r1in r1a r 1 license r1distributed r1with r1a r1certain r1product r1or r1service r1or r1otherwise r1on r1a r1password-protected r1website r1or r1school-approved
learning management system for classroom use.
, IT Auditing 4th Ed—Test Bank, Chapter
r1 r1 r1 r1 r1
1
10. While the Sarbanes-Oxley Act prohibits auditors from providing non-accounting services to their
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
audit clients, they are not prohibited from performing such services for non-audit clients or
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
privately held companies.
r1 r1 r1
ANS: r 1 T PTS: r 1 r 1 1
11. The Sarbanes-Oxley Act requires the audit committee to hire and oversee the external auditors.
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 T PTS: r 1 r 1 1
12. Section 404 requires that corporate management (including the CEO) certify their organization‟s
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
internal controls on a quarterly and annual basis.
r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
13. Section 302 requires the management of public companies to assess and formally report on
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
the effectiveness of their organization‟s internal controls.
r1 r1 r1 r1 r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
14. Application controls apply to a wide range of exposures that threaten the integrity of all
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
programs processed within the computer environment.
r1 r1 r1 r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
15. Advisory services is an emerging field that goes beyond the auditor‟s traditional attestation function.
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 T PTS: r 1 r 1 1
16. An IT auditor expresses an opinion on the fairness of the financial statements.
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
17. External auditing is an independent appraisal function established within an organization to examine
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
and evaluate its activities as a service to the organization.
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
18. External auditors can cooperate with and use evidence gathered by internal audit departments that
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
are organizationally independent and that report to the Audit Committee of the Board of
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
© r12016 r1Cengage r1Learning®. r 1 May r1not r1be r1scanned, r1copied r1or r1duplicated r1or r1posted r1to r1a r1publicly r1accessible r1website, r1in r1whole r1or r1in r1part, r1except
r1for r1use r1as r1permitted r1in r1a r 1 license r1distributed r1with r1a r1certain r1product r1or r1service r1or r1otherwise r1on r1a r1password-protected r1website r1or r1school-approved
learning management system for classroom use.
, IT Auditing 4th Ed—Test Bank, Chapter
r1 r1 r1 r1 r1
r1 Directors. 1
© r12016 r1Cengage r1Learning®. r 1 May r1not r1be r1scanned, r1copied r1or r1duplicated r1or r1posted r1to r1a r1publicly r1accessible r1website, r1in r1whole r1or r1in r1part, r1except
r1for r1use r1as r1permitted r1in r1a r 1 license r1distributed r1with r1a r1certain r1product r1or r1service r1or r1otherwise r1on r1a r1password-protected r1website r1or r1school-approved
learning management system for classroom use.
r1 r1 r1 r1 r1
1
Chapter 1—Auditing and Internal Control
r1 r1 r1 r1
TRUE/FALSE
1. Corporate management (including the CEO) must certify monthly and annually their
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
organization‟s internal controls over financial reporting.
r1 r1 r1 r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
2. Both the SEC and the PCAOB require management to use the COBIT framework for assessing
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
internal control adequacy.
r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
3. Both the SEC and the PCAOB require management to use the COSO framework for assessing
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
internal control adequacy.
r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
4. A qualified opinion on management‟s assessment of internal controls over the financial reporting
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
system necessitates a qualified opinion on the financial statements?
r1 r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
5. The same internal control objectives apply to manual and computer-based information systems.
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 T PTS: r 1 r 1 1
6. The external auditor is responsible for establishing and maintaining the internal control system.
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
7. Segregation of duties is an example of an internal control procedure.
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 T PTS: r 1 r 1 1
8. Preventive controls are passive techniques designed to reduce fraud.
r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 T PTS: r 1 r 1 1
9. A key modifying assumption in internal control is that the internal control system is the
r 1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
responsibility of management.
r1 r1 r1
ANS: r 1 T PTS: r 1 r 1 1
© r12016 r1Cengage r1Learning®. r 1 May r1not r1be r1scanned, r1copied r1or r1duplicated r1or r1posted r1to r1a r1publicly r1accessible r1website, r1in r1whole r1or r1in r1part, r1except
r1for r1use r1as r1permitted r1in r1a r 1 license r1distributed r1with r1a r1certain r1product r1or r1service r1or r1otherwise r1on r1a r1password-protected r1website r1or r1school-approved
learning management system for classroom use.
, IT Auditing 4th Ed—Test Bank, Chapter
r1 r1 r1 r1 r1
1
10. While the Sarbanes-Oxley Act prohibits auditors from providing non-accounting services to their
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
audit clients, they are not prohibited from performing such services for non-audit clients or
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
privately held companies.
r1 r1 r1
ANS: r 1 T PTS: r 1 r 1 1
11. The Sarbanes-Oxley Act requires the audit committee to hire and oversee the external auditors.
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 T PTS: r 1 r 1 1
12. Section 404 requires that corporate management (including the CEO) certify their organization‟s
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
internal controls on a quarterly and annual basis.
r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
13. Section 302 requires the management of public companies to assess and formally report on
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
the effectiveness of their organization‟s internal controls.
r1 r1 r1 r1 r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
14. Application controls apply to a wide range of exposures that threaten the integrity of all
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
programs processed within the computer environment.
r1 r1 r1 r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
15. Advisory services is an emerging field that goes beyond the auditor‟s traditional attestation function.
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 T PTS: r 1 r 1 1
16. An IT auditor expresses an opinion on the fairness of the financial statements.
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
17. External auditing is an independent appraisal function established within an organization to examine
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
and evaluate its activities as a service to the organization.
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
ANS: r 1 F PTS: r 1 r 1 1
18. External auditors can cooperate with and use evidence gathered by internal audit departments that
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
are organizationally independent and that report to the Audit Committee of the Board of
r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1 r1
© r12016 r1Cengage r1Learning®. r 1 May r1not r1be r1scanned, r1copied r1or r1duplicated r1or r1posted r1to r1a r1publicly r1accessible r1website, r1in r1whole r1or r1in r1part, r1except
r1for r1use r1as r1permitted r1in r1a r 1 license r1distributed r1with r1a r1certain r1product r1or r1service r1or r1otherwise r1on r1a r1password-protected r1website r1or r1school-approved
learning management system for classroom use.
, IT Auditing 4th Ed—Test Bank, Chapter
r1 r1 r1 r1 r1
r1 Directors. 1
© r12016 r1Cengage r1Learning®. r 1 May r1not r1be r1scanned, r1copied r1or r1duplicated r1or r1posted r1to r1a r1publicly r1accessible r1website, r1in r1whole r1or r1in r1part, r1except
r1for r1use r1as r1permitted r1in r1a r 1 license r1distributed r1with r1a r1certain r1product r1or r1service r1or r1otherwise r1on r1a r1password-protected r1website r1or r1school-approved
learning management system for classroom use.