WGU D561 INFORMATION SYSTEMS FOR ACCOUNTING AND CONTROL STUDY
GUIDE | TESTBANK | PRACTICE QUESTIONS & ANSWERS | EXAM PREPARATION |
ADVANCED REVIEW | COMPREHENSIVE PRACTICE EXAM | LATEST UPDATE
2026/2027
Examiner:
Western Governors University (WGU)
TABLE OF CONTENTS
1. Information Systems and Internal Control Frameworks
2. Enterprise Resource Planning (ERP) Systems
3. Business Processes and Transaction Cycles
4. IT General Controls (ITGCs)
5. Application Controls
6. Risk Assessment and Governance
7. Accounting Information Systems (AIS)
8. Data Management and Database Controls
9. Cybersecurity and Information Security
10. Segregation of Duties and Access Management
11. Business Continuity and Disaster Recovery
12. Auditing Information Systems
13. Regulatory Compliance and Ethics
14. Emerging Technologies in Accounting and Control
ACCOUNTING INFORMATION SYSTEMS || INTERNAL CONTROLS || ERP || COSO ||
COBIT || IT GENERAL CONTROLS || APPLICATION CONTROLS || CYBERSECURITY ||
RISK MANAGEMENT || GOVERNANCE || DATABASE CONTROLS || ACCESS
MANAGEMENT || AUDIT TRAILS || BUSINESS CONTINUITY || DISASTER RECOVERY
|| DATA ANALYTICS || COMPLIANCE || FRAUD PREVENTION || CHANGE
MANAGEMENT || PROFESSIONAL JUDGMENT
Disclaimer: The following questions are original study-practice material created
for exam preparation based on commonly taught concepts, publicly available
learning objectives, textbooks, study guides, and topics associated with
, Information Systems for Accounting and Control. They are not actual WGU
Objective Assessment questions and are not intended to reproduce or resemble
any confidential examination.
QUESTION 1.
A multinational organization recently centralized its purchasing, accounts payable,
and general ledger functions within an ERP environment. An auditor is concerned
that a single user can create vendors, approve purchase orders, receive goods
electronically, and release payments. Which control improvement would most
effectively reduce fraud risk while preserving operational efficiency?
A. Implement role-based segregation of duties with workflow approvals and periodic
access reviews.
B. Require monthly manual reconciliation of all vendor payments.
C. Increase password complexity requirements for procurement staff.
D. Enable automatic payment processing for all approved invoices.
🔴 Correct Answer: A. Implement role-based segregation of duties with workflow
approvals and periodic access reviews.
🔵 Explanation: Proper segregation of duties within role-based access control prevents
one individual from controlling an entire transaction cycle, substantially reducing
opportunities for fraud. Workflow approvals provide independent authorization, while
periodic access reviews detect privilege creep. The remaining options either address
only a portion of the risk or fail to prevent incompatible duties.
QUESTION 2.
An organization is evaluating whether an application control or an IT general control
is responsible for ensuring that only authorized accounting software changes reach
production. Which control best satisfies this objective?
A. Three-way matching of purchase orders, receiving reports, and invoices.
B. Formal change management procedures requiring testing, approval, and migration
,controls.
C. Automated credit limit validation during sales order entry.
D. Duplicate invoice detection before payment processing.
🔴 Correct Answer: B. Formal change management procedures requiring testing,
approval, and migration controls.
🔵 Explanation: Change management is an IT general control that governs how
software modifications are authorized, tested, documented, and implemented. Effective
change management supports the reliability of application controls. The other options
are application controls embedded within specific business processes.
QUESTION 3.
During a cybersecurity assessment, management discovers that privileged system
administrators can modify transaction logs without independent oversight. Which
consequence presents the greatest control concern?
A. Increased storage utilization.
B. Reduced network bandwidth.
C. Loss of reliable audit evidence supporting financial reporting.
D. Longer report generation times.
🔴 Correct Answer: C. Loss of reliable audit evidence supporting financial
reporting.
🔵 Explanation: If privileged users can alter audit logs, the integrity of evidence
supporting financial reporting and investigations becomes questionable. Audit trails are
fundamental for accountability and forensic analysis. The remaining choices represent
operational concerns rather than significant control deficiencies.
QUESTION 4.
A company implements multifactor authentication (MFA) for all finance employees.
Which risk is primarily mitigated?
, A. Incorrect depreciation calculations.
B. Unauthorized system access resulting from compromised passwords.
C. Duplicate vendor master records.
D. Inventory valuation errors.
🔴 Correct Answer: B. Unauthorized system access resulting from compromised
passwords.
🔵 Explanation: Multifactor authentication significantly reduces the likelihood that
stolen or guessed passwords alone can be used to gain unauthorized access. Although
MFA does not eliminate every cyber risk, it strengthens identity verification. The other
options relate to accounting or operational issues rather than authentication.
QUESTION 5.
Management wants assurance that every sales transaction recorded in the
accounting system represents a legitimate shipment. Which automated application
control most directly supports this objective?
A. Automatic invoice numbering.
B. Validation that shipment confirmation exists before invoice generation.
C. Password expiration every 90 days.
D. Encryption of archived financial reports.
🔴 Correct Answer: B. Validation that shipment confirmation exists before invoice
generation.
🔵 Explanation: Linking invoice generation to shipment confirmation helps ensure that
recorded revenue reflects completed deliveries, supporting transaction validity.
Automatic numbering assists completeness but not legitimacy. Password expiration and
encryption address unrelated control objectives.
QUESTION 6.
Which scenario represents the strongest indicator that an organization should
redesign its access control model?
GUIDE | TESTBANK | PRACTICE QUESTIONS & ANSWERS | EXAM PREPARATION |
ADVANCED REVIEW | COMPREHENSIVE PRACTICE EXAM | LATEST UPDATE
2026/2027
Examiner:
Western Governors University (WGU)
TABLE OF CONTENTS
1. Information Systems and Internal Control Frameworks
2. Enterprise Resource Planning (ERP) Systems
3. Business Processes and Transaction Cycles
4. IT General Controls (ITGCs)
5. Application Controls
6. Risk Assessment and Governance
7. Accounting Information Systems (AIS)
8. Data Management and Database Controls
9. Cybersecurity and Information Security
10. Segregation of Duties and Access Management
11. Business Continuity and Disaster Recovery
12. Auditing Information Systems
13. Regulatory Compliance and Ethics
14. Emerging Technologies in Accounting and Control
ACCOUNTING INFORMATION SYSTEMS || INTERNAL CONTROLS || ERP || COSO ||
COBIT || IT GENERAL CONTROLS || APPLICATION CONTROLS || CYBERSECURITY ||
RISK MANAGEMENT || GOVERNANCE || DATABASE CONTROLS || ACCESS
MANAGEMENT || AUDIT TRAILS || BUSINESS CONTINUITY || DISASTER RECOVERY
|| DATA ANALYTICS || COMPLIANCE || FRAUD PREVENTION || CHANGE
MANAGEMENT || PROFESSIONAL JUDGMENT
Disclaimer: The following questions are original study-practice material created
for exam preparation based on commonly taught concepts, publicly available
learning objectives, textbooks, study guides, and topics associated with
, Information Systems for Accounting and Control. They are not actual WGU
Objective Assessment questions and are not intended to reproduce or resemble
any confidential examination.
QUESTION 1.
A multinational organization recently centralized its purchasing, accounts payable,
and general ledger functions within an ERP environment. An auditor is concerned
that a single user can create vendors, approve purchase orders, receive goods
electronically, and release payments. Which control improvement would most
effectively reduce fraud risk while preserving operational efficiency?
A. Implement role-based segregation of duties with workflow approvals and periodic
access reviews.
B. Require monthly manual reconciliation of all vendor payments.
C. Increase password complexity requirements for procurement staff.
D. Enable automatic payment processing for all approved invoices.
🔴 Correct Answer: A. Implement role-based segregation of duties with workflow
approvals and periodic access reviews.
🔵 Explanation: Proper segregation of duties within role-based access control prevents
one individual from controlling an entire transaction cycle, substantially reducing
opportunities for fraud. Workflow approvals provide independent authorization, while
periodic access reviews detect privilege creep. The remaining options either address
only a portion of the risk or fail to prevent incompatible duties.
QUESTION 2.
An organization is evaluating whether an application control or an IT general control
is responsible for ensuring that only authorized accounting software changes reach
production. Which control best satisfies this objective?
A. Three-way matching of purchase orders, receiving reports, and invoices.
B. Formal change management procedures requiring testing, approval, and migration
,controls.
C. Automated credit limit validation during sales order entry.
D. Duplicate invoice detection before payment processing.
🔴 Correct Answer: B. Formal change management procedures requiring testing,
approval, and migration controls.
🔵 Explanation: Change management is an IT general control that governs how
software modifications are authorized, tested, documented, and implemented. Effective
change management supports the reliability of application controls. The other options
are application controls embedded within specific business processes.
QUESTION 3.
During a cybersecurity assessment, management discovers that privileged system
administrators can modify transaction logs without independent oversight. Which
consequence presents the greatest control concern?
A. Increased storage utilization.
B. Reduced network bandwidth.
C. Loss of reliable audit evidence supporting financial reporting.
D. Longer report generation times.
🔴 Correct Answer: C. Loss of reliable audit evidence supporting financial
reporting.
🔵 Explanation: If privileged users can alter audit logs, the integrity of evidence
supporting financial reporting and investigations becomes questionable. Audit trails are
fundamental for accountability and forensic analysis. The remaining choices represent
operational concerns rather than significant control deficiencies.
QUESTION 4.
A company implements multifactor authentication (MFA) for all finance employees.
Which risk is primarily mitigated?
, A. Incorrect depreciation calculations.
B. Unauthorized system access resulting from compromised passwords.
C. Duplicate vendor master records.
D. Inventory valuation errors.
🔴 Correct Answer: B. Unauthorized system access resulting from compromised
passwords.
🔵 Explanation: Multifactor authentication significantly reduces the likelihood that
stolen or guessed passwords alone can be used to gain unauthorized access. Although
MFA does not eliminate every cyber risk, it strengthens identity verification. The other
options relate to accounting or operational issues rather than authentication.
QUESTION 5.
Management wants assurance that every sales transaction recorded in the
accounting system represents a legitimate shipment. Which automated application
control most directly supports this objective?
A. Automatic invoice numbering.
B. Validation that shipment confirmation exists before invoice generation.
C. Password expiration every 90 days.
D. Encryption of archived financial reports.
🔴 Correct Answer: B. Validation that shipment confirmation exists before invoice
generation.
🔵 Explanation: Linking invoice generation to shipment confirmation helps ensure that
recorded revenue reflects completed deliveries, supporting transaction validity.
Automatic numbering assists completeness but not legitimacy. Password expiration and
encryption address unrelated control objectives.
QUESTION 6.
Which scenario represents the strongest indicator that an organization should
redesign its access control model?