Page |1
WGU D561 – Information Systems for Accounting and Control:
Complete Practice Test (2026) Objective Assessment | OA Questions
and Answers | 2026 Update | 100% Correct
Domain 1: IT Governance & Internal Controls (COSO, COBIT, ITIL)
1. The COSO (Committee of Sponsoring Organizations of the Treadway
Commission) framework is primarily used to:
A) Design and evaluate the effectiveness of internal controls over financial
reporting
B) Manage IT service delivery
C) Govern enterprise IT resources
D) Develop software applications
Answer: A
Rationale: The COSO framework is the gold standard for designing, implementing,
and evaluating internal controls over financial reporting (ICFR). It provides a
comprehensive framework that includes the control environment, risk assessment,
control activities, information and communication, and monitoring. COBIT and ITIL
are IT-specific frameworks.
2. The COBIT (Control Objectives for Information and Related Technologies)
framework focuses on:
A) Financial reporting controls
B) IT governance and management, providing a framework for aligning IT with
business goals
C) Software development methodologies
D) Physical security of data centers
Answer: B
Rationale: COBIT is an IT governance framework that helps organizations achieve
their objectives by managing and governing their IT resources. It provides a
comprehensive set of control objectives and management guidelines to ensure IT
is aligned with the business strategy.
, Page |2
3. The ITIL (Information Technology Infrastructure Library) framework is used to:
A) Audit financial statements
B) Manage IT service management (ITSM), including incident management,
change management, and service desk operations
C) Design internal controls over financial reporting
D) Develop software using agile methodologies
Answer: B
Rationale: ITIL is a set of best practices for IT service management (ITSM). It
focuses on aligning IT services with business needs and managing the lifecycle of
IT services, including incident management, problem management, change
management, and service level management.
4. The "Control Environment" in the COSO framework includes which of the
following?
A) The organization's commitment to integrity and ethical values, the board's
oversight, and the management's philosophy and operating style
B) The policies and procedures that ensure management directives are carried out
C) The identification and analysis of risks to achieving objectives
D) The information systems and communication channels used to support controls
Answer: A
Rationale: The Control Environment is the foundation of the COSO framework. It
sets the tone of the organization and includes: integrity and ethical values, the
board's oversight, management's philosophy and operating style, and the
organization's commitment to competence.
5. According to COSO, "Risk Assessment" is the process of:
A) Identifying and analyzing risks to the achievement of the organization's
objectives
B) Implementing policies and procedures to mitigate risks
C) Monitoring the effectiveness of controls
D) Communicating control responsibilities to employees
, Page |3
Answer: A
Rationale: Risk Assessment is the second component of the COSO framework. It
involves identifying potential risks (both internal and external) that could prevent
the organization from achieving its objectives and analyzing the likelihood and
impact of those risks.
6. The "Control Activities" component of COSO includes:
A) The organization's ethical values
B) Policies, procedures, and activities that ensure management directives are
carried out (e.g., approvals, authorizations, verifications, and reconciliations)
C) The identification of risks
D) The monitoring of internal controls
Answer: B
Rationale: Control Activities are the actions taken by management to mitigate
risks and ensure that objectives are achieved. Examples include: segregation of
duties, authorization of transactions, physical controls, and independent
reconciliations.
7. Segregation of duties is a critical internal control. Which of the following is the
primary purpose of segregation of duties?
A) To ensure that no single individual has the ability to both perpetrate and
conceal a fraud
B) To reduce the number of employees needed to perform a task
C) To increase the speed of transaction processing
D) To reduce the cost of internal controls
Answer: A
Rationale: The primary purpose of segregation of duties is to reduce the risk of
fraud and error. By separating the responsibilities for authorizing, recording, and
custody of assets, it prevents a single individual from being able to both perpetrate
a fraud and conceal it.
8. The Sarbanes-Oxley Act (SOX) of 2002 requires management of publicly
traded companies to:
WGU D561 – Information Systems for Accounting and Control:
Complete Practice Test (2026) Objective Assessment | OA Questions
and Answers | 2026 Update | 100% Correct
Domain 1: IT Governance & Internal Controls (COSO, COBIT, ITIL)
1. The COSO (Committee of Sponsoring Organizations of the Treadway
Commission) framework is primarily used to:
A) Design and evaluate the effectiveness of internal controls over financial
reporting
B) Manage IT service delivery
C) Govern enterprise IT resources
D) Develop software applications
Answer: A
Rationale: The COSO framework is the gold standard for designing, implementing,
and evaluating internal controls over financial reporting (ICFR). It provides a
comprehensive framework that includes the control environment, risk assessment,
control activities, information and communication, and monitoring. COBIT and ITIL
are IT-specific frameworks.
2. The COBIT (Control Objectives for Information and Related Technologies)
framework focuses on:
A) Financial reporting controls
B) IT governance and management, providing a framework for aligning IT with
business goals
C) Software development methodologies
D) Physical security of data centers
Answer: B
Rationale: COBIT is an IT governance framework that helps organizations achieve
their objectives by managing and governing their IT resources. It provides a
comprehensive set of control objectives and management guidelines to ensure IT
is aligned with the business strategy.
, Page |2
3. The ITIL (Information Technology Infrastructure Library) framework is used to:
A) Audit financial statements
B) Manage IT service management (ITSM), including incident management,
change management, and service desk operations
C) Design internal controls over financial reporting
D) Develop software using agile methodologies
Answer: B
Rationale: ITIL is a set of best practices for IT service management (ITSM). It
focuses on aligning IT services with business needs and managing the lifecycle of
IT services, including incident management, problem management, change
management, and service level management.
4. The "Control Environment" in the COSO framework includes which of the
following?
A) The organization's commitment to integrity and ethical values, the board's
oversight, and the management's philosophy and operating style
B) The policies and procedures that ensure management directives are carried out
C) The identification and analysis of risks to achieving objectives
D) The information systems and communication channels used to support controls
Answer: A
Rationale: The Control Environment is the foundation of the COSO framework. It
sets the tone of the organization and includes: integrity and ethical values, the
board's oversight, management's philosophy and operating style, and the
organization's commitment to competence.
5. According to COSO, "Risk Assessment" is the process of:
A) Identifying and analyzing risks to the achievement of the organization's
objectives
B) Implementing policies and procedures to mitigate risks
C) Monitoring the effectiveness of controls
D) Communicating control responsibilities to employees
, Page |3
Answer: A
Rationale: Risk Assessment is the second component of the COSO framework. It
involves identifying potential risks (both internal and external) that could prevent
the organization from achieving its objectives and analyzing the likelihood and
impact of those risks.
6. The "Control Activities" component of COSO includes:
A) The organization's ethical values
B) Policies, procedures, and activities that ensure management directives are
carried out (e.g., approvals, authorizations, verifications, and reconciliations)
C) The identification of risks
D) The monitoring of internal controls
Answer: B
Rationale: Control Activities are the actions taken by management to mitigate
risks and ensure that objectives are achieved. Examples include: segregation of
duties, authorization of transactions, physical controls, and independent
reconciliations.
7. Segregation of duties is a critical internal control. Which of the following is the
primary purpose of segregation of duties?
A) To ensure that no single individual has the ability to both perpetrate and
conceal a fraud
B) To reduce the number of employees needed to perform a task
C) To increase the speed of transaction processing
D) To reduce the cost of internal controls
Answer: A
Rationale: The primary purpose of segregation of duties is to reduce the risk of
fraud and error. By separating the responsibilities for authorizing, recording, and
custody of assets, it prevents a single individual from being able to both perpetrate
a fraud and conceal it.
8. The Sarbanes-Oxley Act (SOX) of 2002 requires management of publicly
traded companies to: