Topic 2, Volume B
During a review of data center physical security and environmental controls,an auditor
should ensure that:
I. Visitors are accompanied by authorized personnel at all times.
II.Only developers and operators have access to the data center.
III.Fire suppression equipment is tested periodically.
IV.Fire and water detectors have been installed.
A.
I and IIIonly
B.
II and IVonly
C.
I,III,and IVonly
D.
II,III,and IVonly
I,III,and IVonly
A quantitative risk assessment model has all of the following advantages except:
A.
Accommodating a large number of risk factors in the assessment.
B.
Providing documentation for the chief audit executive,who must defend the long-range
audit plan.
C.
Providing a systematic method of applying weightings to risks and priorities.
D.
Removing the need for judgment on the part of the chief audit executive.
Removing the need for judgment on the part of the chief audit executive.
The main reason to establish internal controls in an organization is to:
A.
Encourage compliance with policies and procedures.
B.
Safeguard the resources of the organization.
C.
Ensure the accuracy,reliability,and timeliness of information.
D.
Provide reasonable assurance on the achievement of objectives.
Provide reasonable assurance on the achievement of objectives.
When using a risk assessment model to develop audit plans,it is essential that the chief
audit executive take into accountthe:
A.
Results of the last audit.
B.
Planned visits by the external auditors during the upcoming year.
C.
Recent or expected changes in management direction and objectives.
D.
Dates of future board meetings.
Recent or expected changes in management direction and objectives.
The chief audit executive for an organization has just completed a risk assessment
process,identified the areas with the highest risk,and assigned an audit priority to each.
Which of the following statements is true and consistent with the International Professional
Practices Framework?
I.Items should be ranked in the order of quantifiable dollar exposure to the organization.
II.The audit priorities should be in order of major control deficiencies.
III.The risk assessment,though quantified,is the result of professional judgments about both
exposures and probability of occurrences.
A.
Ionly
B.
IIIonly
C.
II and IIIonly
D.
I,II,and III.
IIIonly
Page 31 out of 114 Pages |
Previous |