All questions
Question 1
An auditor determines that an organization's program change controls are ineffective - developers can directly modify production code without authorization. What is the most significant implication for the financial statement audit?
- The auditor must test all input controls manually.
- The organization must restate its financial statements for the prior year.
- Automated application controls in the affected systems cannot be relied upon, requiring the auditor to perform additional substantive procedures. (correct answer)
- The auditor must issue an adverse opinion on the financial statements.
Explanation: Ineffective change controls mean automated controls could have been altered without authorization - the auditor cannot rely on them and must compensate with increased substantive testing. Answer C is correct. Input control testing (A) does not fully compensate. Prior year restatement (B) is not automatic. An adverse opinion (D) is not required solely due to ITGC weaknesses.
Question 2
Which of the following is an example of a computer operations control?
- Requiring manager approval before deploying code changes to production.
- Restricting database access to authorized personnel only.
- Reviewing the design specifications for a new financial application before development begins.
- Monitoring job scheduling to ensure batch processes run at their scheduled times and investigating failures promptly. (correct answer)
Explanation: Computer operations controls govern the day-to-day operation of IT systems - job scheduling, batch monitoring, operations logs, and incident response. Answer D is correct. Deployment approval (A) is a change control. Database access restriction (B) is a logical access control. Design review (C) is a program development control.
Question 3
When evaluating the design of ITGCs, an auditor finds that the organization has no formal segregation of duties between developers and production system administrators. The most significant risk is:
- The development team may not have adequate technical skills.
- Production administrators may not understand the business requirements for system changes.
- Developers could make unauthorized changes directly to production systems without detection, undermining both change management and automated application controls. (correct answer)
- The organization may not comply with IT governance best practices.
Explanation: Without segregation between development and production, developers can implement unauthorized code directly in production - a fundamental ITGC control failure that compromises all downstream application controls. Answer C is correct. Technical skills (A), business requirements (B), and best practice compliance (D) are secondary concerns compared to the unauthorized change risk.
Question 4
An auditor is evaluating ITGCs for a company subject to SOX Section 404. The auditor selects a sample of user account provisioning and termination events. For each sampled event, the auditor verifies that access was granted only to appropriate roles and terminated promptly. This procedure tests which ITGC?
- Logical access controls - specifically the provisioning and deprovisioning process for user accounts. (correct answer)
- Program change controls - confirming that account changes were authorized through the change management process.
- Computer operations controls - confirming that system administrators managed user accounts correctly.
- Program development controls - confirming that the user provisioning system was properly developed.
Explanation: Testing the provisioning and deprovisioning of user accounts is directly testing logical access controls - the ITGC category governing who has access to systems and how access rights are managed. Answer A is correct. Account management is access control (A), not change management (B), operations (C), or development (D).
Question 5
During an ITGC assessment, an auditor finds that the organization's production database has 47 active user accounts belonging to former employees. The most appropriate audit finding is:
- A computer operations control deficiency - former employee accounts affect system performance.
- A program development control deficiency - the user provisioning system was not properly developed.
- A program change control deficiency - account deactivation was not implemented as a change.
- A logical access control deficiency - terminated employee accounts were not promptly deactivated, creating risk of unauthorized access by former employees. (correct answer)
Explanation: Active accounts for terminated employees is a logical access control deficiency - the offboarding process failed to revoke access, creating unauthorized access risk. Answer D is correct. This is not an operations (A), development (B), or change control (C) issue.
Question 6
Which of the following best describes the relationship between ITGCs and automated application controls?
- ITGCs and automated application controls are independent - the effectiveness of one does not affect the other.
- ITGCs provide the foundation for automated application controls - if ITGCs are effective, auditors can place greater reliance on automated controls without additional testing. (correct answer)
- Automated application controls are more important than ITGCs for financial reporting purposes.
- Strong automated application controls can fully compensate for weak ITGCs.
Explanation: Effective ITGCs (especially change controls and access controls) provide assurance that automated application controls have not been tampered with, enabling greater reliance. Weak ITGCs undermine automated control reliability. Answer B is correct. They are interdependent (A). ITGCs underpin application controls (C). Weak ITGCs cannot be fully compensated by strong automated controls (D).
Question 7
When evaluating ITGCs for a cloud-hosted financial system, which of the following additional considerations is unique to the cloud environment?
- Whether the organization has an IT steering committee that reviews IT investments.
- Whether the organization's disaster recovery plan covers the financial system.
- Whether the cloud provider's own ITGCs are adequate, typically assessed through a SOC 1 Type II report covering the provider's relevant controls. (correct answer)
- Whether the system's automated application controls are properly designed.
Explanation: Cloud environments introduce a shared responsibility model - the organization must assess whether the cloud provider's ITGCs (infrastructure access, change management, operations) are effective, typically through a SOC 1 Type II report. Answer C is correct. IT steering committees (A) and DR plans (B) apply to all environments. Application control design (D) is not cloud-specific.
Question 8
An auditor tests ITGC operating effectiveness by selecting a sample of change tickets from throughout the year and testing each for evidence of authorization, testing, and deployment segregation. The sample includes changes from all four quarters. Why is a sample covering the full year important?
- It allows the auditor to calculate a statistically precise error rate.
- It ensures the sample includes both major and minor changes.
- It reduces the time required to complete ITGC testing.
- It provides evidence that controls operated consistently throughout the financial reporting period, not just at the time of testing. (correct answer)
Explanation: For ITGCs supporting financial reporting, controls must have operated throughout the period under audit - a sample covering all quarters provides evidence of consistent operation, not just point-in-time compliance. Answer D is correct. Statistical precision (A), change size coverage (B), and time reduction (C) are not the primary reason for full-year sampling.
Question 9
Which of the following represents a program development control?
- Requiring two approvers for all production deployments.
- Documenting system design specifications, conducting code reviews, and requiring user acceptance testing before any new application goes live. (correct answer)
- Monitoring batch job logs for failures and investigating them promptly.
- Reviewing and approving user access requests based on job function.
Explanation: Program development controls govern the lifecycle of new system development - design documentation, code reviews, and UAT ensure new systems are built correctly and work as intended before production deployment. Answer B is correct. Deployment approvals (A) are change controls. Batch monitoring (C) is operations. Access approval (D) is logical access.
Question 10
An organization relies on a single IT administrator who has full administrative rights to all production systems, performs all deployments, manages user access, and responds to all incidents. From an ITGC perspective, the primary concern is:
- A complete lack of segregation of duties - one person controls all aspects of the IT environment, creating unlimited opportunity for unauthorized changes or fraud without detection. (correct answer)
- The administrator may lack the technical expertise to manage all these functions.
- The organization is non-compliant with IT infrastructure best practices.
- The administrator may become overwhelmed and cause performance issues.
Explanation: One person controlling all IT functions - access, changes, deployments, and operations - eliminates all segregation of duties and any possibility of independent check, representing a critical ITGC deficiency. Answer A is correct. Technical skills (B), best practices (C), and workload (D) are secondary concerns.
Question 11
Which of the following best describes how ITGC testing findings affect the financial statement audit?
- ITGC deficiencies may cause the auditor to assess IT-dependent controls as unreliable, requiring more extensive substantive testing to obtain sufficient audit evidence. (correct answer)
- ITGC deficiencies always require the auditor to issue a qualified opinion.
- ITGC deficiencies require the organization to restate prior year financial statements.
- ITGC deficiencies have no effect on the financial statement audit if management provides written representations about control effectiveness.
Explanation: ITGC deficiencies cascade into the reliance assessment for automated controls - if the IT environment cannot be trusted, the auditor must compensate with more substantive procedures to obtain assurance. Answer A is correct. Qualified opinions (B) are not automatic from ITGC deficiencies. Restatements (C) require actual financial misstatements. Management representations (D) do not resolve ITGC deficiencies.
Question 12
Computer operations controls include which of the following activities?
- Reviewing code quality during software development sprints.
- Approving user access requests for new employees.
- Monitoring scheduled batch jobs, investigating job failures, managing system capacity, and maintaining operations logs. (correct answer)
- Reviewing and approving proposed changes to production systems.
Explanation: Computer operations controls govern the day-to-day running of IT infrastructure - batch scheduling, job monitoring, capacity management, and operational logging. Answer C is correct. Code review (A) is development. Access approvals (B) are logical access. Change approvals (D) are change management.
Question 13
An auditor evaluating ITGCs tests a sample of password configuration settings across financial systems. The auditor finds that three systems do not enforce the minimum password length policy. This is a finding in which ITGC category?
- Program development controls
- Computer operations controls
- Program change controls
- Logical access controls (correct answer)
Explanation: Password configuration settings govern how users authenticate - enforcing password policies is a logical access control requirement that ensures authentication standards are maintained. Answer D is correct. Password settings are not development (A), operations (B), or change (C) controls.
Question 14
Which of the following audit procedures provides the strongest evidence that program change controls operated effectively throughout the audit period?
- Selecting a sample of production changes deployed throughout the year and verifying each has an approved change request, testing evidence, and was deployed by someone other than the developer. (correct answer)
- Reviewing the change management policy to confirm it requires authorization and testing.
- Interviewing the change manager to confirm the process is followed.
- Confirming the change management system generates a ticket for each request.
Explanation: Testing a sample of actual changes against control requirements throughout the year provides direct evidence of consistent operating effectiveness. Answer A is correct. Policy review (B) and interviews (C) address design. Ticket generation (D) confirms process initiation but not control execution.
Question 15
When assessing the severity of an ITGC deficiency for SOX reporting purposes, which factor is most important?
- Whether the deficiency was identified by internal audit or the external auditor.
- How long the deficiency has existed.
- Whether the deficiency creates a reasonable possibility that a material misstatement in the financial statements could occur and not be prevented or detected. (correct answer)
- Whether management was aware of the deficiency before the audit.
Explanation: SOX severity classification (significant deficiency vs. material weakness) depends on whether the control gap creates a meaningful risk of undetected material misstatement - the threshold question for all ITGC deficiency assessments. Answer C is correct. Discovery source (A), deficiency age (B), and management awareness (D) are relevant context but not the primary severity criterion.
Question 16
An organization's new cloud ERP system automatically logs all user activities, access attempts, and configuration changes. How should the auditor evaluate these automated logs as part of the ITGC assessment?
- Accept the logs as sufficient evidence of control effectiveness without further testing.
- Ignore the logs since cloud systems are managed by the provider.
- Use the logs only to assess whether users have appropriate access levels.
- Evaluate whether the logs are comprehensive, tamper-proof, retained for an appropriate period, and reviewed by management on a regular basis with follow-up on exceptions. (correct answer)
Explanation: Logs are only valuable as controls if they are complete, protected from alteration, retained long enough to support investigation, and actually reviewed with follow-up - simply having logs does not confirm effective ITGC monitoring. Answer D is correct. Logs alone are not sufficient evidence (A). Cloud logs are still the organization's responsibility (B). Logs support multiple ITGC assessments beyond just access levels (C).
Question 17
Which of the following correctly identifies the four primary categories of IT general controls?
- Logical access controls, program change controls, computer operations controls, and program development controls. (correct answer)
- Input controls, processing controls, output controls, and interface controls.
- Governance controls, risk controls, compliance controls, and monitoring controls.
- Network controls, database controls, application controls, and physical controls.
Explanation: The four standard ITGC categories are: (1) logical access controls (who can access what), (2) program change controls (how changes are authorized and implemented), (3) computer operations controls (how systems are operated and monitored), and (4) program development controls (how new systems are developed). Answer A is correct. Answer B describes application controls. Answers C and D are not standard ITGC categories.
Question 18
Which of the following most accurately describes the scope of ITGCs relevant to a financial statement audit?
- All IT systems in the organization, regardless of their connection to financial data.
- IT systems and controls that support the processing, storage, or transmission of financial data, or that support automated application controls relied upon in the audit. (correct answer)
- Only the ERP system used for general ledger accounting.
- All IT systems managed by the IT department, including HR, facilities, and marketing systems.
Explanation: ITGC scope for financial auditing is risk-based - focused on systems that touch financial data or support relied-upon application controls. Non-financial systems are generally out of scope. Answer B is correct. All IT systems (A, D) is too broad. Only the GL system (C) may be too narrow if other systems feed financial processes.
Question 19
A financial services company implements a quarterly user access review requiring managers to certify that their team members' system access rights remain appropriate. This is an example of which ITGC category?
- Program development controls
- Logical access controls (correct answer)
- Computer operations controls
- Program change controls
Explanation: User access reviews and recertifications are logical access controls - they ensure that access rights remain appropriate and aligned with current job responsibilities. Answer B is correct. Program development (A) governs new system creation. Computer operations (C) governs system operation. Change controls (D) govern system modifications.
Question 20
An auditor finds that an organization's ITGC framework is comprehensive but has not been updated in four years. Significant technology changes have occurred, including migration to cloud infrastructure and adoption of new ERP modules. The primary risk is:
- The ITGC documentation will fail to impress external auditors.
- The existing ITGC framework may not address risks introduced by new technologies, creating unmitigated control gaps. (correct answer)
- Employees will not be familiar with the outdated ITGC documentation.
- The organization may not achieve the highest rating in IT maturity assessments.
Explanation: ITGCs must evolve with technology - a cloud migration and new ERP introduce new access paths, change mechanisms, and operational risks that the old framework may not address. Answer B is correct. Auditor impressions (A), employee familiarity (C), and maturity ratings (D) are secondary concerns.