Domain 1 Practice Questions Flashcards
Which of the following outlines the overall authority to perform an IS audit?
the approved audit charter
In performing a risk-based audit, which risk assessment is completed FIRST by an IS auditor?
inherent risk assessment
Which of the following would an IS auditor MOST likely focus on when developing a risk-based audit program?
business processes
Which of the following types of audit risk assumes an absence of compensating controls in the area being reviewed?
inherent risk
An IS auditor performing a review of an application’s controls finds a weakness in system software that could materially impact the application. In this situation, an IS auditor should:
review the system software controls as relevant and recommend a detailed system software review
Which of the following is the MOST important reason why an audit planning process should be reviewed at periodic intervals?
to consider changes to the risk environment
Which of the following is MOST effective for implementing a control self-assessment within small business units?
facilitated workshops
Which of the following would an IS auditor perform FIRST when planning an IS audit?
gain an understanding of the business’s objectives and purpose
The approach an IS auditor should use to plan IS audit coverage should be based on:
risk
An organization performs a daily backup of critical data and software files and stores the backup tapes at an offsite location. The backup tapes are used to restore the files in case of a disruption. This is an example of a:
corrective control