ITPEC IP October 2022 Question 64
ITPEC IP October 2022 — Question 64 of 100
A system auditor contributes from an independent, professional standpoint by performing evaluation. The auditor objectively examines whether controls for information-system risks are appropriately designed and operating effectively, then reports findings and recommendations that support IT governance. Management remains responsible for implementing controls.
Answer (d)
Why not others:
- belonging to the responsible department would impair independence
- an auditor evaluates controls rather than taking management's role in implementing them
Key rule: System auditing requires organizational independence and professional judgment; its central function is objective evaluation, not operational execution.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.