ITPEC IP October 2024 Question 65
ITPEC IP October 2024 — Question 65 of 100
A system auditor independently verifies whether information-system risks are controlled appropriately and effectively, then reports the results to the client. Independence and objectivity allow the auditor to gather evidence, compare conditions with audit criteria, identify findings, and communicate an evaluation without taking operational responsibility for the audited area.
Answer (c)
Why not others:
- (a) designing workflows and installing the system are management or implementation responsibilities
- (b) operating monitoring mechanisms and taking operational action belong to the responsible department
- (d) setting policy, objectives, and the management system is senior management's role
Key rule: Auditors evaluate and report independently; management designs, implements, operates, and owns the controls.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.