ITPEC IP October 2025 Question 63
ITPEC IP October 2025 — Question 63 of 100
A system audit independently verifies whether controls over information-system risks are properly implemented and operated — option (b) states its essential purpose.
The auditor gathers objective evidence, compares governance and controls with appropriate criteria, evaluates effectiveness, and reports findings and recommendations. Independence from the activities being audited supports reliable conclusions.
Answer (b)
Why not others:
- (a) describes an IT service-management framework such as ITIL
- (c) describes software-engineering methods and development technology
- (d) is the definition of project management, applying knowledge and techniques to meet project requirements
Key rule: Management establishes and operates controls; a system auditor independently evaluates whether those controls manage information-system risks appropriately.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.