ITPEC IP October 2025 Question 65
ITPEC IP October 2025 — Question 65 of 100
Internal control consists of the five listed components and includes legal and regulatory compliance among its objectives — the description matches the internal-control framework.
A control environment provides the foundation; risk assessment identifies and analyzes threats to objectives; control activities implement responses; information and communication support action; and monitoring checks whether controls continue to work.
Answer (c)
Why not others:
- (a) CMMI is a process-improvement maturity model
- (b) ITIL provides guidance and practices for IT service management
- (d) Risk management is related, but it does not by itself name this five-component organizational control framework
Key rule: Recognize internal control by its objectives and the five components: environment, risk assessment, activities, information and communication, and monitoring.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.