System Audit

System Audit

40 questions · IT Passport

Practice

Which of the following is the most appropriate explanation of IT governance?

It was decided to conduct a system audit and an audit team was formed accordingly. Which of the following is a common requirement for all auditors who participate in the team?

Among the descriptions A through D concerning the concept of internal control, which of the following is the list that contains all appropriate descriptions?

AComplying with the laws, etc. concerning business activities to promote the business activities conforming to social norms is one of the objectives of internal control.BWhile complying with the laws, etc. concerning business activities is one of the objectives of internal control, promotion of business activities conforming to social norms is not required.CThe concept of internal control is effective in non-listed companies too, and it is necessary to work on it.DThe concept of internal control is necessary only in listed companies.

In a company, which of the following is responsible for the establishment of IT governance?

A food manufacturer is conducting business in accordance with food industry safety standards. As the safety standards are revised, the internal standards of the company are also revised accordingly. Which of the following objectives of internal control corresponds to this action?

Which of the following is the most appropriate objective of an accounting audit?

Which of the following is the appropriate explanation of a system audit?

Regarding the roles (i) through (iv) below for establishing appropriate IT governance, which of the following is the appropriate combination of the roles of the company executive responsible for it and the person responsible for the information system department?

(i)Defining the IT governance policy(ii)Formulating principles for decisions on investment in computerization(iii)Deciding the roles and the rights within the information system department(iv)Performing progress management in system development on the basis of a project plan
OptionThe company executiveThe person responsible for the information system department

Which of the following is the initiative that is composed of control environment, risk assessment, control activities, information and communication, and monitoring activities, and has compliance with laws and regulations relating to the business activities as one of its objectives?

Among company rules, which of the following is the rule that describes segregation of duties?

Which of the following is an appropriate description of the targets of a system audit?

Which of the following is the term for the assignment of employees’ role that applies mutual checks among employees for the purpose of reducing the risk of misconduct or errors in work from the standpoint of internal control?

The information system department implements the development and operation of the order entry system and the accounting system. The user of the order entry system is the sales department and the user of the accounting system is the accounting department. Which of the following is the appropriate description concerning internal control of financial reports?

Which of the following is an appropriate explanation of monitoring in internal control?

Which of the following is an appropriate measure to enable internal controls?

Which of the following is an appropriate description of the roles of a system auditor?

Types of governance within a company include IT governance and corporate governance. Which of the following is an appropriate explanation of the positioning of IT governance?

When an external systems auditor conducts a systems audit of a company as an outsourcing service, which of the following is an appropriate action by the external systems auditor?

Which of the following is a process where a third party inspects and evaluates the security and reliability of the information system of a company, and if necessary, the third party makes suggestions and recommendations to the party being inspected and evaluated.

Several functions are implemented for internal control by the system. Which of the following is the appropriate function that the process below implements?

  The login screen is displayed. A user enters the user ID and the password. If the combination of the user ID and the password matches the already-registered combination, the screen transits to the business menu screen. If not, the screen does not transit, and an error message is displayed.

Which of the following is the most appropriate control on the development and implementation of an information systems strategy for improving the competitiveness of a company?

Which of the following is an appropriate explanation of monitoring in internal control?

With the purpose of shortening the business processing time, the throughput of a business system was improved. When a systems audit is performed to evaluate if the improvement is effective, which of the following is the appropriate information to be requested by the system auditor to the operations department?

Which of the following is an appropriate measure to implement internal controls function?

Which of the following is the appropriate combination of terms or phrases to be inserted into blanks A and B in the description below concerning the purpose of system audits?

With regard to the appropriate design and operation of the control for risks concerning information systems, the system auditor A contributes to the realization of IT governance by performing B.

OptionAB

During a systems audit, systems auditors who are independent of the audit target inspect and evaluate the information systems comprehensively from an objective viewpoint. As a result of the systems audit requested by the management of a company, some problems are found in the effectiveness of the current information systems. Who are the most appropriate persons to whom the systems auditor gives advice and makes recommendations?

Which of the following is the most appropriate regulation for developing and implementing an information systems strategy for improving the competitiveness of a company?

The activities of a systems audit are divided into the processes of drafting of an audit plan, acquisition and evaluation of audit evidence, implementation of audit procedures, creation of an audit report, and followup. Which of the following processes gives guidance to auditee on the implementation of appropriate actions for improvement?

Among rules for the organizational operation of a company, which of the following describe separation of job duties?

Which of the following is the purpose of systems audit?

Which of the following persons are responsible for building and promoting IT governance in a company?

Which of the following is an appropriate measure to implement internal controls function?

Which of the following is an appropriate document prepared by an audited department after a system audit in response to the evaluation results?

When an audit that is performed by an auditor is divided into an accounting audit, a business operations audit, a systems audit, and an information security audit, which of the following is the most appropriate description of the business operations audit?

Company A’s internal auditors conduct a system audit concerning the company’s BCP (Business Continuity Plan). The system audit found in the backup measures for computer power supplies that some of the batteries in the uninterruptible power supplies managed by the System Operations Department are deteriorated. Which of the following is the party responsible for making improvements in response to the finding?

Which of the following is the most appropriate phrase to be inserted in blank A in the description below concerning IT control in a company?

A company formulates an effective IT strategy, aiming to A of the organization according to its business strategy, and establishes the life cycle of planning, development, operation, and maintenance of the information systems on the basis of this IT strategy. In order to reduce the risks surrounding the information systems, IT controls are implemented and operated.

IT controls are classified into IT application controls and IT general controls. IT application controls refer to the control activities for ensuring that all approved business operations in the system for managing business operations are processed and recorded appropriately. IT general controls refer to the control activities for guaranteeing the environment in which each IT application control functions effectively. Which of the following controls in a company that performs development and operation of its in-house systems, such as the purchase management system, corresponds to IT application controls?

A system auditor is required to have an independent and professional standpoint. When a system audit is performed in a company, which of the following is the example that contradicts with the independence of the system auditor?

Which of the following is an appropriate combination of words to be inserted into blanks A and B in the description below concerning the implementation of internal control?

The implementation of internal control requires A, separation of duties, setting of rules and procedures, and B.

OptionAB

Which of the following is an appropriate description concerning evaluations in systems audit?