Podcast
Questions and Answers
What is the purpose of control monitoring?
What is the purpose of control monitoring?
- To identify where active monitoring may be useful
- To check if the control itself is operational
- To ensure compliance with enterprise policies only
- To verify whether the control is effectively addressing the risk (correct)
How should the monitoring of controls be based?
How should the monitoring of controls be based?
- On irrelevant data
- On irrelevant data or through self-assessment
- On data that are relevant to the risk and overall performance (correct)
- On data that are not relevant to the risk and overall performance
When risk action plans are required, what should be monitored?
When risk action plans are required, what should be monitored?
- Appropriate risk management practices in alignment with enterprise risk appetite and tolerance (correct)
- The effectiveness of the firewall
- Control requirements
- Employee compliance with policies
How is control monitoring conducted?
How is control monitoring conducted?
What is the main benefit of continuous audit techniques?
What is the main benefit of continuous audit techniques?
Which type of automated evaluation technique embeds specially written audit software in the enterprise host application system?
Which type of automated evaluation technique embeds specially written audit software in the enterprise host application system?
How do continuous audit techniques affect the confidence in the reliability of an IT system?
How do continuous audit techniques affect the confidence in the reliability of an IT system?
What is the purpose of snapshots as an automated evaluation technique?
What is the purpose of snapshots as an automated evaluation technique?
What is the purpose of the integrated test facility (ITF) technique?
What is the purpose of the integrated test facility (ITF) technique?
What is the main function of audit hooks in application systems?
What is the main function of audit hooks in application systems?
What does continuous and intermittent simulation (CIS) involve during a process run of a transaction?
What does continuous and intermittent simulation (CIS) involve during a process run of a transaction?
How does an IT auditor verify the correctness of computer-processed data using the ITF technique?
How does an IT auditor verify the correctness of computer-processed data using the ITF technique?