M03_Risk assessment –IT understanding

M03_Risk assessment – IT understanding

Professional Development

6 Qs

quiz-placeholder

Similar activities

Module 5: Halal Internal Audit Facilitation (Day 8)

Module 5: Halal Internal Audit Facilitation (Day 8)

Professional Development

10 Qs

M07_Information used in the audit

M07_Information used in the audit

Professional Development

9 Qs

BDM/SSC Christmas Party Trivia

BDM/SSC Christmas Party Trivia

Professional Development

10 Qs

Activity 1

Activity 1

Professional Development

10 Qs

The car quiz

The car quiz

KG - Professional Development

10 Qs

Access quiz by Simar Brahma :D

Access quiz by Simar Brahma :D

5th Grade - Professional Development

10 Qs

old exam 2017 (INFS)

old exam 2017 (INFS)

University - Professional Development

10 Qs

Q-iCORE

Q-iCORE

Professional Development

10 Qs

M03_Risk assessment –IT understanding

M03_Risk assessment – IT understanding

Assessment

Quiz

Other

Professional Development

Medium

Created by

Lily Lin

Used 1+ times

FREE Resource

6 questions

Show all answers

1.

MULTIPLE SELECT QUESTION

1 min • 1 pt

M03Q1. During your audit engagements, what layers of technology do you commonly identify as relevant? Select all that apply.

Application

Database

Operating system

Network

2.

MULTIPLE SELECT QUESTION

1 min • 1 pt

M03Q2. Based on the scenario presented, which layers would be considered relevant to risk assessment?

Application, Database and Operating System.

Application and Operating System.

Application and Database

Database and Operating System

3.

MULTIPLE SELECT QUESTION

1 min • 1 pt

M03Q3. What areas does the engagement team document in the IT Understanding Screen?

How the entity uses IT as part of financial reporting and related business processes.

The entity’s IT organization.

The entity’s IT policies and procedures.

All of the above.

4.

MULTIPLE SELECT QUESTION

2 mins • 1 pt

M03Q4. When do we use the SSC instructions and reporting templates in KAEG?

To document your evaluation of a service organization controls (SOC) report.

To communicate the nature, timing and extent of procedures performed by the SSC auditor on behalf of the group engagement team and/or SSC user auditors.

When a SOC report is not provided by the Service Organization.

When the SSC auditor identifies issues that may require an audit response.

5.

MULTIPLE SELECT QUESTION

45 sec • 1 pt

M03Q5. Did you find it easy navigating KAEG?

Yes

No

6.

MULTIPLE SELECT QUESTION

2 mins • 1 pt

M03Q6. When do we involve a team member with specialization in IT in response to a cybersecurity incident?

When an exception is noted during your testing of database access.

If an interface from an external source does not successfully complete.

When a cybersecurity incident at any layer comes to your attention during the audit.

When an terminated employee retains access privileges to a financially relevant application.