What this quiz covers
This quiz focuses on Evaluate It General Controls Itgcs, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
An auditor determines that an organization's program change controls are ineffective - developers can directly modify production code without authorization. What is the most significant implication for the financial statement audit?
CPA Isc Quiz
Practice Evaluate It General Controls Itgcs in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.
This quiz focuses on Evaluate It General Controls Itgcs, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.
An auditor determines that an organization's program change controls are ineffective - developers can directly modify production code without authorization. What is the most significant implication for the financial statement audit?
Explanation: Ineffective change controls mean automated controls could have been altered without authorization - the auditor cannot rely on them and must compensate with increased substantive testing. Answer C is correct. Input control testing (A) does not fully compensate. Prior year restatement (B) is not automatic. An adverse opinion (D) is not required solely due to ITGC weaknesses.
An auditor is evaluating ITGCs for a company subject to SOX Section 404. The auditor selects a sample of user account provisioning and termination events. For each sampled event, the auditor verifies that access was granted only to appropriate roles and terminated promptly. This procedure tests which ITGC?
Explanation: Testing the provisioning and deprovisioning of user accounts is directly testing logical access controls - the ITGC category governing who has access to systems and how access rights are managed. Answer A is correct. Account management is access control (A), not change management (B), operations (C), or development (D).
An auditor tests ITGC operating effectiveness by selecting a sample of change tickets from throughout the year and testing each for evidence of authorization, testing, and deployment segregation. The sample includes changes from all four quarters. Why is a sample covering the full year important?
Explanation: For ITGCs supporting financial reporting, controls must have operated throughout the period under audit - a sample covering all quarters provides evidence of consistent operation, not just point-in-time compliance. Answer D is correct. Statistical precision (A), change size coverage (B), and time reduction (C) are not the primary reason for full-year sampling.
An organization relies on a single IT administrator who has full administrative rights to all production systems, performs all deployments, manages user access, and responds to all incidents. From an ITGC perspective, the primary concern is:
Explanation: One person controlling all IT functions - access, changes, deployments, and operations - eliminates all segregation of duties and any possibility of independent check, representing a critical ITGC deficiency. Answer A is correct. Technical skills (B), best practices (C), and workload (D) are secondary concerns.
Which of the following best describes how ITGC testing findings affect the financial statement audit?
Explanation: ITGC deficiencies cascade into the reliance assessment for automated controls - if the IT environment cannot be trusted, the auditor must compensate with more substantive procedures to obtain assurance. Answer A is correct. Qualified opinions (B) are not automatic from ITGC deficiencies. Restatements (C) require actual financial misstatements. Management representations (D) do not resolve ITGC deficiencies.
An auditor evaluating ITGCs tests a sample of password configuration settings across financial systems. The auditor finds that three systems do not enforce the minimum password length policy. This is a finding in which ITGC category?
Explanation: Password configuration settings govern how users authenticate - enforcing password policies is a logical access control requirement that ensures authentication standards are maintained. Answer D is correct. Password settings are not development (A), operations (B), or change (C) controls.
An organization's new cloud ERP system automatically logs all user activities, access attempts, and configuration changes. How should the auditor evaluate these automated logs as part of the ITGC assessment?
Explanation: Logs are only valuable as controls if they are complete, protected from alteration, retained long enough to support investigation, and actually reviewed with follow-up - simply having logs does not confirm effective ITGC monitoring. Answer D is correct. Logs alone are not sufficient evidence (A). Cloud logs are still the organization's responsibility (B). Logs support multiple ITGC assessments beyond just access levels (C).
Which of the following most accurately describes the scope of ITGCs relevant to a financial statement audit?
Explanation: ITGC scope for financial auditing is risk-based - focused on systems that touch financial data or support relied-upon application controls. Non-financial systems are generally out of scope. Answer B is correct. All IT systems (A, D) is too broad. Only the GL system (C) may be too narrow if other systems feed financial processes.
A financial services company implements a quarterly user access review requiring managers to certify that their team members' system access rights remain appropriate. This is an example of which ITGC category?
Explanation: User access reviews and recertifications are logical access controls - they ensure that access rights remain appropriate and aligned with current job responsibilities. Answer B is correct. Program development (A) governs new system creation. Computer operations (C) governs system operation. Change controls (D) govern system modifications.
An auditor finds that an organization's ITGC framework is comprehensive but has not been updated in four years. Significant technology changes have occurred, including migration to cloud infrastructure and adoption of new ERP modules. The primary risk is:
Explanation: ITGCs must evolve with technology - a cloud migration and new ERP introduce new access paths, change mechanisms, and operational risks that the old framework may not address. Answer B is correct. Auditor impressions (A), employee familiarity (C), and maturity ratings (D) are secondary concerns.
An organization's ITGC assessment reveals that automated batch jobs run without monitoring and frequently fail without anyone noticing until business users report missing data. This represents a deficiency in which ITGC category?
Explanation: Monitoring batch job execution and responding to failures is a computer operations control responsibility. Unmonitored job failures represent an operations control deficiency. Answer B is correct. Access controls (A), change controls (C), and development controls (D) are not implicated by batch monitoring failures.
A company implements a change management control requiring that all production deployments be performed by a dedicated release management team, separate from the development team. This control addresses which ITGC risk?
Explanation: Separating development from production deployment enforces segregation of duties, preventing developers from unilaterally deploying their own code - the primary change management ITGC risk. Answer A is correct. Release team errors (B), ticket generation (C), and change request volume (D) are secondary concerns.
When evaluating ITGCs for a cloud-hosted financial system, which of the following additional considerations is unique to the cloud environment?
Explanation: Cloud environments introduce a shared responsibility model - the organization must assess whether the cloud provider's ITGCs (infrastructure access, change management, operations) are effective, typically through a SOC 1 Type II report. Answer C is correct. IT steering committees (A) and DR plans (B) apply to all environments. Application control design (D) is not cloud-specific.
Which of the following represents a program development control?
Explanation: Program development controls govern the lifecycle of new system development - design documentation, code reviews, and UAT ensure new systems are built correctly and work as intended before production deployment. Answer B is correct. Deployment approvals (A) are change controls. Batch monitoring (C) is operations. Access approval (D) is logical access.
IT general controls (ITGCs) are important to financial statement audits primarily because:
Explanation: ITGCs are the IT environment controls that underpin application controls. Weak ITGCs (e.g., poor change management) mean that automated application controls could have been modified without authorization, making their outputs unreliable. Answer B is correct. ITGCs do not directly process transactions (A). Effective ITGCs reduce but do not eliminate substantive testing (C). GAAP does not prescribe ITGCs (D).
Which of the following is an example of a computer operations control?
Explanation: Computer operations controls govern the day-to-day operation of IT systems - job scheduling, batch monitoring, operations logs, and incident response. Answer D is correct. Deployment approval (A) is a change control. Database access restriction (B) is a logical access control. Design review (C) is a program development control.
When evaluating the design of ITGCs, an auditor finds that the organization has no formal segregation of duties between developers and production system administrators. The most significant risk is:
Explanation: Without segregation between development and production, developers can implement unauthorized code directly in production - a fundamental ITGC control failure that compromises all downstream application controls. Answer C is correct. Technical skills (A), business requirements (B), and best practice compliance (D) are secondary concerns compared to the unauthorized change risk.
During an ITGC assessment, an auditor finds that the organization's production database has 47 active user accounts belonging to former employees. The most appropriate audit finding is:
Explanation: Active accounts for terminated employees is a logical access control deficiency - the offboarding process failed to revoke access, creating unauthorized access risk. Answer D is correct. This is not an operations (A), development (B), or change control (C) issue.
Which of the following best describes the relationship between ITGCs and automated application controls?
Explanation: Effective ITGCs (especially change controls and access controls) provide assurance that automated application controls have not been tampered with, enabling greater reliance. Weak ITGCs undermine automated control reliability. Answer B is correct. They are interdependent (A). ITGCs underpin application controls (C). Weak ITGCs cannot be fully compensated by strong automated controls (D).
Computer operations controls include which of the following activities?
Explanation: Computer operations controls govern the day-to-day running of IT infrastructure - batch scheduling, job monitoring, capacity management, and operational logging. Answer C is correct. Code review (A) is development. Access approvals (B) are logical access. Change approvals (D) are change management.