Skip to content

CMA Final · Cost and Management Audit · Information Systems Security Audit

Which audit technique involves the auditor processing test transactions with known expected results through the client's live application to verify that its programmed controls work correctly?

The test data technique is described. The auditor submits prepared valid and invalid transactions with known expected outcomes through the client's application and compares actual outputs to expectations, confirming that programmed controls operate. Audit software analyses existing files, and observation or inquiry gives weaker evidence about application logic.

  1. ATest data techniqueCorrect
  2. BGeneralised audit software extraction of the master file
  3. CObservation of the server room
  4. DInquiry of the IT manager

Explanation

The test data technique feeds the auditor's prepared transactions, including invalid ones, through the application and compares outputs with expected results. Audit software analyses existing data, while observation and inquiry do not directly test programmed controls.

Did you get it right without looking?

One question tells you little. A timed set on Information Systems Security Audit shows your real accuracy, how long you take and where you lose marks.

More Information Systems Security Audit questions