CMA Final · Cost and Management Audit · Information Systems Security Audit
Which audit technique involves the auditor processing test transactions with known expected results through the client's live application to verify that its programmed controls work correctly?
The test data technique is described. The auditor submits prepared valid and invalid transactions with known expected outcomes through the client's application and compares actual outputs to expectations, confirming that programmed controls operate. Audit software analyses existing files, and observation or inquiry gives weaker evidence about application logic.
- ATest data techniqueCorrect
- BGeneralised audit software extraction of the master file
- CObservation of the server room
- DInquiry of the IT manager
Explanation
The test data technique feeds the auditor's prepared transactions, including invalid ones, through the application and compares outputs with expected results. Audit software analyses existing data, while observation and inquiry do not directly test programmed controls.
Did you get it right without looking?
One question tells you little. A timed set on Information Systems Security Audit shows your real accuracy, how long you take and where you lose marks.
More Information Systems Security Audit questions
- Which of the following is an example of a logical access control, as distinct from a physical access control?
- During an audit of a firm's ERP, the auditor wants to test whether application controls correctly reject invalid data, using the company's l…
- An auditor reviewing a company's disaster recovery plan finds that backups are taken daily but have never been restored in a test. Which con…
- Which of the following best describes the purpose of a 'segregation of duties' control in a computerised cost accounting environment?
- A firm's disaster recovery plan states that after an outage, systems must be running within 4 hours, and that no more than 30 minutes of tra…
- An auditor finds that a cost accounting application's database administrator can also approve journal entries and delete audit log records. …