Skip to content

CMA Final · Cost and Management Audit · Information Systems Security Audit

Which of the following is an example of an application control rather than a general IT control?

A system check that rejects an invoice when billed quantity exceeds the goods receipt quantity is an application control, because it works inside a specific application to validate transactions. Physical access limits, password policies and change management apply across the whole IT environment and are general controls.

  1. ARestricting physical access to the server room
  2. BA check that rejects a purchase invoice if the quantity billed exceeds the quantity on the goods receipt noteCorrect
  3. CPolicy for periodic change of operating system passwords
  4. DChange management procedure for migrating programs to production

Explanation

Application controls operate within a specific application to ensure accuracy and validity of transactions, such as matching billed and received quantities. Physical access, password policy and change management apply across the IT environment and are general controls.

Did you get it right without looking?

One question tells you little. A timed set on Information Systems Security Audit shows your real accuracy, how long you take and where you lose marks.

More Information Systems Security Audit questions