CMA Final · Cost and Management Audit · Information Systems Security Audit
Which of the following is an example of an application control rather than a general IT control?
A system check that rejects an invoice when billed quantity exceeds the goods receipt quantity is an application control, because it works inside a specific application to validate transactions. Physical access limits, password policies and change management apply across the whole IT environment and are general controls.
- ARestricting physical access to the server room
- BA check that rejects a purchase invoice if the quantity billed exceeds the quantity on the goods receipt noteCorrect
- CPolicy for periodic change of operating system passwords
- DChange management procedure for migrating programs to production
Explanation
Application controls operate within a specific application to ensure accuracy and validity of transactions, such as matching billed and received quantities. Physical access, password policy and change management apply across the IT environment and are general controls.
Did you get it right without looking?
One question tells you little. A timed set on Information Systems Security Audit shows your real accuracy, how long you take and where you lose marks.
More Information Systems Security Audit questions
- An auditor finds that a cost accounting application's database administrator can also approve journal entries and delete audit log records. …
- During an IS security audit at a manufacturing company in Pune, the auditor finds that several former employees' user IDs remain active in t…
- Which of the following best describes the purpose of a 'segregation of duties' control in a computerised cost accounting environment?
- During an IS audit of a manufacturing company's ERP, the auditor wants to confirm that a programmer cannot both modify production code and m…
- An auditor reviewing a company's ERP finds that the same employee can create a vendor master record, approve purchase orders to that vendor …
- In an information systems security audit, which control is a preventive control rather than a detective or corrective one?