Home › Certifications › CPA ISC › Internal controls
28 multiple-choice questions and 24 flashcards on Internal controls, about 7% of the CPA ISC bank. Every one carries a written rationale.
Internal controls is one of 5 chapters in CoStudy's CPA — Information Systems & Controls (ISC) [Discipline] bank, and it holds 28 of the bank's 378 multiple-choice questions — roughly 7% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.
Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.
7 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.
An organization discovers during an ITGC review that its change management process (a general control) has weaknesses, and a related automated application control (three-way match) has not been retested since a system upgrade. Combining IT audit sampling and ITGC concepts, the auditor should MOST reasonably:
Answer: B — Recognize that the ITGC weakness (change management) undermines the basis for relying on the automated control without retesting after the upgrade, and extend testing or reduce reliance accordingly
A) Continuing full reliance without retesting after a system upgrade, especially with a known change management weakness, is unsupported — the upgrade itself is a change that should trigger reassessment. B) Correct — a weak change management ITGC combined with an untested post-upgrade automated control means the auditor can't safely assume continued effectiveness; the appropriate response is to extend testing (retest the control post-upgrade) or reduce reliance and increase substantive procedures accordingly. C) Concluding the audit without addressing this identified gap would leave a material audit risk unaddressed. D) Assuming no impact from the upgrade without evidence directly contradicts the auditor's professional skepticism obligation, especially given the known ITGC weakness.
Application controls are automated controls that are:
Answer: D — Applied within a specific application to ensure processing is complete, accurate, and authorized
A) Firewalls are network controls, not application controls. B) Hypervisor isolation is an infrastructure control, not an application control. C) Badge readers are physical controls, not application controls. D) Correct — application controls target specific app processing objectives.
A key SDLC control objective regardless of methodology (waterfall or Agile) is to ensure that:
Answer: B — Changes are appropriately tested, reviewed/approved, and documented before being promoted to the production environment
A) Allowing developers unilateral production deployment without independent review undermines segregation of duties, a core control objective regardless of methodology. B) Correct — across both waterfall and Agile, a fundamental SDLC control objective is ensuring changes are tested, appropriately reviewed/approved, and documented before reaching production, protecting against errors and unauthorized changes. C) Skipping testing based solely on developer confidence contradicts the standard requirement for independent verification before production deployment. D) Leaving documentation entirely discretionary undermines auditability and knowledge transfer, both important SDLC control considerations.
The primary control objective of change management is to ensure that:
Answer: D — Changes are authorized, tested, and migrated with proper segregation
A) Skipping approval defeats the control. B) Emergency changes still need post-hoc approval — never blanket bypass. C) That violates segregation of duties between dev and prod. D) Correct — the objective is authorized, tested, segregated migration to prod.
An organization designing its identity governance program for a system with strong SoD requirements (e.g., financial transaction processing) should combine which practices?
Answer: A — Role-based birthright access provisioning at hire, ongoing periodic access recertification, and explicit SoD conflict detection rules within the access request/approval workflow
A) Correct — a robust SoD-aware identity governance program combines appropriate initial role-based provisioning, ongoing recertification to catch drift over time, and explicit conflict-detection logic to prevent incompatible combined access from being granted in the first place. B) Granting universal admin access is the opposite of an SoD-conscious design and would create severe control weaknesses. C) A one-time review at hire fails to catch subsequent role changes or accumulated access that could create SoD conflicts over time. D) Disabling access-change logging would eliminate a critical audit trail needed to detect and investigate SoD violations, undermining the entire control objective.
An organization's IT audit function notes that automated application controls have historically required less extensive sample sizes than manual controls for the same assurance level. This is because:
Answer: B — A properly functioning automated control processes every instance consistently (absent a change), reducing the variability that drives larger sample sizes for human-performed manual controls
A) Automated controls still require testing; they aren't exempt from audit procedures. B) Correct — because automated controls apply the same logic consistently to every transaction absent a configuration change, the auditor can gain assurance about the entire population from testing a smaller number of instances (plus IT general controls around changes), unlike manual controls subject to human variability requiring larger samples. C) Automated controls are often HIGHLY significant to financial reporting reliability, not inherently less important than manual controls. D) Sample size approaches specifically DO depend on the nature of the control (automated vs. manual) being tested, contradicting this option.
Embedded audit modules are code inserted into the client's application to:
Answer: D — Continuously flag transactions meeting auditor-specified criteria for later independent review
A) That is encryption, not embedded audit modules. D) Correct — embedded modules flag transactions for auditor review. C) That is backup, not audit modules. B) That is patching, not audit modules.
3 cards from the 24 in this chapter.
Compensating control?
Alternative control when primary control isn't feasible (e.g., review reports when SOD impossible).
SDLC phases?
Planning → analysis → design → implementation → testing → deployment → maintenance.
CSPM + NGFW + ITGC attribute sampling + TPRM used together — overarching lesson?
Effective technology risk management requires multiple complementary tools spanning cloud, network, controls testing, and vendor management.
These are a sample. The full Internal controls chapter runs 52 items with per-chapter progress tracking, on the web and in the iOS app.