Domain 3: Information Systems Acquisition, Development, and Implementation - PART 3A Flashcards

1
Q

Assignment of process ownership is essential in system development projects because it:

A

ensures that system design is based on business needs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Before implementing controls in a newly developed system, management should PRIMARILY ensure that the controls:

A

satisfy a requirement in addressing a risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The BEST time for an IS auditor to assess the control specifications of a new application software package which is being considered for acquisition is during:

A

during the requirements gathering process.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A company has implemented a new client- server enterprise resource planning (ERP) system. Local branches transmit customer orders to a central manufacturing facility. Which of the following would BEST ensure that the orders are processed accurately, and the corresponding products are produced?

A

Verifying production of customer orders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A company’s development team does not follow generally accepted system development life cycle practices. Which of the following is MOST likely to cause problems for software development projects?

A

Project responsibilities are not formally defined at the beginning of a project.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A company undertakes a business process reengineering project in support of a new and direct marketing approach to its customers. Which of the following would be an IS auditor’s main concern about the new process?

A

Whether key controls are in place to protect assets and information resources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The development of an application has been outsourced to an offshore vendor. Which of the following should be of GREATEST concern to an IS auditor?

A

The business case was not established.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Documentation of a business case used in an IT development project should be retained until:

A

the end of the system’s life cycle.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Due to a reorganization, a business application system will be extended to other departments. Which of the following should be of the GREATEST concern for an IS auditor?

A

Process owners have not been identified.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

During a system development life cycle audit of a human resources and payroll application, the IS auditor notes that the data used for user acceptance testing have been masked. The purpose of masking the data is to ensure the:

A

confidentiality of the data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

During the audit of an acquired software package, an IS auditor finds that the software purchase was based on information obtained through the Internet, rather than from responses to a request for proposal. The IS auditor should FIRST:

A

ensure that the procedure had been approved.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

During the review of a web-based software development project, an IS auditor realizes that coding standards are not enforced, and code reviews are rarely carried out. This will MOST likely increase the likelihood of a successful:

A

buffer overflow.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The editing/validation of data entered at a remote site is performed MOST effectively at the:

A

remote processing site PRIOR to transmission of the data to the central processing site.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

An enterprise is developing a strategy to upgrade to a newer version of its database software. Which of the following tasks can an IS auditor perform without compromising the objectivity of the IS audit function?

A

Review the acceptance test case documentation BEFORE the tests are carried out.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Following good practices, formal plans for implementation of new information systems are developed during the:

A

Design Phase.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Information for detecting unauthorized input from a user workstation would be BEST provided by the:

A

transaction journal.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

An IS auditor assesses the project management process for an internal software development project. In respect to the software functionality, the IS auditor should look for sign-off by:

A

business unit management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

An IS auditor has been asked to participate in project initiation meetings for a critical project. The IS auditor’s MAIN concern should be that the:

A

complexity and risk associated with the project have been analyzed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

An IS auditor has found time constraints and expanded needs to be the root causes for recent violations of corporate data definition standards in a new business intelligence project. Which of the following is the MOST appropriate suggestion for an auditor to make?

A

Achieve standards alignment through an increase of resources devoted to the project.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

An IS auditor invited to a project development meeting notes that no project risk has been documented. When the IS auditor raises this issue, the project manager responds that it is too early to identify risk and that, if risk starts impacting the project, a risk manager will be hired. The appropriate response of the IS auditor would be to:

A

Stress the importance of spending time at this point in the project to consider and DOCUMENT risk and to develop contingency plans.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

An IS auditor is assigned to audit a software development project, which is more than 80 percent complete, but has already overrun time by 10 percent and costs by 25 percent. Which of the following actions should the IS auditor take?

A

Review the business case and project management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

An IS auditor is performing a post- implementation review of an organization’s system and identifies output errors within an accounting application. The IS auditor determined this was caused by input errors. Which of the following controls should the IS auditor recommend to management?

A

Limit checks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

An IS auditor is reviewing IT projects for a large company and wants to determine whether the IT projects undertaken in a given year are those which have been assigned the highest priority by the business and which will generate the greatest business value. Which of the following is MOST relevant?

A

Portfolio management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

An IS auditor is reviewing the software development capabilities of an organization that has adopted the agile methodology. The IS auditor would be the MOST concerned if:

A

certain project iterations produce proof-of- concept deliverables and unfinished code.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

An IS auditor performing a review of a major software development project finds that it is on schedule and under budget even though the software developers have worked considerable amounts of unplanned overtime. The IS auditor should:

A

investigate further to determine whether the project plan may not be accurate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

An IS auditor recommends that an initial validation control be programmed into a credit card transaction capture application. The initial validation process would MOST likely:

A

verify the format of the number entered, then locate it on the database.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

An IS auditor reviewing a proposed application software acquisition should ensure that the:

A

product is compatible with the current or planned OS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

An IS auditor reviewing a series of completed projects finds that the implemented functionality often exceeded requirements and most of the projects ran significantly over budget. Which of these areas of the organization’s project management process is the MOST likely cause of this issue?

A

Project scope management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

An IS auditor reviewing the IT project management process is reviewing a feasibility study for a critical project to build a new data center. The IS auditor is MOST concerned about the fact that:

A

the organizational impact of the project has not been assessed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

An IS auditor who is auditing the software acquisition process will ensure that the:

A

contract is reviewed and approved by the legal counsel before it is signed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

A large industrial organization is replacing an obsolete legacy system and evaluating whether to buy a custom solution or develop a system in-house. Which of the following will MOST likely influence the decision?

A

Technical skills and knowledge within the organization related to sourcing and software development

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

The MAIN purpose of a transaction audit trail is to:

A

determine accountability and responsibility for processed transactions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

The MAJOR advantage of a component- based development approach is the:

A

support of multiple development environments.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

The MAJOR consideration for an IS auditor reviewing an organization’s IT project portfolio is the:

A

business plan.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Management observed that the initial phase of a multiphase implementation was behind schedule and over budget. Prior to commencing with the next phase, an IS auditor’s PRIMARY suggestion for a postimplementation focus should be to:

A

review the impact of program changes made during the first phase on the remainder of the project.

36
Q

Many IT projects experience problems because the development time and/or resource requirements are underestimated. Which of the following techniques provides the GREATEST assistance in developing an estimate of project duration?

A

Program evaluation review technique chart

37
Q

The most common reason for the failure of information systems to meet the needs of users is that:

A

user participation in defining the system’s requirements was inadequate.

38
Q

Normally, it would be essential to involve which of the following stakeholders in the initiation stage of a project?

A

System owners

39
Q

Once an organization has finished the business process reengineering (BPR) of all its critical operations, an IS auditor would MOST likely focus on a review of:

A

post-BPR process flowcharts.

40
Q

An organization implemented a distributed accounting system, and the IS auditor is conducting a postimplementation review to provide assurance of the data integrity controls. Which of the following choices should the auditor perform FIRST?

A

Review the data flow diagram.

41
Q

An organization is implementing an enterprise resource planning application. Of the following, who is PRIMARILY responsible for overseeing the project to ensure that it is progressing in accordance with the project plan and that it will deliver the expected results?

A

Project steering committee

42
Q

An organization sells books and music online at its secure web site. Transactions are transferred to the accounting and delivery systems every hour to be processed. Which of the following controls BEST ensures that sales processed on the secure web site are transferred to both the delivery and accounting systems?

A

Transactions are automatically numerically sequenced. Sequences are checked and gaps in continuity are accounted for.

43
Q

The phases and deliverables of a system development life cycle project should be determined:

A

during the initial planning stages of the project.

44
Q

A project manager for a project that is scheduled to take 18 months to complete announces that the project is in a healthy financial position because, after six months, only one-sixth of the budget has been spent. The IS auditor should FIRST determine:

A

the amount of progress achieved compared to the project schedule.

45
Q

The project steering committee is ultimately responsible for:

A

project deliverables, costs and timetables

46
Q

A proposed transaction processing application will have many data capture sources and outputs in paper and electronic form. To ensure that transactions are not lost during processing, an IS auditor should recommend the inclusion of:

A

automated systems balancing.

47
Q

A rapid application development methodology has been selected to implement a new enterprise resource planning system. All of the project activities have been assigned to the contracted consulting company because internal employees are not available. What is the IS auditor’s FIRST step to compensate for the lack of resources?

A

Review the project plan and approach.

48
Q

The reason for establishing a stop or freezing point on the design of a new system is to:

A

require that changes after that point be evaluated for cost- effectiveness.

49
Q

To minimize the cost of a software project, quality management techniques should be applied:

A

continuously throughout the project with an emphasis on finding and fixing defects primarily through testing to maximize the defect detection rate.

50
Q

wo months after a major application implementation, management, who assume that the project went well, requests that an IS auditor perform a review of the completed project. The IS auditor’s PRIMARY focus should be to:

A

review controls built into the system to assure that they are operating as designed.

51
Q

The use of object-oriented design and development techniques would MOST likely:

A

facilitate the ability to reuse modules.

52
Q

The waterfall life cycle model of software development is most appropriately used when:

A

requirements are well understood and are expected to remain stable, as is the business environment in which the system will operate.

53
Q

When auditing the proposed acquisition of a new computer system, an IS auditor should FIRST ensure that:

A

a clear business case has been approved by management.

54
Q

When identifying an earlier project completion time, which is to be obtained by paying a premium for early completion, the activities that should be selected are those:

A

that have zero slack time.

55
Q

When implementing an application software package, which of the following presents the GREATEST risk?

A

Incorrectly set parameters

56
Q

When planning to add personnel to tasks imposing time constraints on the duration of a project, which of the following should be revalidated FIRST?

A

The critical path for the project

57
Q

When preparing a business case to support the need of an electronic data warehouse solution, which of the following choices is the MOST important to assist management in the decision-making process?

A

Demonstrate feasibility.

58
Q

When reviewing an active project, an IS auditor observed that the business case was no longer valid because of a reduction in anticipated benefits and increased costs. The IS auditor should recommend that the:

A

business case be updated and possible corrective actions be identified.

59
Q

When reviewing a project where quality is a major concern, an IS auditor should use the project management triangle to explain that:

A

increases in quality can be achieved, if resource allocation is decreased.

60
Q

Which of the following BEST helps an IS auditor evaluate the quality of programming activities related to future maintenance capabilities?

A

Program coding standards

61
Q

Which of the following BEST helps ensure that deviations from the project plan are identified?

A

Project performance criteria

62
Q

Which of the following BEST helps to prioritize project activities and determine the time line for a project?

A

Program evaluation review technique

63
Q

Which of the following considerations is the MOST important while evaluating a business case for the acquisition of a new accounting application?

A

Return on investment to the company

64
Q

Which of the following controls helps prevent duplication of vouchers during data entry?

A

A sequence check

65
Q

Which of the following data validation edits is effective in detecting transposition and transcription errors?

A

Check digit

66
Q

Which of the following is a characteristic of timebox management?

A

Prevents cost overruns and delivery delays

67
Q

Which of the following is an advantage of prototyping?

A

Prototype systems can provide significant time and cost savings.

68
Q

Which of the following is MOST relevant to an IS auditor evaluating how the project manager has monitored the progress of the project?

A

Gantt charts

69
Q

Which of the following is the BEST method of controlling scope creep in a system development project?

A

Establishing a software baseline

70
Q

Which of the following is the GREATEST risk to the effectiveness of application system controls?

A

Collusion between employees

71
Q

Which of the following is the most important element in the design of a data warehouse?

A

Quality of the metadata

72
Q

Which of the following is the MOST likely benefit of implementing a standardized infrastructure?

A

Improved cost- effectiveness of IT service delivery and operational support

73
Q

Which of the following should an IS auditor review to gain an understanding of the effectiveness of controls over the management of multiple projects?

A

Project portfolio database

74
Q

Which of the following should an IS auditor review to understand project progress in terms of time, budget and deliverables for early detection of possible overruns and for projecting estimates at completion?

A

Earned value analysis

75
Q

Which of the following should be an IS auditor’s PRIMARY concern after discovering that the scope of an IS project has changed, and an impact study has not been performed?

A

The time and cost implications caused by the change

76
Q

Which of the following should be developed during the requirements definition phase of a software development project to address aspects of software testing?

A

User acceptance test specifications

77
Q

Which of the following should be included in a feasibility study for a project to implement an electronic data interchange process?

A

The necessary communication protocols

78
Q

Which of the following techniques would BEST help an IS auditor gain reasonable assurance that a project can meet its target date?

A

Extrapolation of the overall end date based on completed work packages and current resources

79
Q

Which of the following types of risk could result from inadequate software baselining?

A

Scope creep

80
Q

Which of the following types of risk is MOST likely encountered in a software as a service environment?

A

Performance issues due to Internet delivery method

81
Q

Which of the following will BEST ensure the successful offshore development of business applications?

A

Detailed and correctly applied specifications

82
Q

Which of the following would be the MOST cost-effective recommendation for reducing the number of defects encountered during software development projects?

A

Implement formal software inspections.

83
Q

While evaluating the “out of scope” section specified in a project plan, an IS auditor should ascertain whether the section:

A

effectively describes project boundaries.

84
Q

While reviewing an ongoing project, the IS auditor notes that the development team has spent eight hours of activity on the first day against a budget of 24 hours (over three days). The projected time to complete the remainder of the activity is 20 hours. The IS auditor should report that the project:

A

is behind schedule.

85
Q

Who should review and approve system deliverables as they are defined and accomplished to ensure the successful completion and implementation of a new business system application?

A

User Management