IT Audit Basics MCQs 2026

20 questions with detailed answers · 11 from past papers · 2 quiz batches available

📚 Auditing Mcqs 📄 11 Past-Paper Qs ✓ Free · No Login Needed
🎯 Mock Test

Read each question, think about the answer, then click Show Answer to reveal the correct option and explanation. Load 10 at a time so it stays manageable — perfect for one-topic study sessions on the bus or during a break.

Page 1 of 1 Questions 110 of 20
  1. Q1 medium

    Regarding Change management control in IT Audit Basics, the accurate view is

    1. A direct production edit without testing
    2. B formal process for program and configuration changes
    3. C no approval for emergency always means skip all docs
    4. D developers alone push to live without review
    💡 Explanation:

    Changes tested approved and documented before production.

  2. Q2 easy

    In IT Audit Basics, IT audit primarily means

    1. A evaluation of information systems controls and data integrity
    2. B only counting warehouse boxes manually always
    3. C only painting server room
    4. D only typing letters without systems review
    💡 Explanation:

    IT audit addresses automated processing risks.

  3. Q3 easy

    Logical access review in the context of IT Audit Basics refers to

    1. A review never needed after hire day
    2. B periodic review of user IDs and privileges
    3. C only physical keys reviewed
    4. D admin accounts exempt from review
    💡 Explanation:

    Access reviews detect inappropriate permissions.

  4. Q4 medium

    Which statement about Data backup and recovery is correct

    1. A no backups ever acceptable
    2. B backup tape stored on same server only
    3. C never test restoration
    4. D controls ensuring data can be restored after failure
    💡 Explanation:

    Disaster recovery testing validates backup integrity.

  5. Q5 Past Paper · PPSC/FPSC/NTS easy

    A key aspect of Audit trail in IT systems is that it involves

    1. A electronic logs linking user actions to transactions
    2. B delete logs to save space always acceptable
    3. C no logs required in software
    4. D only paper trail valid
    💡 Explanation:

    Audit trails support fraud investigation and testing.

  6. Q6 Past Paper · PPSC/FPSC/NTS hard

    In IT Audit Basics, Cloud computing audit issues primarily means

    1. A cloud means no audit needed
    2. B auditor has automatic access to provider data always
    3. C ignore subservice organizations
    4. D data location shared tenancy and vendor control reports
    💡 Explanation:

    Cloud requires understanding provider controls.

  7. Q7 Past Paper · PPSC/FPSC/NTS medium

    IT general controls deficiency is best described as

    1. A may prevent reliance on automated application controls
    2. B never affects audit approach
    3. C always ignore and reduce substantive
    4. D only affects marketing IT
    💡 Explanation:

    ITGC weakness leads to more substantive testing.

  8. Q8 Past Paper · PPSC/FPSC/NTS hard

    Cybersecurity audit in the context of IT Audit Basics refers to

    1. A cyber never audit concern
    2. B only paper records at risk
    3. C antivirus alone sufficient always
    4. D assessing protection against ransomware phishing and data breach
    💡 Explanation:

    Cyber risks affect financial reporting integrity.

  9. Q9 Past Paper · PPSC/FPSC/NTS medium

    Regarding System development life cycle controls in IT Audit Basics, the accurate view is

    1. A buy software and use production immediately always
    2. B no user acceptance testing
    3. C skip security review
    4. D controls over new system design testing and implementation
    💡 Explanation:

    SDLC controls reduce implementation risk.

  10. Q10 Past Paper · PPSC/FPSC/NTS hard

    A key aspect of SOC report reliance is that it involves

    1. A always substitute full audit
    2. B service organization control report may support user auditor
    3. C never read SOC report
    4. D SOC replaces all testing of client
    💡 Explanation:

    Type 2 SOC reports cover period of operation.

  11. Q11 Past Paper · PPSC/FPSC/NTS medium

    ERP system audit is best described as

    1. A ERP never used in Pakistan industry
    2. B testing controls in integrated SAP Oracle or similar systems
    3. C only audit paper journal outside system
    4. D ignore automated interfaces
    💡 Explanation:

    Most large entities rely on ERP controls.

  12. Q12 Past Paper · PPSC/FPSC/NTS hard

    Which statement about Database audit is correct

    1. A examining database permissions sensitive data and audit logs
    2. B every user admin rights always
    3. C delete all logs daily
    4. D no encryption for personal data ever
    💡 Explanation:

    Database controls protect confidentiality and integrity.

  13. Q13 Past Paper · PPSC/FPSC/NTS medium

    Network security audit in the context of IT Audit Basics refers to

    1. A open WiFi to public for core banking always
    2. B never patch systems
    3. C reviewing firewalls intrusion detection and segmentation
    4. D ignore malware alerts
    💡 Explanation:

    Network controls protect against external threats.

  14. Q14 Past Paper · PPSC/FPSC/NTS medium

    A key aspect of Computer-assisted audit techniques is that it involves

    1. A using software to analyze full data populations
    2. B only manual sampling always required
    3. C prohibited by ISA
    4. D only for hackers not auditors
    💡 Explanation:

    CAATs improve coverage and efficiency.

  15. Q15 Past Paper · PPSC/FPSC/NTS easy

    Which statement about General IT controls is correct

    1. A only marketing website colours
    2. B only cafeteria software
    3. C only employee sports schedule app
    4. D controls over access program change and operations
    💡 Explanation:

    ITGC underpin application controls.

  16. Q16 easy

    A key aspect of Access controls is that it involves

    1. A user authentication authorization and periodic access review
    2. B shared admin password for all
    3. C never remove terminated user access
    4. D guest full production access always
    💡 Explanation:

    Access controls prevent unauthorized changes and viewing.

  17. Q17 medium

    Regarding Pakistan digital invoicing FBR in IT Audit Basics, the accurate view is

    1. A systems integration affects tax reporting controls audited by tax and statutory auditors
    2. B never affects accounting systems
    3. C only manual invoices forever
    4. D no IT control implications
    💡 Explanation:

    Digital invoicing increases IT dependency in tax compliance.

  18. Q18 hard

    Audit of automated controls is best described as

    1. A only test manual controls always
    2. B one sample always enough for all automated
    3. C never test system configuration
    4. D testing whether automated control operated consistently
    💡 Explanation:

    Automated control testing uses CAATs and reperformance.

  19. Q19 medium

    A key aspect of IT audit and financial audit integration is that it involves

    1. A financial auditor may use IT specialist for controls understanding
    2. B IT never relevant to FS audit
    3. C only separate IT opinion always required
    4. D ignore automated revenue system
    💡 Explanation:

    Reliance on IT controls affects substantive strategy.

  20. Q20 medium

    Regarding IT application controls in IT Audit Basics, the accurate view is

    1. A only building locks
    2. B only paper filing system
    3. C only manual calculator without integration
    4. D automated checks within systems such as edit checks and batch totals
    💡 Explanation:

    Application controls ensure complete accurate processing.