OCEG
GRCA
Q1:
The two kinds of PROACTIVE controls are
○
A
training and education○
B
promoting and preventive○
C
access and system
OCEG
GRCA
Q2:
During Assessment Planning, it is important to conduct a complete risk assessment and conduct detailed testing to understand inherent risks and control risk.
○
A
True. Everything needs to be fully understood before a plan can be finalized.○
B
False. Limited information gathering and procedures should be conducted to get an initial estimate of inherent risk and control risk so that planning can proceed.
OCEG
GRCA
Q3:
What level of assurance is required for an assessment?
○
A
Medium○
B
High○
C
Low○
D
An assessment may target any level of assurance. The key is to define this level prior to setting the purpose and parameters.
OCEG
GRCA
Q4:
Identifying root causes helps to
○
A
Be more specific regarding who is to blame○
B
Find a solution to fixing not only this problem but potential other problems that result from the same root cause
OCEG
GRCA
Q5:
Follow-up on the implementation status of the recommendation by assurance personnel is known as
○
A
Follow-Up by Process Owner○
B
Follow-Up by Independent Assurance○
C
Follow-Up by Targeted Review