CAF-3 · Chapter 16
The 5 Key Components of ITGCs (Application Scenarios) MCQs with Answers
15 multiple-choice questions on The 5 Key Components of ITGCs (Application Scenarios) for CAF-3 Data, Systems and Risks. Try each one before revealing the answer and explanation.
Practise this chapter interactivelyQuestion 1
A financial controller sets a rule in the accounting software that no invoice above Rs. 500,000 can be processed without two managerial signatures. Meanwhile, the IT department enforces a mandatory 30-day password rotation policy for every computer across the entire company. The password rotation policy represents:
- A) An Application-Specific Control
- B) An IT General Control (ITG
- C)
- C) A Physical Security Control
- D) A Software Development Control
Show answer & explanation
Answer: B) An IT General Control (ITG
IT General Controls (ITGCs) are broad-based controls that apply to all aspects of an organization’s IT infrastructure (like network-wide password policies), whereas application controls are tailored to individual software systems (like the invoice signature rule)
Question 2
What is the fundamental, overarching objective of implementing IT General Controls (ITGCs) within an organization?
- A) To completely supplant human employees with fully automated workflows.
- B) To establish a reliable, secure, and compliant IT environment that aligns with business objectives.
- C) To eliminate the need for physical office buildings.
- D) To guarantee that cyberattacks will never happen.
Show answer & explanation
Answer: B) To establish a reliable, secure, and compliant IT environment that aligns with business objectives.
The primary objective of ITGCs is to ensure the reliability, security, and integrity of IT systems, safeguarding infrastructure so that technology-based assets support business objectives securely and comply with regulations
Question 3
An American multinational company implements stringent ITGCs specifically to ensure that its financial reporting data cannot be tampered with by its own IT staff. Which major regulation explicitly mandates these ITGCs for financial reporting integrity?
- A) GDPR
- B) PECA, 2016
- C) Sarbanes-Oxley Act (SOX)
- D) PCI DSS
Show answer & explanation
Answer: C) Sarbanes-Oxley Act (SOX)
The Sarbanes-Oxley Act (SOX) is a major US regulation that explicitly mandates strict ITGCs to protect the accuracy, reliability, and integrity of corporate financial reporting . --------------------------------------------------------------------------------
Question 4
To fix a minor bug quickly, a programmer edits the source code of the live CRM system without logging the change, testing it, or seeking managerial approval. The system immediately crashes. This represents a catastrophic failure of which ITGC component?
- A) Access Controls
- B) Physical Security Controls
- C) Change Management Controls
- D) IT Operations Controls
Show answer & explanation
Answer: C) Change Management Controls
Change Management Controls ensure that all modifications to IT systems are authorized, tested, and documented. Allowing a programmer to bypass these steps to alter live code is a major failure of this control
Question 5
A junior database administrator was inadvertently given superuser administrative rights. While trying to clean up old files, they accidentally deleted a critical customer database. To prevent this, the company should have implemented:
- A) Environmental Controls
- B) Privileged Access Management (PAM)
- C) Program Development Controls
- D) Antivirus Software
Show answer & explanation
Answer: B) Privileged Access Management (PAM)
Privileged Access Management (PAM) is a crucial part of Access Controls. It involves restricting, monitoring, and limiting elevated administrative rights to prevent misuse or accidental damage by highly privileged users
Question 6
A bank's IT department conducts daily automated backups of all customer transaction data and stores them in a secure, geographically separate location. This specific activity falls under which key component of ITGCs?
- A) Change Management Controls
- B) Program Development Controls
- C) Access Controls
- D) IT Operations Controls
Show answer & explanation
Answer: D) IT Operations Controls
IT Operations Controls manage the day-to-day running of IT systems. Crucial tasks like automated daily backups, disaster recovery, and system monitoring fall directly under this component
Question 7
A hospital configures its central database so that doctors can only view patient medical histories, while the billing department can only view patient payment statuses. Neither department can see the other's data. This is an application of:
- A) Role-Based Access Control (RBA
- B) Physical Access Control
- C)
- C) Change Management
- C) Correct Answer: A Explanation: Role-Based Access Control (RBA
- C) ensures that users are granted access to systems and data based strictly on their specific job roles and responsibilities within the organization .
- D) System Development Life Cycle (SDL
Show answer & explanation
Answer: A) Role-Based Access Control (RBA
Role-Based Access Control (RBAC) ensures that users are granted access to systems and data based strictly on their specific job roles and responsibilities within the organization
Question 8
An organization is building a new mobile banking app. Management mandates that stringent security testing, code reviews, and vulnerability scans must happen at every single phase of the System Development Life Cycle (SDLC) before the app is launched. This represents:
- A) Physical Security Controls
- B) Program Development Controls
- C) Environmental Controls
- D) Privileged Access Management
Show answer & explanation
Answer: B) Program Development Controls
Program Development Controls ensure that new systems are built securely from the ground up by integrating security testing and quality assurance into every phase of the software development lifecycle
Question 9
An e-commerce company installs fire suppression systems, raised floors, temperature sensors, and biometric fingerprint scanners at the entrance of its main server data center. These measures are classified as:
- A) Logical Access Controls
- B) IT Operations Controls
- C) Physical Security Controls
- D) Change Management Controls
Show answer & explanation
Answer: C) Physical Security Controls
Physical Security Controls protect the tangible hardware of an IT environment. This includes physical locks, biometric scanners, and environmental controls like fire suppression and temperature monitoring to prevent hardware damage
Question 10
Before deploying a major software update to the live ERP system, the IT team runs the new code in an isolated "sandbox" environment to ensure it doesn't break existing features. This practice is a core element of:
- A) Change Management Controls
- B) Physical Security Controls
- C) Multi-Factor Authentication
- D) Data Backups
Show answer & explanation
Answer: A) Change Management Controls
A fundamental part of Change Management Controls is ensuring that all updates or modifications are thoroughly tested in an isolated environment before being deployed to the live system to prevent operational disruption . --------------------------------------------------------------------------------
Question 11
Before designing or purchasing any new IT controls, the Chief Information Security Officer (CISO) conducts a thorough review to identify the organization's most critical data assets and their specific vulnerabilities. Which step of the ITGC implementation process is this?
- A) Control Design
- B) Risk Assessment
- C) Training and Awareness
- D) Monitoring and Review
Show answer & explanation
Answer: B) Risk Assessment
The first step in implementing ITGCs is Risk Assessment, where an organization identifies its critical assets, evaluates potential threats, and determines the vulnerabilities that need to be addressed
Question 12
Six months after implementing a new Role-Based Access Control policy, the IT audit team evaluates the system logs to ensure the controls are actively preventing unauthorized access and haven't become obsolete. This phase of the implementation cycle is known as:
- A) Control Design
- B) Risk Assessment
- C) System Deployment
- D) Monitoring and Review
Show answer & explanation
Answer: D) Monitoring and Review
Monitoring and Review is the final, ongoing step of the ITGC lifecycle. It ensures that controls remain effective over time and are adjusted as new risks emerge or business objectives change
Question 13
A global retail brand struggles to maintain a unified ITGC framework because its European branches must follow GDPR privacy laws, while its US and Asian branches follow entirely different regulations. This highlights which specific challenge of managing ITGCs?
- A) Lack of physical hardware
- B) Compliance with evolving and diverse regulatory landscapes
- C) The inability to conduct risk assessments
- D) Over-reliance on physical locks
Show answer & explanation
Answer: B) Compliance with evolving and diverse regulatory landscapes
Multinational organizations face significant hurdles in managing ITGCs because different regions impose distinct, continually shifting legal and regulatory compliance mandates (like GDPR vs. local laws)
Question 14
An organization implements such strict and complex IT General Controls that employees find it difficult to complete basic daily tasks efficiently, leading to complaints about reduced business agility. This scenario highlights the organizational challenge of:
- A) Balancing security with operational flexibility
- B) Funding the IT department
- C) Upgrading legacy hardware
- D) Eliminating cyber threats
Show answer & explanation
Answer: A) Balancing security with operational flexibility
A major challenge in ITGC management is finding the right balance; controls must be strict enough to ensure security, but flexible enough not to hinder user convenience or operational agility
Question 15
Why must an organization's ITGC framework continuously evolve rather than remaining static after its initial implementation?
- A) Because physical servers expire every 6 months.
- B) Because emerging technologies (like AI) and the increased frequency of sophisticated cyberattacks constantly introduce new vulnerabilities.
- C) Because IT auditors require new software every year.
- D) Because static controls are illegal under PECA 2016.
Show answer & explanation
Answer: B) Because emerging technologies (like AI) and the increased frequency of sophisticated cyberattacks constantly introduce new vulnerabilities.
ITGCs must continuously adapt because the adoption of emerging technologies (like AI) and the ever-increasing frequency and sophistication of cyberattacks constantly introduce new risks into the IT environment
