The CA Hub
All CAF-3 chapters

CAF-3 · Chapter 16

The 5 Key Components of ITGCs (Application Scenarios) MCQs with Answers

15 multiple-choice questions on The 5 Key Components of ITGCs (Application Scenarios) for CAF-3 Data, Systems and Risks. Try each one before revealing the answer and explanation.

Practise this chapter interactively
  1. Question 1

    A financial controller sets a rule in the accounting software that no invoice above Rs. 500,000 can be processed without two managerial signatures. Meanwhile, the IT department enforces a mandatory 30-day password rotation policy for every computer across the entire company. The password rotation policy represents:

    • A) An Application-Specific Control
    • B) An IT General Control (ITG
    • C)
    • C) A Physical Security Control
    • D) A Software Development Control
    Show answer & explanation

    Answer: B) An IT General Control (ITG

    IT General Controls (ITGCs) are broad-based controls that apply to all aspects of an organization’s IT infrastructure (like network-wide password policies), whereas application controls are tailored to individual software systems (like the invoice signature rule)

  2. Question 2

    What is the fundamental, overarching objective of implementing IT General Controls (ITGCs) within an organization?

    • A) To completely supplant human employees with fully automated workflows.
    • B) To establish a reliable, secure, and compliant IT environment that aligns with business objectives.
    • C) To eliminate the need for physical office buildings.
    • D) To guarantee that cyberattacks will never happen.
    Show answer & explanation

    Answer: B) To establish a reliable, secure, and compliant IT environment that aligns with business objectives.

    The primary objective of ITGCs is to ensure the reliability, security, and integrity of IT systems, safeguarding infrastructure so that technology-based assets support business objectives securely and comply with regulations

  3. Question 3

    An American multinational company implements stringent ITGCs specifically to ensure that its financial reporting data cannot be tampered with by its own IT staff. Which major regulation explicitly mandates these ITGCs for financial reporting integrity?

    • A) GDPR
    • B) PECA, 2016
    • C) Sarbanes-Oxley Act (SOX)
    • D) PCI DSS
    Show answer & explanation

    Answer: C) Sarbanes-Oxley Act (SOX)

    The Sarbanes-Oxley Act (SOX) is a major US regulation that explicitly mandates strict ITGCs to protect the accuracy, reliability, and integrity of corporate financial reporting . --------------------------------------------------------------------------------

  4. Question 4

    To fix a minor bug quickly, a programmer edits the source code of the live CRM system without logging the change, testing it, or seeking managerial approval. The system immediately crashes. This represents a catastrophic failure of which ITGC component?

    • A) Access Controls
    • B) Physical Security Controls
    • C) Change Management Controls
    • D) IT Operations Controls
    Show answer & explanation

    Answer: C) Change Management Controls

    Change Management Controls ensure that all modifications to IT systems are authorized, tested, and documented. Allowing a programmer to bypass these steps to alter live code is a major failure of this control

  5. Question 5

    A junior database administrator was inadvertently given superuser administrative rights. While trying to clean up old files, they accidentally deleted a critical customer database. To prevent this, the company should have implemented:

    • A) Environmental Controls
    • B) Privileged Access Management (PAM)
    • C) Program Development Controls
    • D) Antivirus Software
    Show answer & explanation

    Answer: B) Privileged Access Management (PAM)

    Privileged Access Management (PAM) is a crucial part of Access Controls. It involves restricting, monitoring, and limiting elevated administrative rights to prevent misuse or accidental damage by highly privileged users

  6. Question 6

    A bank's IT department conducts daily automated backups of all customer transaction data and stores them in a secure, geographically separate location. This specific activity falls under which key component of ITGCs?

    • A) Change Management Controls
    • B) Program Development Controls
    • C) Access Controls
    • D) IT Operations Controls
    Show answer & explanation

    Answer: D) IT Operations Controls

    IT Operations Controls manage the day-to-day running of IT systems. Crucial tasks like automated daily backups, disaster recovery, and system monitoring fall directly under this component

  7. Question 7

    A hospital configures its central database so that doctors can only view patient medical histories, while the billing department can only view patient payment statuses. Neither department can see the other's data. This is an application of:

    • A) Role-Based Access Control (RBA
    • B) Physical Access Control
    • C)
    • C) Change Management
    • C) Correct Answer: A Explanation: Role-Based Access Control (RBA
    • C) ensures that users are granted access to systems and data based strictly on their specific job roles and responsibilities within the organization .
    • D) System Development Life Cycle (SDL
    Show answer & explanation

    Answer: A) Role-Based Access Control (RBA

    Role-Based Access Control (RBAC) ensures that users are granted access to systems and data based strictly on their specific job roles and responsibilities within the organization

  8. Question 8

    An organization is building a new mobile banking app. Management mandates that stringent security testing, code reviews, and vulnerability scans must happen at every single phase of the System Development Life Cycle (SDLC) before the app is launched. This represents:

    • A) Physical Security Controls
    • B) Program Development Controls
    • C) Environmental Controls
    • D) Privileged Access Management
    Show answer & explanation

    Answer: B) Program Development Controls

    Program Development Controls ensure that new systems are built securely from the ground up by integrating security testing and quality assurance into every phase of the software development lifecycle

  9. Question 9

    An e-commerce company installs fire suppression systems, raised floors, temperature sensors, and biometric fingerprint scanners at the entrance of its main server data center. These measures are classified as:

    • A) Logical Access Controls
    • B) IT Operations Controls
    • C) Physical Security Controls
    • D) Change Management Controls
    Show answer & explanation

    Answer: C) Physical Security Controls

    Physical Security Controls protect the tangible hardware of an IT environment. This includes physical locks, biometric scanners, and environmental controls like fire suppression and temperature monitoring to prevent hardware damage

  10. Question 10

    Before deploying a major software update to the live ERP system, the IT team runs the new code in an isolated "sandbox" environment to ensure it doesn't break existing features. This practice is a core element of:

    • A) Change Management Controls
    • B) Physical Security Controls
    • C) Multi-Factor Authentication
    • D) Data Backups
    Show answer & explanation

    Answer: A) Change Management Controls

    A fundamental part of Change Management Controls is ensuring that all updates or modifications are thoroughly tested in an isolated environment before being deployed to the live system to prevent operational disruption . --------------------------------------------------------------------------------

  11. Question 11

    Before designing or purchasing any new IT controls, the Chief Information Security Officer (CISO) conducts a thorough review to identify the organization's most critical data assets and their specific vulnerabilities. Which step of the ITGC implementation process is this?

    • A) Control Design
    • B) Risk Assessment
    • C) Training and Awareness
    • D) Monitoring and Review
    Show answer & explanation

    Answer: B) Risk Assessment

    The first step in implementing ITGCs is Risk Assessment, where an organization identifies its critical assets, evaluates potential threats, and determines the vulnerabilities that need to be addressed

  12. Question 12

    Six months after implementing a new Role-Based Access Control policy, the IT audit team evaluates the system logs to ensure the controls are actively preventing unauthorized access and haven't become obsolete. This phase of the implementation cycle is known as:

    • A) Control Design
    • B) Risk Assessment
    • C) System Deployment
    • D) Monitoring and Review
    Show answer & explanation

    Answer: D) Monitoring and Review

    Monitoring and Review is the final, ongoing step of the ITGC lifecycle. It ensures that controls remain effective over time and are adjusted as new risks emerge or business objectives change

  13. Question 13

    A global retail brand struggles to maintain a unified ITGC framework because its European branches must follow GDPR privacy laws, while its US and Asian branches follow entirely different regulations. This highlights which specific challenge of managing ITGCs?

    • A) Lack of physical hardware
    • B) Compliance with evolving and diverse regulatory landscapes
    • C) The inability to conduct risk assessments
    • D) Over-reliance on physical locks
    Show answer & explanation

    Answer: B) Compliance with evolving and diverse regulatory landscapes

    Multinational organizations face significant hurdles in managing ITGCs because different regions impose distinct, continually shifting legal and regulatory compliance mandates (like GDPR vs. local laws)

  14. Question 14

    An organization implements such strict and complex IT General Controls that employees find it difficult to complete basic daily tasks efficiently, leading to complaints about reduced business agility. This scenario highlights the organizational challenge of:

    • A) Balancing security with operational flexibility
    • B) Funding the IT department
    • C) Upgrading legacy hardware
    • D) Eliminating cyber threats
    Show answer & explanation

    Answer: A) Balancing security with operational flexibility

    A major challenge in ITGC management is finding the right balance; controls must be strict enough to ensure security, but flexible enough not to hinder user convenience or operational agility

  15. Question 15

    Why must an organization's ITGC framework continuously evolve rather than remaining static after its initial implementation?

    • A) Because physical servers expire every 6 months.
    • B) Because emerging technologies (like AI) and the increased frequency of sophisticated cyberattacks constantly introduce new vulnerabilities.
    • C) Because IT auditors require new software every year.
    • D) Because static controls are illegal under PECA 2016.
    Show answer & explanation

    Answer: B) Because emerging technologies (like AI) and the increased frequency of sophisticated cyberattacks constantly introduce new vulnerabilities.

    ITGCs must continuously adapt because the adoption of emerging technologies (like AI) and the ever-increasing frequency and sophistication of cyberattacks constantly introduce new risks into the IT environment

Sponsored slot availableRun a CA academy or hiring firm? Put your name in front of students preparing for this exam.Advertise →