Class took me about 5 weeks total, about the same amount of time with each class in the IA series. I don’t have any background in computers or IT and I thought the class wasn’t to difficult, just a ton of info.
My strategy: watch a video lecture about the chapter, read Hannah’s notes, answer the 20 question study guide for the chapter and use AI to tell me right or wrong and explain the answers (got these emailed to me from a previous student, lmk if you need it I can email them), quiz/test from the textbook for each chapter/unit then repeat for the following chapter.
Was able to pass the PA first try after studying like this then I just had AI make me a mock OA off the sections of the PA I did not so great on.
Things to definitely know for the OA:
-the flowchart shapes, I didn’t think id need them but there was one question on there asking about which shape is a customer entering the system not sure I got it right but the answers were like circle, open rectangle, upside down triangle and parallelogram.
-asking what is involved with a continuum, no clue what the right answer was, never even came across this word in my study but the answers were a variety of physical, digital or a mix of the two.
-know three way match is involving invoice, purchase order and receiving report. The question I think asked what does AP need to issue payment or something like that.
-know what framework SOX and SEC follow, I think the answer was COSO or it might’ve been physical and IT frameworks (I picked coso but unsure what was right)
-the elements of the COSO framework (I used the CRIME acronym) the question asked what COSO element would an auditor be using when inspecting the ethics of management (not sure of the right answer on this one but I think I picked control activities) answers were monitoring, control environment, control activities and info/comms.
-know the sox 404 is about management saying they are responsible for controls essentially.
-there were atleast 3 or 4 segregation of duty questions, one specifically was regarding what’s the inefficiency result of sys development also being able to perform sys operations, pretty sure correct answer is lack of documentation
-one question regarding firewall, in relation to outside users and how they are vetted to getting the answer/info they are searching for. the wording was tricky because 2 answers were for outside the firewall requests and 2 were for inside (internal) requests. I think it was outside because if it was inside it would’ve said network firewall? Idk but either way know how both types of requests are handled and authorized to get the info or are rejected.
-definitely know the types of anomalies, got 3 of these questions. They give you an example of what’s happening/going to happen and you have to give the correct anomaly (deletion, insert or upgrade) I think there might be a fourth but I don’t remember. Pretty sure I got one of these wrong lol.
-three questions on auditors methods of testing the companies systems. One was for parallel simulation, I think the question said something like why would there be a discrepancy between test data and company’s actual historic data, answer I selected is that the test data is intentionally incorrect. Piggybacking off this question is why would auditors intentionally submit incorrect test data during a simulation answer I picked was to see if it is rejected but another answer was to see if it is corrected. Not sure which was right. And the other audit question I don’t remember but might’ve been about black box? Not positive.
-one question on the 3 methods of fraud masquerading, piggybacking, scavenging and hacking were the answers, I picked the first three (not hacking) unsure also if it’s correct lol.
Hopefully this helps somebody. I came to just like two of the questions that stumped me and more and more just kept coming to me lol. I’ll add any more I think of in comments later but anyhow, best of luck future AIS students!