All Practice Exams

100+ Free TCU Auditor Federal de Controle Externo — TI Practice Questions

Prepare for the Tribunal de Contas da União — Auditor Federal de Controle Externo — Especialidade: Tecnologia da Informação exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
100+ Questions
100% Free

Loading practice questions...

Same family resources

Explore More Tribunal de Contas da União (TCU) Career Examinations

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.

2026 Statistics

Key Facts: TCU Auditor Federal de Controle Externo — TI Exam

100 Questions

Comprehensive practice bank questions across 5 core domains

OpenExamPrep Technical Blueprint

5 Hours

Official examination session duration

Cebraspe / TCU Edital

R$ 200,00

Official candidate registration fee for AUFC

Tribunal de Contas da União Edital

R$ 22.000+

Initial monthly gross salary for AUFC

Portal da Transparência TCU

CF/88 Arts. 70-75

Constitutional mandate for federal external control

Constituição Federal de 1988

IN 94/2022

Federal SISP IT procurement regulation

Secretaria de Governo Digital / MGI

TCU AUFC – Auditoria de Tecnologia da Informação tests IT governance (COBIT/ITIL), cybersecurity (ISO 27001/LGPD/NIST), data engineering and AI in audit, cloud and software architecture, and federal IT procurement oversight (Lei 14.133/2021) across 200 Cebraspe Certo/Errado items plus a discursive paper. This page provides 100 free English-language practice MCQs adapted from the official blueprint.

Sample TCU Auditor Federal de Controle Externo — TI Practice Questions

Try these sample questions to test your TCU Auditor Federal de Controle Externo — TI exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1COBIT 2019 distinguishes between principles that describe the core requirements of a governance system for enterprise information and technology (I&T) and principles for a governance framework. Which of the following is officially classified by COBIT 2019 as a principle for a 'governance framework' rather than a 'governance system'?
A.Based on a Conceptual Model
B.Provide Stakeholder Value
C.Holistic Approach
D.Dynamic Governance System
Explanation: COBIT 2019 establishes three governance framework principles: 1) Based on a conceptual model, 2) Open and flexible, and 3) Aligned to major standards. In contrast, the six governance system principles are: Provide stakeholder value, Holistic approach, Dynamic governance system, Governance distinct from management, Tailored to enterprise needs, and End-to-end governance system.
2During an IT audit of a federal regulatory agency, an auditor analyzes how the organization tailored its I&T governance system using COBIT 2019. Which of the following correctly identifies a COBIT 2019 'Design Factor' and its expected impact on governance objective priority?
A.Threat Landscape: High-threat environments trigger higher target capability levels for DSS05 (Managed Security Services) and APO13 (Managed Security).
B.Sourcing Model: Complete outsourcing of IT operations eliminates the enterprise's need to govern and monitor EDM01 (Ensured Governance Framework Setting).
C.Role of IT: When IT is considered 'Support' only, the enterprise must achieve capability level 4 across all BAI (Build, Acquire, Implement) processes.
D.Enterprise Strategy: An innovation/differentiation strategy prioritizes DSS01 (Managed Operations) and MEA01 (Managed Performance and Conformance Monitoring).
Explanation: In COBIT 2019, 'Threat Landscape' is one of the 11 Design Factors. An enterprise operating in a high-threat environment must prioritize security-related governance and management objectives, specifically APO13 (Managed Security) and DSS05 (Managed Security Services), typically raising their target capability levels.
3COBIT 2019 defines seven components that individually and collectively contribute to the good operations of an enterprise I&T governance system. Which of the following is NOT one of these seven components?
A.External Regulatory Enforcement Bodies
B.Organizational Structures
C.Culture, Ethics and Behavior
D.Services, Infrastructure and Applications
Explanation: The seven COBIT 2019 governance system components (formerly called enablers in COBIT 5) are: 1) Processes, 2) Organizational Structures, 3) Principles, Policies and Frameworks, 4) Information, 5) Culture, Ethics and Behavior, 6) People, Skills and Competencies, and 7) Services, Infrastructure and Applications. External regulatory enforcement bodies are external stakeholders/environmental factors, not an internal governance system component.
4COBIT 2019 organizes its 40 core governance and management objectives into five domains. Which domain specifically contains the governance objectives that are the direct responsibility of the board of directors and governing body?
A.EDM (Evaluate, Direct and Monitor)
B.APO (Align, Plan and Organize)
C.BAI (Build, Acquire and Implement)
D.MEA (Monitor, Evaluate and Assess)
Explanation: The EDM (Evaluate, Direct and Monitor) domain contains the five governance objectives (EDM01 to EDM05) that set strategic direction, evaluate options, and monitor compliance and performance, which are the direct responsibility of the governing body/board.
5In the COBIT 2019 process capability assessment scheme (which aligns with CMMI), what defines a process that has achieved Capability Level 3?
A.The process is well defined, documented, and uses standardized organizational assets to achieve its intended purpose across the entire enterprise.
B.The process achieves its purpose through the application of an incomplete set of activities that can be characterized as initial or intuitive.
C.The process is quantitatively managed using statistical and quantitative techniques to control process performance.
D.The process is continuously improved through automated feedback and innovative technological changes to meet current and projected business goals.
Explanation: Under CMMI and COBIT 2019 capability levels: Level 0 is Incomplete; Level 1 is Performed (achieves purpose through basic activities); Level 2 is Managed (planned, monitored, and adjusted); Level 3 is Defined (well defined, standardized, and maintained across the organization); Level 4 is Quantitatively Managed; and Level 5 is Optimizing.
6A federal audit team at the TCU evaluates whether a public agency's board optimizes the value delivered from major multi-year digital transformation investments while maintaining prudent risk appetite. Which COBIT 2019 governance objective directly addresses this mandate?
A.EDM02 — Ensured Benefits Delivery
B.EDM04 — Ensured Resource Optimization
C.APO05 — Managed Portfolio
D.BAI01 — Managed Programs
Explanation: EDM02 (Ensured Benefits Delivery) is the governance objective dedicated to securing optimal value from I&T-enabled initiatives, services, and assets by evaluating and directing the realization of benefits and aligning investments with strategic business objectives.
7According to the COBIT 2019 Design Guide, what is the correct chronological sequence of stages for designing a tailored I&T governance system?
A.Understand enterprise context and strategy -> Determine the initial scope of the governance system -> Refine the scope of the governance system -> Conclude the governance system design
B.Determine the initial scope -> Assess process capability levels -> Refine the scope -> Implement the governance system
C.Establish the program -> Understand context and strategy -> Define target capability -> Plan program execution
D.Identify pain points -> Select focus areas -> Perform gap analysis -> Monitor and evaluate conformance
Explanation: The COBIT 2019 Design Guide specifies a rigorous four-stage workflow: Stage 1: Understand enterprise context and strategy; Stage 2: Determine the initial scope of the governance system; Stage 3: Refine the scope of the governance system; Stage 4: Conclude the governance system design.
8In ITIL 4, the Service Value System (SVS) represents how all the components and activities of an organization work together to enable value creation. Which set correctly lists the five core components of the ITIL 4 Service Value System?
A.Guiding Principles, Governance, Service Value Chain, Practices, Continual Improvement
B.Plan, Improve, Engage, Design and Transition, Deliver and Support
C.Organizations and People, Information and Technology, Partners and Suppliers, Value Streams and Processes
D.Service Strategy, Service Design, Service Transition, Service Operation, Continual Service Improvement
Explanation: The ITIL 4 Service Value System (SVS) consists of five core components: 1) Guiding Principles, 2) Governance, 3) Service Value Chain (SVC), 4) Practices, and 5) Continual Improvement.
9In the ITIL 4 Service Value Chain (SVC), which activity has the primary purpose of ensuring a shared understanding of the vision, current status, and improvement direction for all four dimensions and all products and services across the organization?
A.Plan
B.Engage
C.Design and Transition
D.Obtain/Build
Explanation: The purpose of the 'Plan' value chain activity is to ensure a shared understanding of the vision, current status, and improvement direction for all four dimensions and all products and services across the organization.
10An IT auditor notices that a federal agency's public portal failed because third-party cloud service contracts lacked adequate SLA penalties and data exchange integration protocols. Under ITIL 4, which dimension of service management failed in this scenario?
A.Partners and Suppliers
B.Organizations and People
C.Information and Technology
D.Value Streams and Processes
Explanation: The 'Partners and Suppliers' dimension encompasses an organization's relationships with other organizations involved in the design, development, deployment, delivery, and continual improvement of services, including vendor contracts, cloud service agreements, and partner management.

About the TCU Auditor Federal de Controle Externo — TI Exam

The Concurso Público para Auditor Federal de Controle Externo (AUFC) — Especialidade: Tecnologia da Informação do Tribunal de Contas da União (TCU) is the premier federal oversight and IT audit civil service competition in Brazil. Operating directly under the constitutional mandate of Articles 70 to 75 of the 1988 Federal Constitution, TCU IT Auditors evaluate, audit, and supervise the strategic alignment, cybersecurity, algorithmic integrity, and multi-billion-real public procurements across all federal ministries, regulatory agencies, autarquias, and state-owned enterprises (such as Serpro, Dataprev, Petrobras, and Banco do Brasil). The exam syllabus tests deep proficiency across five foundational pillars: IT Governance and Management (COBIT 2019, ITIL 4, DAMA DMBOK2, Agile frameworks, PMBOK 7th ed.), Information Security & Cybersecurity (ISO/IEC 27001/27002:2022, ISO 27005, LGPD Lei 13.709/2018, NIST CSF, Cryptography/ICP-Brasil, OWASP Top 10, ISO 22301), Data Engineering & AI in Audit (Advanced SQL window functions and CTEs, Kimball dimensional modeling, Hadoop/Spark/Kafka pipelines, NoSQL, graph analytics, machine learning fraud detection algorithms and evaluation metrics), Software Engineering & Cloud Computing (Microservices, SOA, REST/gRPC, DevOps CI/CD, Terraform IaC, Docker, Kubernetes, AWS/Azure/GCP shared responsibility), and Federal IT Procurement Oversight (IN SGD/MGI nº 94/2022, landmark TCU Plenary jurisprudence, Nova Lei de Licitações Lei 14.133/2021, and Lei Orgânica do TCU Lei 8.443/1992).

Assessment

First stage: P1 Objetiva — Conhecimentos Básicos, 100 items; P2 Objetiva — Conhecimentos Específicos, 100 items covering IT governance, information security, data engineering and AI, software architecture and cloud, and IT procurement oversight; P3 Discursiva — three discursive questions plus one peça de natureza técnica. Second stage: Programa de Formação (eliminatory).

Time Limit

Objective papers 5 hours (morning); discursive paper 4h30 (afternoon)

Passing Score

Minimum scores set per objective paper and for the combined objective result, followed by approval in the discursive paper and in the Programa de Formação

Exam Fee

R$ 120,00 (Tribunal de Contas da União (Organized by Cebraspe))

TCU Auditor Federal de Controle Externo — TI Exam Content Outline

25%

Governança e Gestão de TI (IT Governance & Management)

COBIT 2019 framework (Governance Principles, Design Factors, Governance Components, Focus Areas, 40 Governance and Management Objectives across EDM, APO, BAI, DSS, and MEA domains, CMMI-based process capability assessment), ITIL 4 (Service Value System - SVS, Service Value Chain activities, 4 Dimensions of Service Management, 7 Guiding Principles, 34 Management Practices including Incident, Problem, Change Enablement, and Service Level Management), DAMA-DMBOK2 (Data Governance wheel, Data Quality dimensions, Metadata Management, Data Lineage), and Agile Frameworks (Scrum roles and events, Kanban WIP limits and flow metrics, SAFe Agile Release Trains, and PMBOK 7th Edition 12 Principles and 8 Performance Domains).

25%

Segurança da Informação e Cibersegurança (Information Security & Cybersecurity)

ABNT NBR ISO/IEC 27001 and ISO/IEC 27002:2022 (Organizational [37], People [8], Physical [14], and Technological [34] controls, Control Attributes taxonomy), ISO/IEC 27005 (Information Security Risk Management process and risk treatment options), Lei Geral de Proteção de Dados Pessoais (LGPD - Lei nº 13.709/2018: 10 principles, 10 legal bases under Art. 7º, sensitive data under Art. 11, Data Subject Rights, DPO/Encarregado duties, RIPD/DPIA, ANPD administrative sanctions), NIST Cybersecurity Framework (IPDRR: Govern, Identify, Protect, Detect, Respond, Recover), Cryptography (Symmetric AES/ChaCha20, Asymmetric RSA/ECC, SHA-2/3, HMAC, PKI / ICP-Brasil, Medida Provisória 2.200-2/2001, Lei nº 14.063/2020), OWASP Top 10 (Injection, Broken Access Control, Cryptographic Failures, SSRF, XSS/CSRF), Incident Response (CSIRT/CTIR Gov), Zero Trust Architecture (NIST SP 800-207), and Business Continuity (ISO 22301).

20%

Engenharia de Dados, Big Data e IA em Auditoria (Data Engineering & AI in Audit)

Relational database modeling and normalization (1NF to BCNF), advanced SQL querying (CTEs, recursive CTEs, window functions ROW_NUMBER/RANK/DENSE_RANK/LAG/LEAD, index internals B-Tree/Hash/GiST, execution plans, transaction isolation levels and MVCC), Dimensional Modeling (Ralph Kimball Star/Snowflake schemas, Fact tables additive/semi-additive/non-additive, Dimension tables, Slowly Changing Dimensions SCD Types 1/2/3/4/6, Bill Inmon Corporate Information Factory), Data Lakes and Lakehouses (Medallion architecture, Delta Lake, Iceberg), Big Data Technologies (Hadoop HDFS NameNode/DataNode, MapReduce, Apache Spark Driver/Executors/RDDs/DataFrames/Narrow vs Wide dependencies, Apache Kafka topics/partitions/offsets/KRaft), NoSQL databases (Key-Value, Document, Wide-Column, Graph Neo4j / Cypher), CAP and PACELC theorems, Graph Network Analysis for cartel detection in bidding, Data Mining (Apriori, Support/Confidence/Lift), and Machine Learning (Supervised/Unsupervised, Logistic Regression, Random Forests, XGBoost, k-Means, DBSCAN, Isolation Forest, ROC-AUC, Precision/Recall/F1-Score calculations, NLP/BERT in tender text analysis).

15%

Engenharia de Software, Arquitetura e Cloud Computing (Software Engineering & Cloud)

Software architecture principles (Microservices vs SOA, API Gateway, Service Mesh, Circuit Breaker, Bulkhead, CQRS, Event Sourcing, Saga distributed transactions), Inter-service communication (RESTful APIs, OpenAPI, gRPC/Protobuf, asynchronous message brokers), DevOps & CI/CD pipelines (Automated testing, SAST/DAST, Blue-Green/Canary/Rolling deployment), Infrastructure as Code (Terraform declarative state, Ansible playbooks, idempotency), Containerization & Orchestration (Docker multi-stage builds, cgroups/namespaces, Kubernetes Control Plane, Worker Nodes, Pods, Services ClusterIP/NodePort/LoadBalancer, Deployments, ConfigMaps, Secrets, HPA), Cloud Computing service and deployment models (IaaS, PaaS, SaaS, Public/Private/Hybrid/Multi-cloud), Cloud Shared Responsibility Models (AWS, Azure, GCP), Cloud Well-Architected Framework pillars, and Software Testing (Unit, Integration, TDD/BDD, Non-functional load/stress/security testing).

15%

Fiscalização de Contratações de TI e Controle Externo (IT Procurement Oversight & External Control)

Instrução Normativa SGD/MGI nº 94/2022 (SISP IT Procurement Lifecycle: Planejamento da Contratação, DOD, ETP da TIC, Termo de Referência, Matriz de Riscos, Seleção do Fornecedor, Gestão e Fiscalização Contratual, Critérios de Medição por Resultados e Níveis Mínimos de Serviço - NMS), Landmark TCU Jurisprudence and Súmulas (Súmula TCU 269 and Acórdão 1521/2003-Plenário prohibiting simple headcount supply / locação de mão de obra, Súmula TCU 270 restricting brand preference, Acórdão 2308/2010-Plenário on UST / Function Points sizing, Acórdão 1233/2012-Plenário on strategic IT governance and IP rights), Nova Lei de Licitações (Lei nº 14.133/2021: Pregão, Concorrência, Diálogo Competitivo, Inexigibilidade Art. 74, Dispensa Art. 75, Matriz de Riscos, Contratos de Eficiência), and Institutional TCU Legal Framework (Constituição Federal de 1988 Arts. 70-75, Lei Orgânica do TCU Lei nº 8.443/1992, Título Executivo Extrajudicial, Acórdãos, Multas, and Declaração de Inidoneidade).

How to Pass the TCU Auditor Federal de Controle Externo — TI Exam

What You Need to Know

  • Passing score: Minimum scores set per objective paper and for the combined objective result, followed by approval in the discursive paper and in the Programa de Formação
  • Assessment: First stage: P1 Objetiva — Conhecimentos Básicos, 100 items; P2 Objetiva — Conhecimentos Específicos, 100 items covering IT governance, information security, data engineering and AI, software architecture and cloud, and IT procurement oversight; P3 Discursiva — three discursive questions plus one peça de natureza técnica. Second stage: Programa de Formação (eliminatory).
  • Time limit: Objective papers 5 hours (morning); discursive paper 4h30 (afternoon)
  • Exam fee: R$ 120,00

Keys to Passing

  • Work through all 100 available questions
  • Review every answer and explanation
  • Track weak areas and revisit them
  • Use our AI tutor for tough concepts

TCU Auditor Federal de Controle Externo — TI Study Tips from Top Performers

1Distinguish COBIT 2019 Governance Principles (system vs framework) and memorize the 40 governance and management objectives across EDM, APO, BAI, DSS, and MEA domains.
2Internalize the 4 control themes and 93 controls of ISO/IEC 27002:2022, and understand the 10 legal bases under LGPD Article 7º and why Legitimate Interest cannot justify processing sensitive personal data under Article 11.
3Practice SQL window functions (ROW_NUMBER, RANK, DENSE_RANK, LAG, LEAD) and calculate machine learning fraud detection metrics (Precision, Recall, F1-Score, ROC-AUC) given confusion matrices.
4Master the procurement phases under IN SGD/MGI nº 94/2022: understand the mandatory contents of the DOD, ETP da TIC, TR, and the role of Níveis Mínimos de Serviço (NMS) for glosas.
5Review landmark TCU Plenary decisions: memorize Acórdão 1521/2003 (prohibition of paying for mere headcount/body shopping), Acórdão 2308/2010 (UST/PF measurement criteria), and Súmulas 269 and 270.

Frequently Asked Questions

What is the role of an Auditor Federal de Controle Externo — TI at TCU?

AUFC IT Auditors lead inspections, compliance audits, operational evaluations, and continuous algorithmic monitoring of federal IT systems, multi-million BRL software procurements, cloud migrations, and cybersecurity frameworks across all three branches of the Brazilian Federal Government and state-owned enterprises.

What is the official structure and scoring of the TCU AUFC TI exam?

The official examination administered by Cebraspe comprises objective items evaluated under the Certo/Errado net scoring system (where wrong answers deduct points) split into Conhecimentos Gerais (P1) and Conhecimentos Específicos (P2), followed by two discursive questions and a technical piece (peça de natureza técnica) evaluating IT audit findings.

What education degree is required to sit for the TCU AUFC TI competition?

Candidates must hold an officially recognized university bachelor's degree (diploma de nível superior) in any field of study issued by an educational institution accredited by the Ministry of Education (MEC).

What are the passing score criteria for the TCU AUFC examination?

Candidates must achieve at least 50% in the Basic Knowledge module, 50% in the Specific Knowledge module, and at least 60% overall on net scoring, in addition to achieving a passing grade on the discursive and technical audit report stages.

What is the initial remuneration for an AUFC at the Tribunal de Contas da União?

The initial monthly compensation for an Auditor Federal de Controle Externo at the TCU exceeds R$ 22.000,00, progressing beyond R$ 33.000,00 at the peak of the federal external control career path.

How does this OpenExamPrep question bank prepare candidates?

This practice bank adapts the official Cebraspe technical syllabus into 100 comprehensive 4-option MCQs in English, thoroughly explaining COBIT 2019, ITIL 4, ISO 27001/2:2022, LGPD, advanced SQL/ML, Kubernetes, and IN SGD/MGI nº 94/2022 with rigorous legal, technical, and distractor rationales.