While developing a risk-based audit program, the Information Technology Auditor most likely will focus on:

A. Strategic controls
B. Critical IT applications
C. Operation control
D. Business strategy
E. Business process

B. Critical IT applications

Explanation:
The correct answer is “B” because, in a risk-based audit program, IT auditors prioritize critical IT applications as they are essential to business operations and carry significant risks if compromised. Focusing on critical applications helps ensure the integrity, security, and reliability of the information systems that directly impact the organization’s objectives.