Labour Day Sale - Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 575363r9

Welcome To DumpsPedia

IIA-ACCA Sample Questions Answers

Questions 4

According to IIA guidance, which of the following roles would be appropriate for an internal auditor regarding fraud risk?

1. Identification.

2. Mitigation.

3. Remediation.

4. Reduction.

Options:

A.

1 only. |

B.

1 and 4 only.

C.

1, 3, and 4 only.

D.

1,2, 3, and 4.

Buy Now
Questions 5

Which of the following are typical responsibilities for operational management within a risk management program?

1. Implementing corrective actions to address process deficiencies.

2. Identifying shifts in the organization's risk management environment.

3. Providing guidance and training on risk management processes.

4. Assessing the impact of mitigation strategies and activities.

Options:

A.

1 and 2 only

B.

1 and 4 only

C.

2 and 3 only

D.

3 and 4 only

Buy Now
Questions 6

A government agency maintains a system of internal control, according to the COSO model, and has made a change to its employee performance reviews and rewards program. This change relates to which of the following components of COSO's internal control framework?

Options:

A.

Control environment.

B.

Control activities.

C.

Information and communication.

D.

Monitoring activities.

Buy Now
Questions 7

Which of the following standards would be most useful in evaluating the performance of a customer-service group?

Options:

A.

The average time per customer inquiry should be kept to a minimum.

B.

Customer complaints should be processed promptly.

C.

Employees should maintain a positive attitude when dealing with customers.

D.

All customer inquiries should be answered within seven days of receipt.

Buy Now
Questions 8

A large trucking organization wants to reduce traffic accidents by improving its system of internal controls.

Which of the following controls is correctly classified?

1. Review of speeding violations to identify repetitive locations and drivers is an example of a preventive control.

2. Defensive driver training is an example of a directive control.

3. The installation of tracking devices in delivery vehicles is an example of a corrective control.

4. Providing a vehicle driver handbook is an example of a detective control.

Options:

A.

1 and 2.

B.

1 and 4.

C.

2 and 3.

D.

3 and 4.

Buy Now
Questions 9

Which of the following steps should an internal auditor take during an audit of an organization's business continuity plans?

1. Evaluate the business continuity plans for adequacy and currency.

2. Prepare a business impact analysis regarding the loss of critical business.

3. Identify key personnel who will be required to implement the plans.

4. Identify and prioritize the resources required to support critical business processes.

Options:

A.

1 only

B.

2 and 4 only

C.

1, 3, and 4 only

D.

1, 2, 3, and 4

Buy Now
Questions 10

Which of the following is a primary driver behind the creation and prioritization of new strategic initiatives established by an organization?

Options:

A.

Risk tolerance

B.

Performance.

C.

Threats and opportunities.

D.

Governance

Buy Now
Questions 11

Organizational activities that complement each other and create a competitive advantage are called a:

Options:

A.

Merger.

B.

Strategic fit.

C.

Joint venture.

D.

Strategic goal.

Buy Now
Questions 12

A capital investment project will have a higher net present value, everything else being equal, if it has:

Options:

A.

A higher initial investment level.

B.

A higher discount rate.

C.

Cash inflows that are larger in the later years of the life of the project.

D.

Cash inflows that are larger in the earlier years of the life of the project.

Buy Now
Questions 13

Which of the following factors would reduce dissatisfaction for a management trainee but would not particularly motivate the trainee?

Options:

A.

A sense of achievement.

B.

Promotion.

C.

Recognition.

D.

An incremental increase in salary.

Buy Now
Questions 14

An internal auditor is investigating a potential fraudulent activity. What is the first test the auditor should perform on the transaction data under scrutiny?

Options:

A.

Digital analysis for statistically unlikely occurrences that may indicate system tampering.

B.

Verification of the completeness and integrity of the obtained data.

C.

Detailed review of the data contents to strategize the best analytical techniques.

D.

Calculation of statistical parameters to identify outliers requiring further scrutiny.

Buy Now
Questions 15

According to IIA guidance, which of the following are the most important objectives for helping to ensure the appropriate completion of an engagement?

1. Coordinate audit team members to ensure the efficient execution of all engagement procedures.

2. Confirm engagement workpapers properly support the observations, recommendations, and conclusions.

3. Provide structured learning opportunities for engagement auditors when possible.

4. Ensure engagement objectives are reviewed for satisfactory achievement and are documented properly.

Options:

A.

1, 2, and 3

B.

1, 2, and 4

C.

1, 3, and 4

D.

2, 3, and 4

Buy Now
Questions 16

The newly appointed chief audit executive (CAE) of a large multinational corporation, with seasoned internal audit departments located around the world, is reviewing responsibilities for engagement reports. According to IIA guidance, which of the following statements is true?

Options:

A.

The CAE is required to review, approve, and sign every engagement report.

B.

The CAE is required to review, approve, and sign all regulatory compliance engagement reports only

C.

The CAE may delegate responsibility for reviewing, approving and signing engagement reports, but should review the reports after they are issued.

D.

The internal audit charter must identify authorized signers of engagement reports.

Buy Now
Questions 17

Which of the following statements is most accurate with respect to various forms, elements, and characteristics of business contracts?

Options:

A.

A contract is a tool used by both suppliers and customers, the model and complexity of which generally remains constant

B.

Collaboration during contract negotiation encourages stakeholders to develop consensus but typically increases cycle times and the likelihood that the contract will fail

C.

Differing legal requirements affect the attitudes of contracting parties as well as the length content and language of contracts

D.

A contract is a tool used by both suppliers and customers though it offers commercial assurance of the relationship, purely from a customer perspective

Buy Now
Questions 18

An organization uses a database management system (DBMS) as a repository for data. The DBMS, in turn, supports a number of end-user developed applications which were created using fourth-generation programming languages. Some of the applications update the database. Which of the following is the most important control related to the integrity of the data in the database?

Options:

A.

End users have their read-only applications approved by the information systems department before accessing the database.

B.

Concurrency update controls are in place.

C.

End-user applications are developed on personal computers before being implemented on the mainframe.

D.

A hierarchical database model is adopted so that multiple users can be served at the same time.

Buy Now
Questions 19

According to the HA Code of Ethics, which of the following statements best describes the principle of competency?

Options:

A.

Internal auditors shall perform their work with honesty, diligence, and responsibility.

B.

Internal auditors shall perform their work in accordance with the Standards.

C.

Internal auditors shall perform their work in accordance with the law and make disclosures expected by the law.

D.

Internal auditors shall be prudent in the use of information acquired while performing their work.

Buy Now
Questions 20

Which of the following scenarios best illustrates the principle of due professional care?

Options:

A.

An internal auditor evaluates the significant risks arising from a consulting engagement.

B.

An internal auditor declares that he would have a conflict of interest in providing planned audit support.

C.

An internal auditor has been given sufficient authority to access documents needed to make an appraisal of an issue.

D.

An internal auditor uses technology-based audit techniques to ensure that all significant risks are identified.

Buy Now
Questions 21

Which of the following statements is true regarding assurance services provided to clients outside of the organization?

Options:

A.

Assurance services for outside clients are not covered under the internal audit charter.

B.

Assurance services for outside clients must be approved on a case-by-case basis by the board of directors.

C.

The nature of assurance services for outside clients should be defined in the internal audit charter.

D.

The nature of assurance services for outside clients is the same as for internal clients.

Buy Now
Questions 22

Which of the following is most likely to function as a directive control?

Options:

A.

Security dogs.

B.

Alert employees.

C.

Insurance claims.

D.

Cycle counts.

Buy Now
Questions 23

An internal auditor in a small broadcasting organization was assigned to review the revenue collection process. The auditor discovered that some checks from three customers were never recorded in the organization's financial records. Which of the following documents would be the least useful for the auditor to verify the finding?

Options:

A.

Bank statements.

B.

Customer confirmation letters.

C.

Copies of sales invoices.

D.

Copies of deposit slips.

Buy Now
Questions 24

An internal auditor completed an audit of a bank's loan department and found all significant risks to be managed adequately through effective internal controls. Which of the following would be an appropriate conclusion to report to management?

Options:

A.

The residual risk is lower than or equal to the risk appetite.

B.

The residual risk is higher than or equal to the risk appetite.

C.

The inherent risk is lower than or equal to the risk tolerance.

D.

The inherent risk is higher than or equal to the risk tolerance.

Buy Now
Questions 25

Which of the following statements is true regarding outsourced business processes?

Options:

A.

Outsourced business processes should not be considered in the internal audit universe because the controls are owned by the external service provider.

B.

Generally, independence is improved when the internal audit activity reviews outsourced business processes.

C.

The key controls of outsourced business processes typically are more difficult to audit because they are designed and managed externally.

D.

The system of internal controls may be better and more efficient when the business process is outsourced compared to internally sourced.

Buy Now
Questions 26

Which of the following does not provide operational assurance that a computer system is operating properly?

Options:

A.

Performing a system audit.

B.

Making system changes.

C.

Testing policy compliance.

D.

Conducting system monitoring.

Buy Now
Questions 27

An organization produces two products, X and Y. The materials used for the production of both products are limited to 500 kilograms (kg) per month. All other resources are unlimited and their costs are fixed. Individual product details are as follows:

Product X

Product Y

Selling price per unit

$10

$13

Materials per unit (at $1/kg)

2 kg

6 kg

Monthly demand

100 units

120 units

In order to maximize profit, how much of product Y should the organization produce each month?

Options:

A.

50 units.

B.

60 units.

C.

100 units.

D.

120 units.

Buy Now
Questions 28

Which of the following performance measures would be appropriate for evaluating an investment center, which has responsibility for its revenues, costs, and investment base, but would not be appropriate for evaluating cost, revenue, or profit centers?

Options:

A.

A flexible budget.

B.

Variance analysis.

C.

A contribution margin income statement by segment.

D.

Residual income.

Buy Now
Questions 29

When establishing a quality assurance and improvement program, the chief audit executive should ensure the program is designed to accomplish which of the following objectives?

1. Add value.

2. Improve operations.

3. Provide assurance that the internal audit activity conforms with the Standards.

4. Provide assurance that the internal audit activity conforms with the IIA Code of Ethics.

Options:

A.

1 only

B.

1 and 2 only

C.

1 and 3 only

D.

1, 2, 3, and 4

Buy Now
Questions 30

Which of the following actions are appropriate for the chief audit executive to perform when identifying audit resource requirements?

1. Consider employees from other operational areas as audit resources, to provide additional audit coverage in the organization.

2. Approach an external service provider to conduct internal audits on certain areas of the organization, due to a lack of skills in the organization.

3. Suggest to the audit committee that an audit of technology be deferred until staff can be trained, due to limited IT audit skills among the audit staff.

4. Communicate to senior management a summary report on the status and adequacy of audit resources.

Options:

A.

1 and 3 only

B.

2 and 4 only

C.

1, 2, and 4

D.

2, 3, and 4

Buy Now
Questions 31

A snow removal company is conducting a scenario planning exercise where participating employees consider the potential impacts of a significant reduction in annua snowfall for the coming winter. Which of the following best describes this type of risk?

Options:

A.

Residual.

B.

Net.

C.

Inherent.

D.

Accepted.

Buy Now
Questions 32

Which is the least effective form of risk management?

Options:

A.

Systems-based preventive control.

B.

People-based preventive control.

C.

Systems-based detective control.

D.

People-based detective control.

Buy Now
Questions 33

Which of the following statements is true regarding a bring-your-own-device (BYOD) environment?

Options:

A.

There is a greater need Kr organizations to rely on users to comply with policies and procedures.

B.

With fewer devices owned by the organization, there is reduced need to maintain documented policies and procedures.

C.

Incident response times are less critical in the BYOD environment. compared to a traditional environment

D.

There is greater sharing of operational risk in a BYOD environment.

Buy Now
Questions 34

Which of the following statements is true regarding the roles and responsibilities associated with a corporate social responsibility (CSR) program?

Options:

A.

The board has overall responsibility for the internal control processes associated with the CSR program.

B.

Management has overall responsibility for the effectiveness of governance, risk management, and internal control processes associated with the CSR program.

C.

The internal audit activity is responsible for ensuring that CSR principles are integrated into the organization's policies and procedures.

D.

Every employee has a responsibility for ensuring the success of the organization's CSR objectives.

Buy Now
Questions 35

An internal auditor discovered that several unauthorized modifications were made to the production version of an organization's accounting application. Which of the following best describes this deficiency?

Options:

A.

Production controls weakness.

B.

Application controls weakness.

C.

Authorization controls weakness.

D.

Change controls weakness.

Buy Now
Questions 36

Capacity overbuilding is most likely to occur when management is focused on which of the following?

Options:

A.

Marketing.

B.

Finance.

C.

Production.

D.

Diversification.

Buy Now
Questions 37

Which of the following actions is most likely to gain support for process change?

Options:

A.

Set clear objectives.

B.

Engage the various communities of practice within the organization.

C.

Demonstrate support from senior management.

D.

Establish key competencies.

Buy Now
Questions 38

Which of the following statements accurately describes one of the characteristics that distinguishes a multinational company from a domestic company?

Options:

A.

A multinational company has stockholders in other countries.

B.

A multinational company exports its products to other countries.

C.

A multinational company operates outside of its country of origin.

D.

A multinational company uses raw materials and components from more than one country.

Buy Now
Questions 39

In an analysis of alternative credit-management policies, which of the following components will cause the net present value of receivables on credit sales to increase, if everything else remains constant?

Options:

A.

A tougher collections policy that reduces the bad debt loss ratio.

B.

A higher cost per unit sold.

C.

A longer average collection period.

D.

An increase in the cost of capital.

Buy Now
Questions 40

Listening effectiveness is best increased by:

Options:

A.

Resisting both internal and external distractions.

B.

Waiting to review key concepts until the speaker has finished talking.

C.

Tuning out messages that do not seem to fit the meeting purpose.

D.

Factoring in biases in order to evaluate the information being given.

Buy Now
Questions 41

Which of the following COSO internal control framework components encompasses establishing structures, reporting lines, authorities, and responsibilities?

Options:

A.

Control environment.

B.

Control activities.

C.

Information and communication.

D.

Monitoring.

Buy Now
Questions 42

Which of the following is the primary benefit of including end users in the system development process?

Options:

A.

Improved integrity of programs and processing.

B.

Enhanced ongoing maintenance of the system.

C.

Greater accuracy of the testing phase.

D.

Reduced need for unexpected software changes.

Buy Now
Questions 43

Which of the following is false with regard to Internet connection firewalls?

Options:

A.

Firewalls can protect against computer viruses.

B.

Firewalls monitor attacks from the Internet.

C.

Firewalls provide network administrators tools to retaliate against hackers.

D.

Firewalls may be software-based or hardware-based.

Buy Now
Questions 44

Which of the following network types should an organization choose if it wants to allow access only to its own personnel?

Options:

A.

An extranet

B.

A local area network.

C.

An intranet

D.

The internet

Buy Now
Questions 45

Which of the following would best prevent unauthorized external changes to an organization's data?

Options:

A.

Antivirus software, firewall, data encryption.

B.

Firewall, data encryption, backup procedures.

C.

Antivirus software, firewall, backup procedures.

D.

Antivirus software, data encryption, change logs.

Buy Now
Questions 46

A headquarters-based internal auditor has been sent to a major overseas subsidiary to conduct various engagements. Initially, the internal auditor spends time to become familiar with local customs and organization's practices while embarking on the first engagement. Which of the following competencies does the internal auditor exercise?

Options:

A.

Communication.

B.

Persuasion and collaboration.

C.

Business acumen.

D.

Governance, risk, and control.

Buy Now
Questions 47

Which of the following control methods is effective in reducing the risk of purchasing-scheme fraud?

1. Periodically reviewing the vendor list for unusual vendors and addresses.

2. Segregating duties for amount purchasing, receiving, shipping, and accounting.

3. Validating sequential integrity of purchase orders.

4. Verifying the validity of invoices with post office box addresses.

Options:

A.

1 and 2 only

B.

3 and 4 only

C.

1, 2, and 4 only

D.

1, 2, 3, and 4

Buy Now
Questions 48

Which of the following would be considered a violation of The IIA's mandatory guidance on independence?

Options:

A.

The chief audit executive (CAE) reports functionally to the board and administratively to the chief financial officer.

B.

The board seeks senior management's recommendation before approving the annual salary adjustment of the CAE.

C.

The CAE confirms to the board, at least once every five years, the organizational independence of the internal audit activity.

D.

The CAE updates the internal audit charter and presents it to the board for approval periodically, not on a specific timeline.

Buy Now
Questions 49

An internal auditor who is carrying out an engagement to review controls related to corporate tax reporting must possess which of the following competencies?

1. Proficiency in analyzing key IT risks and controls.

2. The ability to recognize significant deviations from good business practices.

3. Knowledge of key indicators of fraud in tax reporting.

4. The ability to recognize the existence of problems related to tax accounting.

Options:

A.

1 and 4 only.

B.

3 and 4 only.

C.

2, 3, and 4 only.

D.

1,2, 3, and 4.

Buy Now
Questions 50

Which of the following is a weakness of observation as audit evidence?

Options:

A.

It cannot be used to test the completeness assertion.

B.

It cannot be used to test the existence assertion.

C.

It cannot be used to test the occurrence assertion.

D.

It cannot be relied upon because the evidence is not persuasive.

Buy Now
Questions 51

According to IIA guidance, which of the following is least compliant with the requirements regarding an internal auditor's need for objectivity?

Options:

A.

An internal auditor assessed the effectiveness of controls over payroll software, which he had helped implement with a previous employer.

B.

An internal auditor participated in an audit of controls around absenteeism, despite providing some consultation on controls in this area earlier in the year.

C.

An internal auditor performed an assurance engagement for the effectiveness of accounts payable access controls, one of which he previously helped to design.

D.

An internal auditor, previously employed in the quality assurance operations area, performed a consulting engagement for the operations manager.

Buy Now
Questions 52

According to IIA guidance, which of the following statements is true when an internal auditor performs consulting services that improve an organization's operations?

Options:

A.

The services must be aligned with those defined in the internal audit charter.

B.

The services must not be performed by the same internal auditor who performed assurance services, in order to maintain objectivity.

C.

The services may preclude assurance services from the consulting engagement.

D.

The services impose no responsibility to communicate information other than to the engagement client.

Buy Now
Questions 53

When developing the organization's first risk universe, which of the following would the chief audit executive be least likely to consider?

Options:

A.

The amount of risk that an organization is willing to seek or accept.

B.

The extent and degree of interdependency for identified key risks.

C.

The boundaries established to manage the amount of risk taken.

D.

The exposure to risks following management's risk responses.

Buy Now
Questions 54

Which of the following is the primary engagement responsibility of an entry-level internal auditor?

Options:

A.

Leadership.

B.

Documentation.

C.

Analysis.

D.

Reporting.

Buy Now
Questions 55

A furniture manufacturer has installed a new fire sprinkler system at its central warehouse and canceled the existing fire insurance policy on that property. What change of risk response strategy does this course of action most likely reflect?

Options:

A.

From sharing to reduction.

B.

From acceptance to reduction.

C.

From sharing to avoidance.

D.

From acceptance to avoidance.

Buy Now
Questions 56

A chief audit executive (CAE) is selecting an internal audit team to perform an audit engagement that requires a high level of knowledge in the areas of finance, investment portfolio management, and taxation. If neither the CAE nor the existing internal audit staff possess the required knowledge, which of the following actions should the CAE take?

Options:

A.

Postpone the audit until the CAE hires internal audit staff with the required knowledge.

B.

Ask the audit committee to decide the course of action.

C.

Select the most experienced auditors in the department to perform the engagement.

D.

Hire consultants who possess the required knowledge to perform the engagement.

Buy Now
Questions 57

An internal auditor is evaluating techniques management uses to mitigate risks within a particular product division. Which of the following is an example of risk reduction?

Options:

A.

Management sells the product division to a competitor.

B.

Management outsources the product division to a third party.

C.

Management allows the product division to remain unchanged.

D.

Management modifies the product division to minimize errors.

Buy Now
Questions 58

According to IIA guidance, which of the following should be included in the internal audit charter?

Options:

A.

The minimum resources and competencies needed for the internal audit activity.

B.

Identification of the organizational units where engagements are to be performed.

C.

Organizational relationships and reporting lines.

D.

Assigned responsibilities for designing and implementing controls.

Buy Now
Questions 59

Which of the following is most likely to be considered a control weakness?

Options:

A.

Vendor invoice payment requests are accompanied by a purchase order and receiving report.

B.

Purchase orders are typed by the purchasing department using prenumbered forms.

C.

Buyers promptly update the official vendor listing as new supplier sources become known.

D.

Department managers initiate purchase requests that must be approved by the plant superintendent.

Buy Now
Questions 60

An internal auditor is performing analytical reviews as part of an audit of a supermarket's merchandising department. Because the economy has declined since midyear, the auditor can expect to encounter which of the following?

Options:

A.

Higher inventory turnover.

B.

Higher operating margin.

C.

Lower obsolete stock disposal.

D.

Lower sales volume.

Buy Now
Questions 61

A chief audit executive (CAE) reports functionally to the CEO and administratively to the chief financial officer, both of whom serve on the company's board of directors. According to IIA guidance, which of the following would offer the greatest protection for the independence of the internal audit activity?

Options:

A.

Appoint the CAE as a member of the board.

B.

Move the CAE's functional reporting to an executive who is not on the board.

C.

Obtain full board approval of the internal audit activity's annual audit plan.

D.

Move the CAE's functional reporting to the audit committee.

Buy Now
Questions 62

Which of the following is an example of a detective control?

Options:

A.

Automatic shut-off valve.

B.

Auto-correct software functionality.

C.

Confirmation with suppliers and vendors.

D.

Safety instructions.

Buy Now
Questions 63

Which of the following controls could an internal auditor reasonably conclude is effective by observing the physical controls of a large server room?

Options:

A.

Adequate signs are in place to assist in locating safety equipment.

B.

Servers are secured individually to their racks by locks.

C.

Foam fire extinguishers are operable to protect against electrical fires.

D.

Swipe card access is required to gain access to the server room.

Buy Now
Questions 64

A new internal audit activity is creating its first charter. According to IIA guidance, which of the following objectives would be appropriate for inclusion in the charter?

Options:

A.

Continuously monitor the organization's overall risk activities in relation to its risk appetite.

B.

Evaluate the adequacy and effectiveness of the organization's governance activities.

C.

Oversee the establishment and administration of an effective risk management program.

D.

Assist management in implementing recommended control improvements.

Buy Now
Questions 65

The board has asked the internal audit activity (IAA) to be involved in the organization's enterprise risk management process. Which of the following activities is appropriate for IAA to perform without safeguards?

Options:

A.

Coach management in responding to risks.

B.

Develop risk management strategies for board approval.

C.

Facilitate identification and evaluation of risks.

D.

Evaluate risk management processes.

Buy Now
Questions 66

Which of the following is an effective approach for internal auditors to take to improve collaboration with audit clients during an engagement?

1. Obtain control concerns from the client before the audit begins so the internal auditor can tailor the scope accordingly.

2. Discuss the engagement plan with the client so the client can understand the reasoning behind the approach.

3. Review test criteria and procedures where the client expresses concerns about the type of tests to be conducted.

4. Provide all observations at the end of the audit to ensure the client is in agreement with the facts before publishing the report.

Options:

A.

1 and 2 only

B.

1 and 4 only

C.

2 and 3 only

D.

3 and 4 only

Buy Now
Questions 67

Which of the following recommendations made by the internal audit activity (IAA) is most likely to help prevent fraud?

Options:

A.

A review of password policy compliance found that employees frequently use the same password more than once during a year. The IAA recommends that the access control software reject any password used more than once during a 12-month period.

B.

A review of internal service-level agreement compliance in financial services found that requests for information frequently are fulfilled up to two weeks late. The IAA recommends that the financial services unit be eliminated for its ineffectiveness.

C.

A vacation policy compliance review found that employees frequently leave on vacation before their leave applications are signed by their manager. The IAA recommends that the manager attend to the leave applications in a more timely fashion.

D.

A review of customer service-level agreements found that orders to several customers are frequently delivered late. The IAA recommends that the organization extend the expected delivery time advertised on its website.

Buy Now
Questions 68

Which of the following evaluation criteria would be the most useful to help the chief audit executive determine whether an external service provider possesses the knowledge, skills, and other competencies needed to perform a review?

Options:

A.

The financial interest the service provider may have in the organization.

B.

The relationship the service provider may have had with the organization or the activities being reviewed.

C.

Compensation or other incentives that may be applicable to the service provider.

D.

The service provider's experience in the type of work being considered.

Buy Now
Questions 69

Which of the following situations would justify the removal of a finding from the final audit report?

Options:

A.

Management disagrees with the report findings and conclusions in their responses.

B.

Management has already satisfactorily completed the recommended corrective action.

C.

Management has provided additional information that contradicts the findings.

D.

Management believes that the finding is insignificant and unfairly included in the report.

Buy Now
Questions 70

Which of the following should be included in a privacy audit engagement?

1. Assess the appropriateness of the information gathered.

2. Review the methods used to collect information.

3. Consider whether the information collected is in compliance with applicable laws.

4. Determine how the information is stored.

Options:

A.

1 and 3 only

B.

2 and 4 only

C.

1, 3, and 4 only

D.

1, 2, 3, and 4

Buy Now
Questions 71

A chief audit executive (CAE) received a detailed internal report of senior management's internal control assessment. Which of the following subsequent actions by the CAE would provide the greatest assurance over management's assertions?

Options:

A.

Assert whether the described and reported control processes and systems exist.

B.

Assess whether senior management adequately supports and promotes the internal control culture described in the report.

C.

Evaluate the completeness of the report and management's responses to identified deficiencies.

D.

Determine whether management's operating style and the philosophy described in the report reflect the effective functioning of internal controls.

Buy Now
Questions 72

Which of the following is not an outcome of control self-assessment?

Options:

A.

Informal, soft controls are omitted, and greater focus is placed on hard controls.

B.

The entire objectives-risks-controls infrastructure of an organization is subject to greater monitoring and continuous improvement.

C.

Internal auditors become involved in and knowledgeable about the self-assessment process.

D.

Nonaudit employees become experienced in assessing controls and associating control processes with managing risks.

Buy Now
Questions 73

For which of the following fraud engagement activities would it be most appropriate to involve a forensic auditor?

Options:

A.

Independently evaluating conflicts of interests.

B.

Assessing contracts for relevant terms and conditions.

C.

Performing statistical analysis for data anomalies.

D.

Preparing evidentiary documentation.

Buy Now
Questions 74

An organization's internal audit plan includes a recurring assurance review of the human resources (HR) department. Which of the following statements is true regarding preliminary communication between the auditor in charge (AIC) and the HR department?

1. The AIC should notify HR management when the draft audit plan is being developed, as a courtesy.

2. The AIC should notify HR management before the planning stage begins.

3. The AIC should schedule formal status meetings with HR management at the start of the engagement.

4. The AIC should finalize the scope of the engagement before communicating with HR management.

Options:

A.

1 and 3

B.

1 and 4

C.

2 and 3

D.

2 and 4

Buy Now
Questions 75

An internal auditor and engagement client are deadlocked over the auditor's differing opinion with management on the adequacy of access controls for a major system. Which of the following strategies would be the most helpful in resolving this dispute?

Options:

A.

Conduct a joint brainstorming session with management.

B.

Ask the chief audit executive to mediate.

C.

Disclose the client's differing opinion in the final report.

D.

Escalate the issue to senior management for a decision.

Buy Now
Questions 76

The internal audit activity (IAA) wants to measure its performance related to the quality of audit recommendations. Which of the following client survey questions would best help the IAA meet this objective?

Options:

A.

Were audit findings relevant and useful to management?

B.

Does the audit report format present issues clearly and concisely?

C.

Does the IAA work with a high degree of professionalism and objectivity?

D.

Were the findings reported in a timely manner?

Buy Now
Questions 77

According to IIA guidance, which of the following would not be a consideration for the internal audit activity (IAA) when determining the need to follow-up on recommendations?

Options:

A.

Degree of effort and cost needed to correct the reported condition.

B.

Complexity of the corrective action.

C.

Impact that may result should the corrective action fail.

D.

Amount of resources required to conduct the follow-up activities.

Buy Now
Questions 78

An internal auditor is conducting an assessment of the purchasing department. She has worked the full amount of hours budgeted for the engagement; however, the audit objectives are not yet complete. According to IIA guidance, which of the following are appropriate options available to the chief audit executive?

1. Allow the auditor to decide whether to extend the audit engagement.

2. Determine whether the work already completed is sufficient to conclude the engagement.

3. Provide the auditor feedback on areas of improvement for future engagements.

4. Provide the auditor with instructions and directions to complete the audit.

Options:

A.

1, 2, and 3

B.

1, 2, and 4

C.

1, 3, and 4

D.

2, 3, and 4

Buy Now
Questions 79

A chief audit executive (CAE) is determining which engagements to include on the annual audit plan. She would like to consider the organization's attitude toward risk and the degree of difficulty in achieving objectives. Which of the following resources should the CAE consult?

Options:

A.

The corporate risk register.

B.

The strategic plan.

C.

Internal and external audit reports.

D.

The board's meeting records.

Buy Now
Questions 80

An internal auditor notes that employees continue to violate segregation-of-duty controls in several areas of the finance department, despite previous audit recommendations. Which of the following recommendations is the most appropriate to address this concern?

Options:

A.

Recommend additional segregation-of-duty reviews.

B.

Recommend appropriate awareness training for all finance department staff.

C.

Recommend rotating finance staff in this area.

D.

Recommend that management address these concerns immediately.

Buy Now
Questions 81

After the team member who specialized in fraud investigations left the internal audit team, the chief audit executive decided to outsource fraud investigations to a third party service provider on an as needed basis. Which of the following is most likely to be a disadvantage of this outsourcing decision?

Options:

A.

Cost.

B.

Independence.

C.

Familiarity.

D.

Flexibility.

Buy Now
Questions 82

Which of the following factors should a chief audit executive consider when determining the audit universe?

1. Components of the organization's strategic plan.

2. Inputs from senior management and the board.

3. Views of competitors and business associates.

4. Results of exit interviews with departing employees.

Options:

A.

1 and 2 only

B.

2 and 4 only

C.

1, 2, and 4

D.

2, 3, and 4

Buy Now
Questions 83

The chief audit executive of a medium-sized financial institution is evaluating the staffing model of the internal audit activity (IAA). According to IIA guidance, which of the following are the most appropriate strategies to maximize the value of the current IAA resources?

• The annual audit plan should include audits that are consistent with the skills of the IAA.

• Audits of high-risk areas of the organization should be conducted by internal audit staff.

• External resources may be hired to provide subject-matter expertise but should be supervised.

• Auditors should develop their skills by being assigned to complex audits for learning opportunities.

Options:

A.

1 and 2 only

B.

1 and 4 only

C.

2 and 3 only

D.

3 and 4 only

Buy Now
Questions 84

An internal control questionnaire would be most appropriate in which of the following situations?

Options:

A.

Testing controls where operating procedures vary.

B.

Testing controls in decentralized offices.

C.

Testing controls in high risk areas.

D.

Testing controls in areas with high control failure rates.

Buy Now
Questions 85

Which of the following best illustrates the primary focus of a risk-based approach to control self-assessment?

Options:

A.

To evaluate controls regarding the computer security of an oil refinery.

B.

To examine the processes involved in exploring, developing, and operating a gold mine.

C.

To assess the likelihood and impact of events associated with operating a finished goods warehouse.

D.

To link a financial institution's business objectives to a work unit responsible for the associated risk.

Buy Now
Questions 86

Which of the following is not a primary reason for outsourcing a portion of the internal audit activity?

Options:

A.

To gain access to a wider variety of skills, competencies and best practices.

B.

To complement existing expertise with a required skill and competency for a particular audit engagement.

C.

To focus on and strengthen core audit competencies.

D.

To provide the organization with appropriate contingency planning for the internal audit function.

Buy Now
Questions 87

When setting the scope for the identification and assessment of key risks and controls in a process, which of the following would be the least appropriate approach?

Options:

A.

Develop the scope of the audit based on a bottom-up perspective to ensure that all business objectives are considered.

B.

Develop the scope of the audit to include controls that are necessary to manage risk associated with a critical business objective.

C.

Specify that the auditors need to assess only key controls, but may include an assessment of non-key controls if there is value to the business in providing such assurance.

D.

Ensure the audit includes an assessment of manual and automated controls to determine whether business risks are effectively managed.

Buy Now
Questions 88

An internal auditor submitted a report containing recommendations for management to enhance internal controls related to investments. To follow up, which of the following is the most appropriate action for the internal auditor to take?

Options:

A.

Observe corrective measures.

B.

Seek a management assurance declaration.

C.

Follow up during the next scheduled audit.

D.

Conduct appropriate testing to verify management responses.

Buy Now
Questions 89

According to the Standards, which of the following is leastimportant in determining the adequacy of an annual audit plan?

Options:

A.

Sufficiency.

B.

Appropriateness.

C.

Effective deployment.

D.

Cost effectiveness.

Buy Now
Questions 90

According to IIA guidance, which of the following is true regarding audit supervision?

1. Supervision should be performed throughout the planning, examination, evaluation, communication, and follow-up stages of the audit engagement.

2. Supervision should extend to training, time reporting, and expense control, as well as administrative matters.

3. Supervision should include review of engagement workpapers, with documented evidence of the review.

Options:

A.

1 and 2 only

B.

1 and 3 only

C.

2 and 3 only

D.

1, 2, and 3

Buy Now
Exam Code: IIA-ACCA
Exam Name: ACCA CIA Challenge Exam
Last Update: Apr 17, 2024
Questions: 604
$64  $159.99
$48  $119.99
$40  $99.99
buy now IIA-ACCA