Summer Sale - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65percent

Welcome To DumpsPedia

IIA-CIA-Part3 Sample Questions Answers

Questions 4

Which of the following is a result of implementing an e-commerce system that relies heavily on electronic data interchange (EDI) and electronic funds transfer (EFT) for purchasing and billing?

Options:

A.

Higher cash flow and treasury balances.

B.

Higher inventory balances.

C.

Higher accounts receivable.

D.

Higher accounts payable.

Buy Now
Questions 5

Which of the following activities most significantly increases the risk that a bank will make poor-quality loans to its customers?

Options:

A.

Borrowers may not sign all required mortgage loan documentation.

B.

Fees paid by the borrower at the time of the loan may not be deposited in a timely manner.

C.

The bank ' s loan documentation may not meet the government ' s disclosure requirements.

D.

Loan officers may override the lending criteria established by senior management.

Buy Now
Questions 6

An organization’s income and retained earnings statement is as follows:

Sales: $3,000

Cost of goods sold: $1,600

Gross profit: $1,400

Operating expenses: $970

Operating income: $430

Interest expense: $30

Income before tax: $400

Income tax: $200

Net income: $200

Plus Jan. 1 retained earnings: $150

Less dividends: $60

Dec. 31 retained earnings: $290

Which of the following is the dividend payout ratio?

Options:

A.

20 percent.

B.

30 percent.

C.

40 percent.

D.

50 percent.

Buy Now
Questions 7

According to IIA guidance, which of the following would be the best first step to manage risk when a third party is overseeing the organization’s network and data?

Options:

A.

Creating a comprehensive reporting system for vendors to demonstrate their ongoing due diligence in network operations

B.

Drafting a strong contract that requires regular vendor control reports and a right-to-audit clause

C.

Applying administrative privileges to ensure right-to-access controls are appropriate

D.

Creating a standing cybersecurity committee to identify and manage risks related to data security

Buy Now
Questions 8

During an internal audit engagement, numerous deficiencies in the organization ' s management of customer data were discovered, entailing the risk of breaching personal data protection legislation. An improvement plan was approved by senior management. Which of the following conditions observed during the periodic follow-up process best justifies the chief audit executive ' s decision to escalate the issue to the board?

Options:

A.

The organization ' s customer satisfaction index does not show any signs of improvement

B.

No budget or resources have been allocated to implement corrective measures

C.

The board has not been informed about the planned improvements approved by senior management

D.

Employees responsible for improvements are resisting any additional workload

Buy Now
Questions 9

Which of the following issues is a concern that a database administrator may face when integrating an organization’s applications that were once operated separately?

Options:

A.

The integrity of the data created by the applications may be compromised by the integration.

B.

The number of users with access to the applications may decrease as a result of the integration.

C.

The cost of maintaining the integration of the applications may increase at the start of the process.

D.

The implementation of more security protocols on the applications may slow down user productivity.

Buy Now
Questions 10

An employee ' s mobile device used for work was stolen in a home burglary. Which control, if already implemented by the organization, would best prevent unauthorized access to organizational data stored on the employee ' s device?

Options:

A.

Access control via biometric authentication.

B.

Access control via passcode authentication.

C.

Access control via swipe pattern authentication.

D.

Access control via security question authentication.

Buy Now
Questions 11

Which of the following attributes of data is the most significantly impacted by the internet of things?

Options:

A.

Normalization

B.

Velocity

C.

Structuration

D.

Veracity

Buy Now
Questions 12

Which of these instances accurately describes the responsibilities for big data governance?

Options:

A.

Management must ensure information storage systems are appropriately defined and processes to update critical data elements are clear.

B.

External auditors must ensure that analytical models are periodically monitored and maintained.

C.

The board must implement controls around data quality dimensions to ensure that they are effective.

D.

Internal auditors must ensure the quality and security of data, with a heightened focus on the riskiest data elements.

Buy Now
Questions 13

An internal audit team performed an assurance engagement of the organization ' s IT security. The audit team found significant flaws in the design and implementation of the internal control framework. IT department managers often disagreed with the audit team on the significance of the findings, claiming that the controls in place partly mitigated the risks. Which of the following should be included when communicating the engagement results to senior management?

Options:

A.

All the correspondence exchanged between the audit team and IT department demonstrating the disagreement

B.

The audit team ' s findings and the IT department’s opinion

C.

Only the audit team ' s findings and the reasons they require immediate action from senior management

D.

Only the findings that were agreed upon between the audit team and the IT department

Buy Now
Questions 14

A chief audit executive (CAE) is developing a strategic plan for the internal audit function. In the last two years, the organization has faced significant IT risks, but the internal audit function has not been able to audit those areas due to a lack of knowledge. How could the CAE address this in the strategic plan?

Options:

A.

Purchase a data analytics program for the internal audit function

B.

Hold listening sessions to receive management ' s input on the strategic plan

C.

Develop a succession plan for the internal audit function to avoid staffing deficiencies

D.

Identify relevant training resources to strengthen staff skillsets

Buy Now
Questions 15

A clothing company sells shirts for $8 per shirt. In order to break even, the company must sell 25.000 shirts. Actual sales total S300.000. What is margin of safety sales for the company?

Options:

A.

$100.000

B.

$200,000

C.

$275,000

D.

$500,000

Buy Now
Questions 16

A rapidly expanding retail organisation continues to be tightly controlled by its original small management team. Which of the following is a potential risk in this vertically centralized organization?

Options:

A.

Lack of coordination among different business units

B.

Operational decisions are inconsistent with organizational goals

C.

Suboptimal decision making

D.

Duplication of business activities

Buy Now
Questions 17

With regard to disaster recovery planning, which of the following would most likely involve stakeholders from several departments?

Options:

A.

Determining the frequency with which backups will be performed.

B.

Prioritizing the order in which business systems would be restored.

C.

Assigning who in the IT department would be involved in the recovery procedures.

D.

Assessing the resources needed to meet the data recovery objectives.

Buy Now
Questions 18

Which of the following best describes the use of predictive analytics?

Options:

A.

A supplier of electrical parts analyzed an instances where different types of spare parts were out of stock prior to scheduled deliveries of those parts.

B.

A supplier of electrical parts analyzed sales, applied assumptions related to weather conditions, and identified locations where stock levels would decrease more quickly.

C.

A supplier of electrical parts analyzed all instances of a part being, out of stock poor to its scheduled delivery date and discovered that increases in sales of that part consistently correlated with stormy weather.

D.

A supplier of electrical parts analyzed sales and stock information and modelled different scenarios for making decisions on stock reordering and delivery

Buy Now
Questions 19

An organization has 1,000 units of a defective item in stock. Per unit, market price is $10; production cost is $4; and the defect selling price is $5. What is the carrying amount (inventory value) of defects at year-end?

Options:

A.

$0

B.

$4,000

C.

$5,000

D.

$10,000

Buy Now
Questions 20

An internal auditor observed that the organization ' s disaster recovery solution will make use of a cold site in a town several miles away. Which of the following is likely to be a characteristic of this disaster recovery solution?

Options:

A.

Data is synchronized in real time.

B.

Recovery time is expected to be less than one week.

C.

Servers are not available and need to be procured.

D.

Recovery resources and data restore processes have been defined.

Buy Now
Questions 21

The internal auditor concluded there was a high likelihood that a significant wind farm development, worth $200 million, would be delayed from its approved schedule. As a result, electricity production would not start on time, leading to considerable financial penalties. Which of the following should be added to the observation to support its clarity and completeness?

Options:

A.

The effect of the observation

B.

The criteria of the observation

C.

The condition of the observation

D.

The cause of the observation

Buy Now
Questions 22

A restaurant decided to expand its business to include delivery services, rather than relying on third-party food delivery services. Which of the following best describes the restaurants strategy?

Options:

A.

Diversification

B.

Vertical integration

C.

Risk avoidance

D.

Differentiation

Buy Now
Questions 23

The chief audit executive (CAE) has embraced a total quality management approach to improving the internal audit activity ' s (lAArs) processes. He would like to reduce the time to complete audits and improve client ratings of the IAA. Which of the following staffing approaches is the CAE most likely lo select?

Options:

A.

Assign a team with a trained audit manager to plan each audit and distribute field work tasks to various staff auditors.

B.

Assign a team of personnel who have different specialties to each audit and empower Team members to participate fully in key decisions

C.

Assign a team to each audit, designate a single person to be responsible for each phase of the audit, and limit decision making outside of their area of responsibility.

D.

Assign a team of personnel who have similar specialties to specific engagements that would benefit from those specialties and limit Key decisions to the senior person.

Buy Now
Questions 24

Which of the following would an organization execute to effectively mitigate and manage risks created by a crisis or event?

Options:

A.

Only preventive measures.

B.

Alternative and reactive measures.

C.

Preventive and alternative measures.

D.

Preventive and reactive measures.

Buy Now
Questions 25

A holding company set up a centralized group technology department, using a local area network with a mainframe computer to process accounting information for all companies within the group. An internal auditor would expect to find all of the following controls within the technology department except:

Options:

A.

Adequate segregation of duties between data processing controls and file security controls.

B.

Documented procedures for remote job entry and for local data file retention.

C.

Emergency and disaster recovery procedures and maintenance agreements in place to ensure continuity of operations.

D.

Established procedures to prevent and detect unauthorized changes to data files.

Buy Now
Questions 26

Which of the following roles would be least appropriate for the internal audit activity to undertake with regard to an organization ' s corporate social responsibility program?

Options:

A.

Consult on project design and implementation of the CSR program.

B.

Serve as an advisor on internal controls related to CSR.

C.

Identify and prioritize the CSR issues that are important to the organization.

D.

Evaluate the effectiveness of the organization ' s CSR efforts.

Buy Now
Questions 27

When reviewing application controls using the four-level model, which of the following processes are associated with level 4 of the business process method?

Options:

A.

Activity

B.

Subprocess

C.

Major process

D.

Mega process

Buy Now
Questions 28

Which of the following best describes the type of control provided by a firewall?

Options:

A.

Corrective

B.

Detective

C.

Preventive

D.

Discretionary

Buy Now
Questions 29

According to IIA guidance, which of the following is an IT project success factor?

Options:

A.

Streamlined decision-making, rather than building consensus among users.

B.

Consideration of the facts, rather than consideration of the emotions displayed by project stakeholders.

C.

Focus on flexibility and adaptability, rather than use of a formal methodology.

D.

Inclusion of critical features, rather than inclusion of an array of supplementary features.

Buy Now
Questions 30

All of the following are possible explanations for a significant unfavorable material efficiency variance except:

Options:

A.

Cutbacks in preventive maintenance.

B.

An inadequately trained and supervised labor force.

C.

A large number of rush orders.

D.

Production of more units than planned for in the master budget.

Buy Now
Questions 31

During an audit of the payroll system, the internal auditor identifies and documents the following condition:

" Once a user is logged into the system, the user has access to all functionality within the system. "

What is the most likely root cause for tins issue?

Options:

A.

The authentication process relies on a simple password only, which is a weak method of authorization.

B.

The system authorization of the user does not correctly reflect the access rights intended.

C.

There was no periodic review to validate access rights.

D.

The application owner apparently did not approve the access request during the provisioning process.

Buy Now
Questions 32

For which of the following scenarios would the most recent backup of the human resources database be the best source of information to use?

Options:

A.

An incorrect program fix was implemented just prior to the database backup.

B.

The organization is preparing to train all employees on the new self-service benefits system.

C.

There was a data center failure that requires restoring the system at the backup site.

D.

There is a need to access prior year-end training reports for all employees in the human resources database

Buy Now
Questions 33

Which of the following methods has the lowest risk of inaccurate authentication?

Options:

A.

Fingerprint identification.

B.

Complex passwords.

C.

Signature verification.

D.

Personal security questions.

Buy Now
Questions 34

An organization filters data packets from public networks to send to an internal private network.

Which of the following devices would accomplish this?

Options:

A.

A router.

B.

A switch.

C.

A hub.

D.

A proxy gateway.

Buy Now
Questions 35

An internationally recognized brand name is an entrance barrier to new competitors because new competitors would:

Options:

A.

Have to initiate a price war in order to enter the industry.

B.

Face increased production costs.

C.

Face increased marketing costs.

D.

Face higher learning costs, which would increase fixed costs.

Buy Now
Questions 36

Which of the following is improved by the use of smart devices?

Options:

A.

Version control

B.

Privacy

C.

Portability

D.

Secure authentication

Buy Now
Questions 37

An organization allows employees to use mobile devices for business purposes. Which of the following could cause decreased employee productivity in case of data loss?

Options:

A.

Malware resulting in data leakage.

B.

Exposure of sensitive data.

C.

Lack of data encryption.

D.

Lack of data backup.

Buy Now
Questions 38

As it relates to the data analytics process, which of the following best describes the purpose of an internal auditor who cleaned and normalized cate?

Options:

A.

The auditor eliminated duplicate information.

B.

The auditor organized data to minimize useless information.

C.

The auditor made data usable for a specific purpose by ensuring that anomalies were Identified and corrected.

D.

The auditor ensured data fields were consistent and that data could be used for a specific purpose.

Buy Now
Questions 39

Which of the following statements is true regarding internal audit methodologies?

Options:

A.

One of the main objectives of internal audit methodologies is to enable audit clients to validate audit observations

B.

IIA guidance states that they should be made available to all stakeholders on the organization’s webpage

C.

One of the main objectives of internal audit methodologies is to ensure the execution of organizational strategy and risk management

D.

Although the content of internal audit methodologies is determined by the chief audit executive, alignment with principles of confidentiality and competency must be demonstrated

Buy Now
Questions 40

Which of the following controls is the most effective in mitigating activities of bots that continuously attempt to access a user’s account?

Options:

A.

Password length.

B.

User session timeout.

C.

User account lockout.

D.

Password aging.

Buy Now
Questions 41

An internal auditor was asked to review an equal equity partnership, in one sampled transaction. Partner A transferred equipment into the partnership with a Self-declared value of 510 ,000, and Partner B contributed equipment with a self-declared value of 515,000. The capital accounts reach partner were subsequently credited with $12,500. Which of the following statements Is true regarding this transection?

Options:

A.

The capital accounts of the partners should be increased by she original cost of the contributed equipment.

B.

The capital accounts should be increased using a weighted average based by the current percentage of ownership.

C.

No action is needed, as the capital account of each partner was increased by the correct amount,

D.

The capital accounts of the partners should be increased by She fair market value of their contribution.

Buy Now
Questions 42

An organization ' s internal audit activity is performing an audit of human resources. As part of the audit a survey of employees was conducted. The survey indicated that employees were concerned about IT security when working outside of the office. The IT department suggested implementing a network that allows employees to send and receive data as if they were connected to a private network.

Which of the following networks is IT recommending?

Options:

A.

Global area network (GAN).

B.

Wide area network (WAN).

C.

Virtual private network (VPN).

D.

Local area network (LAN).

Buy Now
Questions 43

A technology developer has entered a two-year contract with another organization to design new software. According to IIA guidance, which of the following provisions of this agreement would be the most effective to protect the developer ' s product knowledge and expertise?

Options:

A.

The right to audit.

B.

A performance measurement system.

C.

Defined roles and responsibilities.

D.

Intellectual property rights.

Buy Now
Questions 44

According to the Standards, the internal audit activity must evaluate risk exposures relating to which of the following when examining an organization ' s risk management process?

    Organizational governance.

    Organizational operations.

    Organizational information systems.

    Organizational structure.

Options:

A.

1 and 3 only

B.

2 and 4 only

C.

1, 2, and 3 only

D.

1, 2, and 4 only

Buy Now
Questions 45

A manufacturer ss deciding whether to sell or process materials further. Which of the following costs would be relevant to this decision?

Options:

A.

Incremental processing costs, incremental revenue, and variable manufacturing expenses.

B.

Joint costs, incremental processing costs, and variable manufacturing expenses.

C.

Incremental revenue, joint costs, and incremental processing costs.

D.

Variable manufacturing expenses, incremental revenue, and joint costs

Buy Now
Questions 46

Which of the following accounting methods is an investor organization likely to use when buying 40 percent of the stock of another organization?

Options:

A.

Cost method.

B.

Equity method .

C.

Consolidation method.

D.

Fair value method.

Buy Now
Questions 47

An organization that sells products to a foreign subsidiary wants to charge a price that will decrease import tariffs. Which of the following is the best course of action for the organization?

Options:

A.

Decrease the transfer price.

B.

Increase the transfer price.

C.

Charge at the arm’s length price.

D.

Charge at the optimal transfer price.

Buy Now
Questions 48

Which of the following techniques would best detect an inventory fraud scheme?

Options:

A.

Analyze Invoice payments just under individual authorization limits.

B.

Analyze stratification of inventory adjustments by warehouse location.

C.

Analyze inventory invoice amounts and compare with approved contract amounts.

D.

Analyze differences discovered during duplicate payment testing

Buy Now
Questions 49

An organization had three large centralized divisions: one that received customer orders for service work; one that scheduled the service work at customer locations; and one that answered customer calls about service problems. These three divisions were restructured into seven regional groups, each of which performed all three functions. One advantage of this restructuring would be:

Options:

A.

Better internal controls.

B.

Greater economies of scale.

C.

Improved workflow.

D.

Increased specialization.

Buy Now
Questions 50

The decision to implement enhanced failure detection and backup systems to improve data integrity is an example of which risk response?

Options:

A.

Risk acceptance.

B.

Risk sharing.

C.

Risk avoidance.

D.

Risk reduction.

Buy Now
Questions 51

Which of the following types of accounts must be closed at the end of the period?

Options:

A.

Income statement accounts.

B.

Balance sheet accounts.

C.

Permanent accounts.

D.

Real accounts.

Buy Now
Questions 52

Which of the following activities best illustrates a user ' s authentication control?

Options:

A.

Identity requests are approved in two steps.

B.

Logs are checked for misaligned identities and access rights.

C.

Users have to validate their identity with a smart card.

D.

Functions can toe performed based on access rights

Buy Now
Questions 53

In an organization that produces chocolate, the leadership team decides that the organization will open a milk production facility for its milk chocolate. Which of the following strategies have the organization chosen?

Options:

A.

Vertical integration.

B.

Unrelated diversification.

C.

Differentiation

D.

Focus

Buy Now
Questions 54

Which of the following is true of matrix organizations?

Options:

A.

A unity-of-command concept requires employees to report technically, functionally, and administratively to the same manager.

B.

A combination of product and functional departments allows management to utilize personnel from various Junctions.

C.

Authority, responsibility and accountability of the units Involved may vary based on the project ' s life, or the organization ' s culture

D.

It is best suited for firms with scattered locations or for multi-line, Large-scale firms.

Buy Now
Questions 55

Which of the following statements regarding organizational structures is true?

Options:

A.

Decentralized organizations tend to have written rules, established procedures, and a high level of uniformity.

B.

Centralized organizations tend to be more efficient and make faster decisions.

C.

Centralized organizations tend to have less control at the top management level.

D.

Decentralized organizations’ power is more dispersed and is based on the regional managers’ knowledge.

Buy Now
Questions 56

Which of the following physical access controls is most likely to be based on the " something you have " concept?

Options:

A.

A retina characteristics reader.

B.

A PIN code reader.

C.

A card-key scanner.

D.

A fingerprint scanner.

Buy Now
Questions 57

According to IIA guidance, which of the following links computers and enables them to -communicate with each other?

Options:

A.

Application program code

B.

Database system

C.

Operating system

D.

Networks

Buy Now
Questions 58

Internal auditors are reviewing change management processes involving the organization’s IT department.

Which of the following is a characteristic of an ineffective change management process that would impact the organization’s clients?

Options:

A.

Projects delays result in lost opportunities in emerging markets against the competition.

B.

Flaws in the network create the risk of premature press releases that describe details about upcoming products.

C.

Changing priorities result in resources being moved from planned IT projects to unplanned projects.

D.

Staffing shortages result in prolonged delays related to addressing concerns about services.

Buy Now
Questions 59

During a visit to an oil production plant, an internal auditor was surprised to see the accounting employees shopping online using work computers. The auditor knew that the company ' s policy did not allow access to certain webpages, including those being used for online shopping.

Which of the following should the auditor study next to explore the observation further?

Options:

A.

The company’s training policy on social media.

B.

The company’s firewall configuration rules.

C.

The company’s access point encryption settings.

D.

The company’s software installation controls.

Buy Now
Questions 60

Which of the following is the most appropriate way lo record each partner ' s initial Investment in a partnership?

Options:

A.

At the value agreed upon by the partners.

B.

At book value.

C.

At fair value

D.

At the original cost.

Buy Now
Questions 61

Which of the following best describes the primary objective of cybersecurity?

Options:

A.

To protect the effective performance of IT general and application controls.

B.

To regulate users ' behavior it the web and cloud environment.

C.

To prevent unauthorized access to information assets.

D.

To secure application of protocols and authorization routines.

Buy Now
Questions 62

An organization is projecting sales of 100,000 units, at a unit price of $12. Unit variable costs are $7. If fixed costs are $350,000, what is the projected total contribution margin?

Options:

A.

$350,000

B.

$500,000

C.

$850,000

D.

$1,200,000

Buy Now
Questions 63

When determining the level of physical controls required for a workstation, which of the following factors should be considered?

Options:

A.

Ease of use.

B.

Value to the business.

C.

Intrusion prevention.

D.

Ergonomic model.

Buy Now
Questions 64

In an analysis of alternative credit-management policies, which of the following components will cause the net present value of receivables on credit sales to increase, if everything else remains constant?

Options:

A.

A tougher collections policy that reduces the bad debt loss ratio.

B.

A higher cost per unit sold.

C.

A longer average collection period.

D.

An increase in the cost of capital.

Buy Now
Questions 65

Which of the following statements best describes the current state of data privacy regulation?

Options:

A.

Regulations related to privacy are evolving and complex, and the number of laws is increasing

B.

Most privacy laws are prescriptive and focused on organizations’ privacy rights

C.

The concept of data privacy is well established, privacy regulations are mature, and minimal regulatory changes are expected

D.

Because the concept of privacy is different around the world, data privacy is relatively unregulated

Buy Now
Questions 66

An organization plans to upgrade its IT network to address a recent ransomware incident that hampered operations for weeks. The ransomware was the result of lapses in access to the network that exposed sensitive information.

Which of the following is a risk that could significantly be impacted by the organization’s planned change to its IT network?

Options:

A.

The organization lacks the necessary senior management to ensure that project objectives are met.

B.

The organization’s recent hiring of additional staff to the IT department would create more scrutiny of end user activity.

C.

The organization creates new processes and policies that employees feel are too burdensome.

D.

The organization experiences continuing issues that hamper employees’ ability to provide quality customer service.

Buy Now
Questions 67

According to UA guidance on IT, at which of the following stages of the project life cycle would the project manager most likely address the need to coordinate project resources?

Options:

A.

Initiation.

B.

Planning.

C.

Execution.

D.

Monitoring.

Buy Now
Questions 68

Which of the following is likely to occur when an organization decides to adopt a decentralized organizational structure?

Options:

A.

A slower response to external change.

B.

Less controlled decision making.

C.

More burden on higher-level managers.

D.

Less use of employees ' true skills and abilities.

Buy Now
Questions 69

Which of the following would most likely be found in an organization that uses a decentralized organizational structure?

Options:

A.

There is a higher reliance on organizational culture.

B.

There are clear expectations set for employees.

C.

There are electronic monitoring techniques employed.

D.

There is a defined code for employee behavior.

Buy Now
Questions 70

Which of the following risks would involve individuals attacking an oil company’s IT system as a sign of solidarity against drilling in a local area?

Options:

A.

Tampering

B.

Hacking

C.

Phishing

D.

Piracy

Buy Now
Questions 71

Listening effectiveness is best increased by:

Options:

A.

Resisting both internal and external distractions.

B.

Waiting to review key concepts until the speaker has finished talking.

C.

Tuning out messages that do not seem to fit the meeting purpose.

D.

Factoring in biases in order to evaluate the information being given.

Buy Now
Questions 72

Which of the following situations best applies to an organisation that uses a project, rather than a process, to accomplish its business activities?

Options:

A.

Clothing company designs, makes, and sells a new item.

B.

A commercial construction company is hired to build a warehouse.

C.

A city department sets up a new firefighter training program.

D.

A manufacturing organization acquires component parts from a contracted vendor

Buy Now
Questions 73

An organization is planning to outsource its payroll function to an external service provider. The internal auditors advised management of the risks related to outsourcing and the typical controls that should be provided by the external service provider.

Which of the following statements is true regarding the internal auditors’ advice?

Options:

A.

Independence was compromised by recommending internal controls, as the internal auditors will be testing the same controls in the future.

B.

Objectivity was compromised by intervening before the outsourcing procedures and controls were established.

C.

The internal auditors should work directly with the external service provider to ensure basic controls are in place and working as intended.

D.

The external service provider controls recommended by the internal auditors may be insufficient to protect the organization.

Buy Now
Questions 74

An internal auditor was assigned to test for ghost employees using data analytics. The auditor extracted employee data from human resources and payroll. Using spreadsheet functions, the auditor matched data sets by name and assumed that employees who were not present in each data set should be investigated further. However, the results seemed erroneous, as very few employees matched across all data sets. Which of the following data analytics steps has the auditor most likely omitted?

Options:

A.

Data analysis.

B.

Data diagnostics.

C.

Data velocity.

D.

Data normalization.

Buy Now
Questions 75

During her annual performance review, a sales manager admits that she experiences significant stress due to her job but stays with the organization because of the high bonuses she earns. Which of the following best describes her primary motivation to remain in the job?

Options:

A.

Intrinsic reward.

B.

Job enrichment

C.

Extrinsic reward.

D.

The hierarchy of needs.

Buy Now
Questions 76

During a payroll audit, the internal auditor is assessing the security of the local area network of the payroll department computers. Which of the following IT controls should the auditor test?

Options:

A.

IT application-based controls

B.

IT systems development controls

C.

Environmental controls

D.

IT governance controls

Buy Now
Questions 77

Which of the following actions would senior management need to consider as part of new IT guidelines regarding the organization ' s cybersecurity policies?

Options:

A.

Assigning new roles and responsibilities for senior IT management.

B.

Growing use of bring your own devices for organizational matters.

C.

Expansion of operations into new markets with limited IT access.

D.

Hiring new personnel within the IT department for security purposes.

Buy Now
Questions 78

According to IIA guidance, which of the following statements is true regarding analytical procedures?

Options:

A.

Data relationships are assumed to exist and to continue where no known conflicting conditions exist

B.

Analytical procedures are intended primarily to ensure the accuracy of the information being examined

C.

Data relationships cannot include comparisons between operational and statistical data

D.

Analytical procedures can be used to identify differences, but cannot be used to identify the absence of differences

Buy Now
Questions 79

The first stage in the development of a crisis management program is to:

Options:

A.

Formulate contingency plans.

B.

Conduct a risk analysis.

C.

Create a crisis management team.

D.

Practice the response to a crisis.

Buy Now
Questions 80

Which of the following financial statements provides the best disclosure of how a company ' s money was used during a particular period?

Options:

A.

Income statement.

B.

Owner ' s equity statement.

C.

Balance sheet.

D.

Statement of cash flows.

Buy Now
Questions 81

Which of the following best describes depreciation?

Options:

A.

It is a process of allocating cost of assets between periods.

B.

It is a process of assets valuation.

C.

It is a process of accumulating adequate funds to replace assets.

D.

It is a process of measuring decline in the value of assets because of obsolescence

Buy Now
Questions 82

Which of the following activities would come last in the development and implementation of a privacy and data protection program?

Options:

A.

Selecting the privacy and data protection framework.

B.

Establishing an assessment and communication format.

C.

Defining the scope of implementation procedures.

D.

Defining the privacy and data protection risks.

Buy Now
Questions 83

While performing an audit of a car tire manufacturing plant, an internal auditor noticed a significant decrease in the number of tires produced from the previous operating

period. To determine whether worker inefficiency caused the decrease, what additional information should the auditor request?

Options:

A.

Total tire production labor hours for the operating period.

B.

Total tire production costs for the operating period.

C.

Plant production employee headcount average for the operating period.

D.

The production machinery utilization rates.

Buy Now
Questions 84

A large pharmaceutical company would most likely use which of the following to determine liquidity?

Options:

A.

Earnings per share.

B.

Asset turnover ratio.

C.

Net income.

D.

Current ratio.

Buy Now
Questions 85

Which of the following is the best example of IT governance controls?

Options:

A.

Controls that focus on segregation of duties, financial, and change management,

B.

Personnel policies that define and enforce conditions for staff in sensitive IT areas.

C.

Standards that support IT policies by more specifically defining required actions

D.

Controls that focus on data structures and the minimum level of documentation required

Buy Now
Questions 86

According to Herzberg ' s Two-Factor Theory of Motivation, which of the following is a factor mentioned most often by satisfied employees?

Options:

A.

Relationship with supervisor

B.

Salary

C.

Security.

D.

Achievement

Buy Now
Questions 87

A manager who is authorized to make purchases up to a certain dollar amount approves the set-up of a fictitious vendor and subsequently initiates purchase orders. Which of the following controls would best address this risk?

Options:

A.

Establish separate vendor creation and approval teams.

B.

Develop and distribute a code of conduct that prohibits conflicts of interest.

C.

Perform a regular review of the vendor master file.

D.

Require submission of a conflict-of-interest declaration.

Buy Now
Questions 88

Which of the following strategies is most appropriate for an industry that is in decline?

Options:

A.

Invest in marketing.

B.

Invest in research and development.

C.

Control costs.

D.

Shift toward mass production.

Buy Now
Questions 89

Which of the following performance measures includes both profits and investment base?

Options:

A.

Residual income

B.

A flexible budget

C.

Variance analysis.

D.

A contribution margin income statement by segment.

Buy Now
Questions 90

Which of the following statements about assurance maps is true?

Options:

A.

They help identify gaps and duplications in an organization’s assurance coverage

B.

They allow the board to coordinate activities of internal and external assurance providers

C.

They help identify which assurance provider is responsible for performing each audit listed in the annual internal audit plan

D.

They allow internal auditors to map competencies and specialty areas of the assurance providers in an organization

Buy Now
Questions 91

An internal auditor wishes to test why there was a significant drop in accounts payable volume last month and creates several scenarios to help explain the anomaly.

Which of the following best describes this data analysis technique?

Options:

A.

Descriptive.

B.

Diagnostic.

C.

Predictive.

D.

Prescriptive.

Buy Now
Questions 92

A new internal auditor is collecting and analyzing data to investigate potential duplication of customer information. The data includes information unique to each customer. Which of the following should the auditor do to protect the customer data used for the analysis?

Options:

A.

Ensure that the data is secured on the auditor ' s storage device.

B.

Ensure that the data is stored in a cloud management system.

C.

Ensure that the data is protected through the use of a client-privilege agreement.

D.

Ensure that the data is safeguarded as required by established policies.

Buy Now
Questions 93

In reviewing an organization ' s IT infrastructure risks, which of the following controls is to be tested as pan of reviewing workstations?

Options:

A.

Input controls

B.

Segregation of duties

C.

Physical controls

D.

Integrity controls

Buy Now
Questions 94

Internal audit discovered that several loads of pellets were deleted from the scaling database and consequently had no sales invoices, significantly affecting financial statements. An investigation revealed that technicians had deleted the pellet loads accidentally, with no evidence of fraud. Which of the following actions should management implement first?

Options:

A.

Address root causes by launching a project to understand and revise the methods for granting database access rights

B.

Address the condition by limiting technicians ' access to live database data

C.

Address potential risks by reconciling all sales invoices against scaling data

D.

Address investigation results by dismissing technicians who caused the disruption

Buy Now
Questions 95

What would an internal auditor do to ensure that a process to mitigate risk is in place for the organization ' s change management process?

Options:

A.

Develop and enforce change policies to ensure employees are continually trained.

B.

Apply a risk-based approach and impose segregation of duties related to the change management process.

C.

Conduct a high-level threat analysis and implement a compensating control.

D.

Validate authorization, segregation of duties, testing of changes, and approval to move changes into production.

Buy Now
Questions 96

An internal auditor found that several employees of a vendor were authorized to remotely access the internal assets management system.

Which of the following should the auditor determine next?

Options:

A.

Whether there is a documented business need for the access.

B.

Whether access rights granted to vendor employees are read-only.

C.

Who to inform regarding the need to remove vendor employees’ access rights.

D.

Who manages vendor employees’ devices used to access the system.

Buy Now
Questions 97

According to IIA guidance on IT, which of the following controls the routing of data packets to link computers?

Options:

A.

Operating system.

B.

Control environment.

C.

Network.

D.

Application program code.

Buy Now
Questions 98

A capital investment project will have a higher net present value, everything else being equal, if it has:

Options:

A.

A higher initial investment level.

B.

A higher discount rate.

C.

Cash inflows that are larger in the later years of the life of the project.

D.

Cash inflows that are larger in the earlier years of the life of the project.

Buy Now
Questions 99

To assess the effectiveness of an organization ' s privacy program, which of the following approaches should an internal auditor take?

Options:

A.

Conduct a series of employee interviews.

B.

Conduct penetration tests.

C.

Review privacy policies and procedures.

D.

Analyze the life cycle of sensitive data.

Buy Now
Questions 100

Which of the following statements is true regarding cost-volume-profit analysis?

Options:

A.

Contribution margin is the amount remaining from sales revenue after fixed expenses have been deducted.

B.

Breakeven point is the amount of units sold to cover variable costs.

C.

Breakeven occurs when the contribution margin covers fixed costs.

D.

Following breakover1, he operating income will increase by the excess of fixed costs less the variable costs per units sold.

Buy Now
Questions 101

An organization that soils products to a foreign subsidiary wants to charge a price that wilt decrease import tariffs. Which of the following is the best course of action for the organization?

Options:

A.

Decrease the transfer price

B.

Increase the transfer price

C.

Charge at the arm ' s length price

D.

Charge at the optimal transfer price

Buy Now
Questions 102

Which of the following is the most appropriate way to record each partner’s initial investment in a partnership?

Options:

A.

At the value agreed upon by the partners

B.

At book value

C.

At fair value

D.

At the original cost

Buy Now
Questions 103

The process of scenario planning begins with which of the following steps?

Options:

A.

Determining the trends that will influence key factors in the organization ' s environment.

B.

Selecting the issue or decision that will impact how the organization conducts future business.

C.

Selecting leading indicators to alert the organization of future developments.

D.

Identifying how customers, suppliers, competitors, employees, and other stakeholders will react.

Buy Now
Questions 104

Which of the following would be classified as IT general controls?

Options:

A.

Error listings.

B.

Distribution controls.

C.

Transaction logging.

D.

Systems development controls.

Buy Now
Questions 105

Which of the following price adjustment strategies encourages prompt payment?

Options:

A.

Cash discounts.

B.

Quantity discounts.

C.

Functional discounts.

D.

Seasonal discounts.

Buy Now
Questions 106

An organization requires an average of 5S days to convert raw materials into finished products to sell. An average of 42 additional days is required to collect receivables. If the organization takes an average of 10 days to pay for the raw materials, how long is its total cash conversion cycle?

Options:

A.

26 days.

B.

90 days,

C.

100 days.

D.

110 days

Buy Now
Questions 107

Which component of an organization ' s cybersecurity risk assessment framework would allow management to implement user controls based on a user ' s role?

Options:

A.

Prompt response and remediation policy

B.

Inventory of information assets

C.

Information access management

D.

Standard security configurations

Buy Now
Questions 108

An investor has acquired an organization that has a dominant position in a mature. slew-growth Industry and consistently creates positive financial income.

Which of the following terms would the investor most likely label this investment in her portfolio?

Options:

A.

A star

B.

A cash cow

C.

A question mark

D.

A dog

Buy Now
Questions 109

With regard to project management, which of the following statements about project crashing is true?

Options:

A.

It leads to an increase in risk and often results in rework.

B.

It is an optimization technique where activities are performed in parallel rather than sequentially.

C.

It involves a revaluation of project requirements and/or scope.

D.

It is a compression technique in which resources are added to the project.

Buy Now
Questions 110

Which of the following is a true statement regarding the primary functionality of firewalls?

Options:

A.

All firewalls intercept and decode data all the way up the stack to the application layer.

B.

All firewalls receive, process, and transmit data within the network via physical media.

C.

All firewalls monitor and control incoming and outgoing traffic in accordance with predefined rules.

D.

All firewalls secure encryption of data transfer between various users in the organization.

Buy Now
Questions 111

Which of the following is used during all three stages of project management?

Options:

A.

Earned Value Management (EVM).

B.

Organizational procedures.

C.

Performance measurement.

D.

Project Management Information System (PMIS).

Buy Now
Questions 112

An organization produces finished lumber for the construction industry.

Which of the following inventory valuation methods will lead to the highest profit, assuming all other variables remain the same in a period of rising material costs?

Options:

A.

Average-cost method.

B.

Weighted cost method.

C.

First-in, first-out (FIFO).

D.

Specific identification.

Buy Now
Questions 113

An internal auditor is reviewing physical and environmental controls for an IT organization. Which control activity should not be part of this review?

Options:

A.

Develop and test the organization ' s disaster recovery plan.

B.

Install and test fire detection and suppression equipment.

C.

Restrict access to tangible IT resources.

D.

Ensure that at least one developer has access to both systems and operations.

Buy Now
Questions 114

Which of the following techniques would best detect on inventory fraud scheme?

Options:

A.

Analyze invoice payments just under individual authorization limits.

B.

Analyze stratification of inventory adjustments by warehouse location.

C.

Analyze Inventory Invoice amounts and compare with approved contract amounts.

D.

Analyze differences discovered curing duplicate payment testing.

Buy Now
Questions 115

For a multinational organization, which of the following is a disadvantage of an ethnocentric staffing policy?

    It significantly raises compensation and staffing costs.

    It produces resentment among the organization ' s employees in host countries.

    It limits career mobility for parent-country nationals.

    It can lead to cultural myopia.

Options:

A.

1 and 4 only

B.

2 and 3 only

C.

1, 2, and 3 only

D.

1, 2, and 4 only

Buy Now
Questions 116

During a routine bank branch audit, the internal audit function observed that the sole security guard at the branch only worked part time. The chief audit executive (CAE) believed that this increased the risk of loss of property and life in the event of a robbery. The branch security manager informed the CAE that a full-time guard was not needed because the branch was in close proximity to a police station. Still, the CAE found this to be an unacceptable risk due to the recent increase in robberies in that area. Which of the following is the most appropriate next step for the CAE to take?

Options:

A.

Immediately report the issue to the board to ensure timely corrective actions are taken to resolve the risk

B.

Continue discussions with the security manager until he is persuaded and agrees to increase branch security

C.

Document the security manager’s decision to accept the risk in the audit workpapers

D.

Escalate the issue to the bank’s chief security officer to determine acceptability of the risk

Buy Now
Questions 117

A supervisor receives a complaint from an employee who is frustrated about having to learn a new software program. The supervisor responds that the new software will enable the employee to work more efficiently and with greater accuracy. This response is an example of:

Options:

A.

Empathetic listening.

B.

Reframing.

C.

Reflective listening.

D.

Dialogue.

Buy Now
Questions 118

A motivational technique generally used to overcome monotony and job-related boredom is:

Options:

A.

Job specification.

B.

Job objectives.

C.

Job rotation.

D.

Job description.

Buy Now
Questions 119

Which of the following describes the free trade zone in an e-commerce environment?

Options:

A.

Zone that separates an organization ' s servers from outside forces.

B.

Area in which messages are scrutinized to determine if they are authorized.

C.

Area where communication and transactions occur between trusted parties.

D.

Zone where data is encrypted, users are authenticated, and user traffic is filtered.

Buy Now
Questions 120

When granting third parties temporary access to an entity ' s computer systems, which of the following is the most effective control?

Options:

A.

Access is approved by the supervising manager.

B.

User accounts specify expiration dates and are based on services provided.

C.

Administrator access is provided for a limited period.

D.

User accounts are deleted when the work is completed.

Buy Now
Questions 121

An organization had a gross profit margin of 40 percent in year one and in year two. The net profit margin was 18 percent in year one and 13 percent in year two. Which of the following could be the reason for the decline in the net profit margin for year two?

Options:

A.

Cost of sales increased relative to sales.

B.

Total sales increased relative to expenses.

C.

The organization had a higher dividend payout rate in year two.

D.

The government increased the corporate tax rate

Buy Now
Questions 122

A small furniture-manufacturing firm with 100 employees is located in a two-story building and does not plan to expand. The furniture manufactured is not special-ordered or custom-made. The most likely structure for this organization would be:

Options:

A.

Functional departmentalization.

B.

Product departmentalization.

C.

Matrix organization.

D.

Divisional organization.

Buy Now
Questions 123

An organization and its trading partner rely on a computer-to-computer exchange of digital business documents. Which of the following best describes this scenario?

Options:

A.

Use of a central processing unit

B.

Use of a database management system

C.

Use of a local area network

D.

Use of electronic data Interchange

Buy Now
Questions 124

A new chief audit executive (CAE) reviews long overdue audit recommendations, which have been repeatedly reported to senior management but have not been implemented, and is unsure which issues should be escalated to the board. Which of the following would serve as the best guide in this scenario?

Options:

A.

The CAE ' s personal judgment

B.

The organization ' s code of conduct

C.

The organization ' s risk acceptance policy

D.

The organization ' s internal audit charter

Buy Now
Questions 125

Which of the following represents a basis for consolidation under the International Financial Reporting Standards?

Options:

A.

Variable entity approach.

B.

Control ownership.

C.

Risk and reward.

D.

Voting interest.

Buy Now
Questions 126

Which of the following measures immediate liquidity?

Options:

A.

Acid-test (quick) ratio.

B.

Current ratio.

C.

Profit margin.

D.

Times interest earned.

Buy Now
Questions 127

Which of the following attributes of data analytics relates to the growing number of sources from which data is being generated?

Options:

A.

Volume.

B.

Velocity.

C.

Variety.

D.

Veracity.

Buy Now
Questions 128

Which of the following IT-related activities is most commonly performed by the second line of defense?

Options:

A.

Block unauthorized traffic.

B.

Encrypt data.

C.

Review disaster recovery test results.

D.

Provide an independent assessment of IT security.

Buy Now
Questions 129

An organization ' s internal audit activity performed an engagement regarding recent contract bidding. Who should the internal audit activity meet with in order to obtain reliable and relevant information about potential questionable practices related to the contract bidding?

Options:

A.

Senior management, to obtain an understanding about the justification for contract bidding.

B.

Personnel responsible for the organization ' s fraud and ethics hotline, to obtain information related to contract bidding.

C.

Potential vendors, to obtain information about the bid packages related to contract bidding.

D.

Contracting department personnel to obtain information related to contract bidding practices.

Buy Now
Questions 130

Which of the following risks is best addressed by encryption?

Options:

A.

Information integrity risk.

B.

Privacy risk.

C.

Access risk.

D.

Software risk.

Buy Now
Questions 131

When executive compensation is based on the organization ' s financial results, which of the following situations is most likely to arise?

Options:

A.

The organization reports inappropriate estimates and accruals due to poof accounting controls.

B.

The organization uses an unreliable process forgathering and reporting executive compensation data.

C.

The organization experiences increasing discontent of employees, if executives are eligible for compensation amounts that are deemed unreasonable.

D.

The organization encourages employee behavior that is inconsistent with the interests of relevant stakeholders.

Buy Now
Questions 132

Which of the following is the most appropriate action an internal auditor would perform during an audit of his organization ' s IT change management process?

Options:

A.

Validate that only authorized personnel can migrate changes into the production environment.

B.

Perform a risk assessment to determine the likelihood that risk could occur due to insufficient patch application.

C.

Publish a schedule that lists all approved changes and planned implementation dates.

D.

Update change management processes on a consistent basis to keep up with changing technologies.

Buy Now
Questions 133

According to IIA guidance, which of the following corporate social responsibility evaluation activities may be performed by the internal audit activity?

    Consult on CSR program design and implementation.

    Serve as an advisor on CSR governance and risk management.

    Review third parties for contractual compliance with CSR terms.

    Identify and mitigate risks to help meet the CSR program objectives.

Options:

A.

1, 2, and 3

B.

1, 2, and 4

C.

1, 3, and 4

D.

2, 3, and 4

Buy Now
Questions 134

When developing an effective risk-based plan to determine audit priorities, an internal audit activity should start by:

Options:

A.

Identifying risks to the organization ' s operations.

B.

Observing and analyzing controls.

C.

Prioritizing known risks.

D.

Reviewing organizational objectives.

Buy Now
Questions 135

According to the International Professional Practices Framework, internal auditors who are assessing the adequacy of organizational risk management processes should not:

Options:

A.

Recognize that organizations use different techniques for managing risk.

B.

Seek assurance that the key objectives of the risk management processes are being met.

C.

Determine and accept the level of risk for the organization.

D.

Treat the evaluation of risk management processes differently from the risk analysis used to plan audit engagements.

Buy Now
Questions 136

Which of the following statements is true regarding an organization ' s chief audit executive (CAE) when prioritizing the audit universe?

Options:

A.

The CAE uses the risk-factor approach to prioritize the audit universe

B.

The CAE uses risk likelihood scores to prioritize the audit universe

C.

The CAE uses risk impact scores to prioritize the audit universe

D.

The CAE uses heat maps to prioritize the audit universe

Buy Now
Questions 137

What kind of strategy would be most effective for an organization to adopt in order to implement a unique advertising campaign for selling identical products across all of its markets?

Options:

A.

Export strategy.

B.

Transnational strategy.

C.

Multi-domestic strategy.

D.

Globalization strategy.

Buy Now
Questions 138

Which of the following is an example of a smart device security control intended to prevent unauthorized users from gaining access to a device’s data or applications?

Options:

A.

Anti-malware software

B.

Authentication

C.

Spyware

D.

Rooting

Buy Now
Questions 139

Which of the following is the primary goal of an effective business impact analysis?

Options:

A.

It includes business continuity program governance and risk management.

B.

It identifies key assets, critical processes, resources, and technology.

C.

It sets testing requirements for the organization wide continuity functions.

D.

It outlines and communicates recovery points and objectives.

Buy Now
Questions 140

Internal auditors want to increase the likelihood of identifying very small control and transaction anomalies in their testing that could potentially be exploited to cause material breaches. Which of the following techniques would best meet this objective?

Options:

A.

Analysis of the full population of existing data.

B.

Verification of the completeness and integrity of existing data.

C.

Continuous monitoring on a repetitive basis.

D.

Analysis of the databases of partners, such as suppliers.

Buy Now
Questions 141

Which stage of group development is characterized by a decrease in conflict and hostility among group members and an increase in cohesiveness?

Options:

A.

Forming stage.

B.

Norming stage.

C.

Performing stage.

D.

Storming stage.

Buy Now
Questions 142

An organization has instituted a bring-your-own-device (BYOD) work environment. Which of the following policies best addresses the increased risk to the organization ' s network incurred by this environment?

Options:

A.

Limit the use of the employee devices for personal use to mitigate the risk of exposure to organizational data.

B.

Ensure that relevant access to key applications is strictly controlled through an approval and review process.

C.

Institute detection and authentication controls for all devices used for network connectivity and data storage.

D.

Use management software scan and then prompt parch reminders when devices connect to the network

Buy Now
Questions 143

A retail organization mistakenly did not include $10,000 of inventory in the physical count at the end of the year. What was the impact to the organization’s financial statements?

Options:

A.

Cost of sales and net income are understated

B.

Cost of sales and net income are overstated

C.

Cost of sales is understated and net income is overstated

D.

Cost of sales is overstated and net income is understated

Buy Now
Questions 144

Which of the following is a systems software control?

Options:

A.

Restricting server room access to specific individuals

B.

Housing servers with sensitive software away from environmental hazards

C.

Ensuring that all user requirements are documented

D.

Performing of intrusion testing on a regular basis

Buy Now
Questions 145

Which of the following are the most appropriate measures for evaluating the change in an organization ' s liquidity position?

Options:

A.

Times interest earned, return on assets, and inventory turnover.

B.

Accounts receivable turnover, inventory turnover in days, and the current ratio.

C.

Accounts receivable turnover, return on assets, and the current ratio.

D.

Inventory turnover in days, the current ratio, and return on equity.

Buy Now
Questions 146

According to IIA guidance, whose input must be considered when developing the annual internal audit plan?

Options:

A.

Operational management

B.

External auditors

C.

The CEO

D.

Internal assurance providers

Buy Now
Questions 147

With increased cybersecurity threats, which of the following should management consider to ensure that there is strong security governance in place?

Options:

A.

Inventory of information assets

B.

Limited sharing of data files with external parties.

C.

Vulnerability assessment

D.

Clearly defined policies

Buy Now
Questions 148

Which of the following situations best illustrates a " false positive " in the performance of a spam filter?

Options:

A.

The spam filter removed Incoming communication that included certain keywords and domains.

B.

The spam filter deleted commercial ads automatically, as they were recognized as unwanted.

C.

The spam filter routed to the " junk|r folder a newsletter that appeared to include links to fake websites.

D.

The spam filter blocked a fitness club gift card that coworkers sent to an employee for her birthday.

Buy Now
Questions 149

Which of the following principles is shared by both hierarchical and open organizational structures?

A superior can delegate the authority to make decisions but cannot delegate the ultimate responsibility for the results of those decisions.

A supervisor ' s span of control should not exceed seven subordinates.

Responsibility should be accompanied by adequate authority.

Employees at all levels should be empowered to make decisions.

Options:

A.

1 and 3 only

B.

1 and 4 only

C.

2 and 3 only

D.

3 and 4 only

Buy Now
Questions 150

Which of the following storage options would give the organization the best chance of recovering data?

Options:

A.

Encrypted physical copies of the data, and their encryption keys are stored together at the organization and are readily available upon request.

B.

Encrypted physical copies of the data are stored separately from their encryption keys, and both are held in secure locations a few hours away from the organization.

C.

Encrypted reports on usage and database structure changes are stored on a cloud-based, secured database that is readily accessible.

D.

Encrypted copies of the data are stored in a separate secure location a few hours away, while the encryption keys are stored at the organization and are readilyavailable.

Buy Now
Questions 151

Which of the following describes a mechanistic organizational structure?

Options:

A.

Primary direction of communication tends to be lateral.

B.

Definition of assigned tasks tends to be broad and general.

C.

Type of knowledge required tends to be broad and professional.

D.

Reliance on self-control tends to be low.

Buy Now
Questions 152

A large retail customer made an offer to buy 10.000 units at a special price of $7 per unit. The manufacturer usually sells each unit for §10, Variable Manufacturing costs are 55 per unit and fixed manufacturing costs are $3 per unit. For the manufacturer to accept the offer, which of the following assumptions needs to be true?

Options:

A.

Fixed and Variable manufacturing costs are less than the special offer selling price.

B.

The manufacturer can fulfill the order without expanding the capacities of the production facilities.

C.

Costs related to accepting this offer can be absorbed through the sale of other products.

D.

The manufacturer’s production facilities are currently operating at full capacity.

Buy Now
Questions 153

Which of the following engagement observations would provide the least motivation for management to amend or replace an existing cost accounting system?

Options:

A.

The distorted unit cost of a service is 50 percent lower than the true cost, while the true cost is 50 percent higher than the competition ' s cost.

B.

The organization is losing $1,000,000 annually because it incorrectly outsourced an operation based on information from its current system.

C.

The cost of rework, hidden by the current system, is 50 percent of the total cost of all services.

D.

Fifty percent of total organizational cost has been allocated on a volume basis.

Buy Now
Questions 154

An organization has recorded the following profit and expenses:

Profit before interest and tax: $200,000

Sales: $2,300,000

Purchases of materials: $700,000

Interest expenses: $30,000

If the value-added tax rate is 20 percent and the corporate tax rate is 30 percent, which of the following is the amount of VAT that the organization has to pay?

Options:

A.

$34,000

B.

$51,000

C.

$60,000

D.

$320,000

Buy Now
Questions 155

An organization is considering outsourcing its IT services, and the internal auditor as assessing the related risks. The auditor grouped the related risks into three categories;

- Risks specific to the organization itself.

- Risks specific to the service provider.

- Risks shared by both the organization and the service provider

Which of the following risks should the auditor classify as specific to the service provider?

Options:

A.

Unexpected increases in outsourcing costs.

B.

Loss of data privacy.

C.

Inadequate staffing.

D.

Violation of contractual terms.

Buy Now
Questions 156

After identifying and reporting a control deficiency, which of the following actions should an internal auditor perform next?

Options:

A.

Ensure full documentation of the control deficiency and close out the audit file

B.

Follow up on the remediation status with business management periodically

C.

Note this control area “audited” and mark it as out-of-scope for the following year

D.

Design a remediation plan and ensure operational management follows through

Buy Now
Questions 157

Which of the following authentication controls combines what a user knows with the unique characteristics of the user, respectively?

Options:

A.

Voice recognition and token

B.

Password and fingerprint

C.

Fingerprint and voice recognition

D.

Password and token

Buy Now
Questions 158

Which of the following budgets must be prepared first?

Options:

A.

Cash budget.

B.

Production budget.

C.

Sales budget.

D.

Selling and administrative expenses budget.

Buy Now
Questions 159

According to lIA guidance on IT, which of the following plans would pair the identification of critical business processes with recovery time objectives?

Options:

A.

The business continuity management charter.

B.

The business continuity risk assessment plan.

C.

The business Impact analysis plan

D.

The business case for business continuity planning

Buy Now
Questions 160

The internal audit activity completed an initial risk analysis of the organization ' s data storage center and found several areas of concern. Which of the following is the most appropriate next step?

Options:

A.

Risk response.

B.

Risk identification.

C.

Identification of context.

D.

Risk assessment.

Buy Now
Questions 161

Which of the following best explains how selling and administrative expenses are recognized under both absorption and variables costing approaches?

Options:

A.

They are recognized as product costs under absorption costing, and period costs under variable costing.

B.

They are recognized as period costs under absorption costing, and product costs under variable costing.

C.

They are recognized as period costs under both approaches.

D.

They are recognized as product costs under both approaches.

Buy Now
Questions 162

According to The IIA ' s Three Lines Model, which of the following IT security activities is commonly shared by all three lines?

Options:

A.

Assessments of third parties and suppliers.

B.

Recruitment and retention of certified IT talent.

C.

Classification of data and design of access privileges.

D.

Creation and maintenance of secure network and device configuration.

Buy Now
Questions 163

Which of the following best describes a competitive strategy in which the organization focuses on attempts to be more efficient than competitors?

Options:

A.

Differentiation strategy.

B.

Cost leadership strategy.

C.

Focus strategy.

D.

Portfolio strategy.

Buy Now
Questions 164

Which of the following is a key characteristic of a zero-based budget?

Options:

A.

A zero-based budget provides estimates of costs that would be incurred under different levels of activity.

B.

A zero-based budget maintains focus on the budgeting process.

C.

A zero-based budget is prepared each year and requires each item of expenditure to be justified.

D.

A zero-based budget uses input from lower-level and middle-level managers to formulate budget plans.

Buy Now
Questions 165

An organization selected a differentiation strategy to compete at the business level. Which of the following structures best fits this strategic choice?

Options:

A.

Functional structure.

B.

Divisional structure.

C.

Mechanistic structure.

D.

Functional structure with cross-functional teams.

Buy Now
Questions 166

The engagement supervisor prepares the final engagement communication for dissemination. Since the chief audit executive (CAE) is on leave, the supervisor is delegated to disseminate the final engagement communication to all relevant parties. Who should be accountable for the final engagement communication?

Options:

A.

Engagement supervisor

B.

Chief audit executive

C.

The board

D.

The internal audit team

Buy Now
Questions 167

Which of the following key performance indicators would serve as the best measurement of internal audit innovation?

Options:

A.

The number of scheduled and completed audits and percentage of substantial recommendations

B.

The board’s satisfaction index and internal audit staff commitment ratings

C.

Internal audit staff’s application of technology in audit fieldwork and participation in professional organizations and publications

D.

Internal audit staff’s compliance with the audit manual and technical knowledge in auditing, information security, and cloud computing issues

Buy Now
Questions 168

A chief audit executive (CAE) joined an organization in the middle of the financial year. A risk-based annual audit plan has been approved by the board and is already underway. However, after discussions with key stakeholders, the CAE realizes that some significant key risk areas have not been covered in the original audit plan. How should the CAE respond?

Options:

A.

Commit to delivering the original annual audit plan as it has already been approved by the board

B.

Revise the plan to incorporate the newly identified risks, and communicate significant interim changes to senior management and the board for review and approval

C.

Ensure that the newly identified risks are included in the next year ' s annual audit plan

D.

Assign internal auditors to immediately perform assurance engagements in the areas where the new risks have been identified, due to their significance

Buy Now
Questions 169

Which of the following should software auditors do when reporting internal audit findings related to enterprisewide resource planning?

Options:

A.

Draft separate audit reports for business and IT management.

B.

Conned IT audit findings to business issues.

C.

Include technical details to support IT issues.

D.

Include an opinion on financial reporting accuracy and completeness.

Buy Now
Questions 170

Which of the following should the chief audit executive agree upon with the board before starting an external assessment of the internal audit function?

Options:

A.

The audit areas that should be reviewed

B.

The level of testing that will be required

C.

The qualifications needed on the external assessment team

D.

The specialized skills that each external assessment team member needs

Buy Now
Questions 171

An organization decided to outsource its human resources function. As part of its process migration, the organization is implementing controls over sensitive employee data.

What would be the most appropriate directive control in this area?

Options:

A.

Require a Service Organization Controls (SOC) report from the service provider

B.

Include a data protection clause in the contract with the service provider.

C.

Obtain a nondisclosure agreement from each employee at the service provider who will handle sensitive data.

D.

Encrypt the employees ' data before transmitting it to the service provider

Buy Now
Questions 172

Which of the following is on advantage of a decentralized organizational structure, as opposed to a centralized structure?

Options:

A.

Greater cost-effectiveness

B.

Increased economies of scale

C.

Larger talent pool

D.

Strong internal controls

Buy Now
Questions 173

In light of increasing emission taxes in the European Union, a car manufacturer introduced a new middle-class hybrid vehicle specifically for the European market only. Which of the following competitive strategies has the manufacturer used?

Options:

A.

Reactive strategy.

B.

Cost leadership strategy.

C.

Differentiation strategy.

D.

Focus strategy

Buy Now
Questions 174

Which of the following scenarios would require the chief audit executive (CAE) to change the internal audit plan and seek approval for the changes from the board?

Options:

A.

The CAE meets with the organization ' s new CFO to review the internal audit plan. After reviewing the plan, the CFO is satisfied that the plan addressed the top risks facing the organization

B.

The CAE oversees an internal audit function that has one IT auditor on staff. This auditor left the organization eight months ago and the CAE has been unable to hire a suitable replacement

C.

The effective date of a new government regulation occurs during the internal audit plan year. The new regulation and its effective date have been public for several years

D.

The CAE oversees an internal audit function of 15 auditors. An auditor left the organization and was replaced the following week with an auditor who has similar skills and experience

Buy Now
Questions 175

The chief audit executive hired a consultant to update the internal audit function’s methodologies. Which of the following would best ensure that the internal audit function will adhere to the updated methodologies?

Options:

A.

Placing the updated methodologies in an easily accessible location for reference

B.

Requiring a signed acknowledgment that each auditor will comply with the updated methodologies

C.

Preparing a recorded training that reviews the updated methodologies

D.

Sharing a one-page summary of the updated methodologies during an internal audit function meeting

Buy Now
Questions 176

What is the first step an internal audit function should take to define its organizational structure, deliverables, communication protocols, and resourcing model?

Options:

A.

Recommend improvements to the organization’s governance policies, processes, and structures

B.

Define a hiring plan to address competency gaps needed to execute the audit plan

C.

Construct periodic self-assessments, ongoing monitoring, and external assessments to measure quality

D.

Assess the needs and expectations of the board, senior management, and external auditors

Buy Now
Questions 177

Which of the following standards would be most useful in evaluating the performance of a customer-service group?

Options:

A.

The average time per customer inquiry should be kept to a minimum.

B.

Customer complaints should be processed promptly.

C.

Employees should maintain a positive attitude when dealing with customers.

D.

All customer inquiries should be answered within seven days of receipt.

Buy Now
Questions 178

Which of the following capital budgeting techniques considers the expected total net cash flows from investment?

Options:

A.

Cash payback

B.

Annual rate of return

C.

Incremental analysis

D.

Net present value

Buy Now
Questions 179

An intruder posing as the organization ' s CEO sent an email and tricked payroll staff into providing employees ' private tax information. What type of attack was perpetrated?

Options:

A.

Boundary attack.

B.

Spear phishing attack.

C.

Brute force attack.

D.

Spoofing attack.

Buy Now
Questions 180

If legal or regulatory standards prohibit conformance with certain parts of The IIA ' s Standards, the auditor should do which of the following?

Options:

A.

Conform with all other parts of The IIA ' s Standards and provide appropriate disclosures.

B.

Conform with all other parts of The IIA ' s Standards; there is no need to provide appropriate disclosures.

C.

Continue the engagement without conforming with the other parts of The IIA ' s Standards.

D.

Withdraw from the engagement.

Buy Now
Questions 181

A significant project is nearing its development stage end, and line management intends to apply for a final investment decision from senior management at an upcoming meeting. The internal audit function is at the fieldwork stage of an assurance engagement related to this project and discovers that tenders conducted for the project were not carried out transparently by line management. The audit report will not be ready by the upcoming senior management meeting. Which of the following actions is the most appropriate next step for the chief audit executive?

Options:

A.

Escalate the issue to the chief risk officer

B.

Raise the issue with senior management

C.

Continue with the assurance engagement as planned

D.

Place the assurance engagement on hold due to inappropriate timing

Buy Now
Questions 182

A organization finalized a contract in which a vendor is expected to design, procure, and construct a power substation for $3,000,000. In this scenario, the organization agreed to which of the following types of contracts?

Options:

A.

A cost-reimbursable contract.

B.

A lump-sum contract.

C.

A time and material contract.

D.

A bilateral contract.

Buy Now
Questions 183

When examining; an organization ' s strategic plan, an internal auditor should expect to find which of the following components?

Options:

A.

Identification of achievable goals and timelines

B.

Analysis of the competitive environment.

C.

Plan for the procurement of resources

D.

Plan for progress reporting and oversight.

Buy Now
Questions 184

Which of the following best describes a man-in-the-middle cyber-attack?

Options:

A.

The perpetrator is able to delete data on the network without physical access to the device.

B.

The perpetrator is able to exploit network activities for unapproved purposes.

C.

The perpetrator is able to take over control of data communication in transit and replace traffic.

D.

The perpetrator is able to disable default security controls and introduce additional vulnerabilities

Buy Now
Questions 185

According to 11A guidance on IT, which of the following are indicators of poor change management?

1. Inadequate control design.

2. Unplanned downtime.

3. Excessive troubleshooting .

4. Unavailability of critical services.

Options:

A.

2 and 3 only.

B.

1, 2, and 3 only

C.

1, 3, and 4 only

D.

2, 3, and 4 only

Buy Now
Questions 186

Which of the following statements is true concerning the basic accounting treatment of a partnership?

Options:

A.

The initial investment of each partner should be recorded at book value.

B.

The ownership ratio identifies the basis for dividing net income and net toss.

C.

A partner ' s capital only changes due to net income or net loss.

D.

The basis for sharing net incomes or net kisses must be fixed.

Buy Now
Questions 187

An internal auditor observed that the organization ' s disaster recovery solution will make use of a cold site in a town several miles away. Which of the following is likely to be a characteristic of this disaster recover/ solution?

Options:

A.

Data is synchronized in real time

B.

Recovery time is expected to be less than one week

C.

Servers are not available and need to be procured

D.

Recovery resources end data restore processes have not been defined.

Buy Now
Questions 188

According to IIA guidance, which of the following statements is true with regard to workstation computers that access company information stored on the network?

Options:

A.

Individual workstation computer controls are not as important as companywide server controls

B.

Particular attention should be paid to housing workstations away from environmental hazards

C.

Cybersecurity issues can be controlled at an enterprise level, making workstation-level controls redundant

D.

With security risks near an all-time high, workstations should not be connected to the company network

Buy Now
Questions 189

Which of the following best describes the chief audit executive ' s responsibility for assessing the organization ' s residual risk?

Options:

A.

Create an action plan to mitigate the risk

B.

Incorporate management acceptance of risk in the workpapers as internal audit evidence

C.

Report deviations immediately to the board

D.

Communicate the matter with senior management

Buy Now
Questions 190

The project charter is an output from which of the following?

Options:

A.

Scope planning.

B.

Scope definition.

C.

Scope verification.

D.

Project initiation.

Buy Now
Questions 191

A newly established organization wants to use the email service offered by a cloud email provider for its own official email. The organization will use its own domain name for a monthly fee, paid to the cloud provider.

What type of cloud service will fit this organization’s requirements?

Options:

A.

Hardware as a Service (HaaS).

B.

Infrastructure as a Service (IaaS).

C.

Platform as a Service (PaaS).

D.

Software as a Service (SaaS).

Buy Now
Questions 192

Which of the following sites would an Internet service provider most likely use to restore operations after its servers were damaged by a natural disaster?

Options:

A.

On site.

B.

Cold site.

C.

Hot site.

D.

Warm site

Buy Now
Questions 193

Which of the following borrowing options is an unsecured loan?

Options:

A.

Second-mortgage financing from a bank.

B.

An issue of commercial paper.

C.

Pledged accounts receivable.

D.

Asset-based financing.

Buy Now
Questions 194

Which of the following is a characteristic of big data?

Options:

A.

Big data is often structured.

B.

Big data analytic results often need to be visualized.

C.

Big data is often generated slowly and is highly variable.

D.

Big data comes from internal sources kept in data warehouses.

Buy Now
Questions 195

Which of the following best illustrates the meaning of fair value?

Options:

A.

Unrealized gains or losses of the investment portfolio.

B.

The difference between the total cost of securities and their market cost.

C.

The price for which a security could be sold at normal market conditions.

D.

The original cost of a security plus revenues it has earned.

Buy Now
Questions 196

Which of the following statements distinguishes a router from a typical switch?

Options:

A.

A router operates at layer two. while a switch operates at layer three of the open systems interconnection model.

B.

A router transmits data through frames, while a switch sends data through packets.

C.

A router connects networks, while a switch connects devices within a network.

D.

A router uses a media access control address during the transmission of data, whie a switch uses an internet protocol address.

Buy Now
Questions 197

Which of the following controls would be the most effective in preventing the disclosure of an organization ' s confidential electronic information?

Options:

A.

Nondisclosure agreements between the firm and its employees.

B.

Logs of user activity within the information system.

C.

Two-factor authentication for access into the information system.

D.

limited access so information, based on employee duties

Buy Now
Questions 198

Which of the following steps should an internal auditor take during an audit of an organization ' s business continuity plans?

    Evaluate the business continuity plans for adequacy and currency.

    Prepare a business impact analysis regarding the loss of critical business.

    Identify key personnel who will be required to implement the plans.

    Identify and prioritize the resources required to support critical business processes.

Options:

A.

1 only

B.

2 and 4 only

C.

1, 3, and 4 only

D.

1, 2, 3, and 4

Buy Now
Questions 199

Which of the following dimensions relates to the quality of big data?

Options:

A.

Veracity.

B.

Validity.

C.

Value.

D.

Variety.

Buy Now
Questions 200

Which of the following controls helps protect externally stored sensitive or confidential data from cyberthreats?

Options:

A.

Secure configurations and access controls.

B.

Strong vendor contracts with control reports provided by service organizations.

C.

Active and frequent monitoring of network traffic activities.

D.

Firewalls to block unauthorized processing of transactions.

Buy Now
Questions 201

Management has established a performance measurement focused on the accuracy of disbursements. The disbursement statistics, provided daily to ail accounts payable and audit staff, include details of payments stratified by amount and frequency. Which of the following is likely to be the greatest concern regarding this performance measurement?

Options:

A.

Articulation of the data

B.

Availability of the data.

C.

Measurability of the data

D.

Relevance of the data.

Buy Now
Questions 202

Senior management is trying to decide whether to use the direct write-off or allowance method for recording bad debt on accounts receivables. Which of the following would be the best argument for using the direct write-off method?

Options:

A.

It is useful when losses are considered insignificant.

B.

It provides a better alignment with revenue.

C.

It is the preferred method according to The IIA.

D.

It states receivables at net realizable value on the balance sheet.

Buy Now
Questions 203

Following an evaluation of an organization ' s IT controls, an internal auditor suggested improving the process where results are compared against the input. Which of the following IT controls would the Internal auditor recommend?

Options:

A.

Output controls.

B.

Input controls

C.

Processing controls.

D.

Integrity controls.

Buy Now
Questions 204

According to Maslow ' s hierarchy of needs theory, which of the following would likely have the most impact on retaining staff, if their lower-level needs are already met?

Options:

A.

Social benefits.

B.

Compensation.

C.

Job safety.

D.

Recognition

Buy Now
Questions 205

An organization ' s technician was granted a role that enables him to prioritize projects throughout the organization. Which type of authority will the technician most likely be exercising?

Options:

A.

Legitimate authority

B.

Coercive authority.

C.

Referent authority.

D.

Expert authority.

Buy Now
Questions 206

Which of the following scenarios best illustrates a spear phishing attack?

Options:

A.

Numerous and consistent attacks on the company ' s website caused the server to crash and service was disrupted.

B.

A person posing as a representative of the company ' s IT help desk called several employees and played a generic prerecorded message requesting password data.

C.

A person received a personalized email regarding a golf membership renewal, and he clicked a hyperlink to enter his credit card data into a fake website.

D.

Many users of a social network service received fake notifications of a unique opportunity to invest in a new product

Buy Now
Questions 207

Which of the following best describes a detective control designed to protect an organization from cyberthreats and attacks?

Options:

A.

A list of trustworthy, good traffic and a list of unauthorized, blocked traffic.

B.

Monitoring for vulnerabilities based on industry intelligence.

C.

Comprehensive service level agreements with vendors.

D.

Firewall and other network perimeter protection tools.

Buy Now
Questions 208

Based on test results, an IT auditor concluded that the organization would suffer unacceptable loss of data if there was a disaster at its data center. Which of the following test results would likely lead the auditor to this conclusion?

Options:

A.

Requested backup tapes were not returned from the offsite vendor in a timely manner

B.

Returned backup tapes from the offsite vendor contained empty spaces

C.

Critical systems have been backed up more frequently than required

D.

Critical system backup tapes are taken off site less frequently than required

Buy Now
Questions 209

Which of the following is considered a physical security control?

Options:

A.

Transaction logs are maintained to capture a history of system processing.

B.

System security settings require the use of strong passwords and access controls.

C.

Failed system login attempts are recorded and analyzed to identify potential security incidents.

D.

System servers are secured by locking mechanisms with access granted to specific individuals.

Buy Now
Questions 210

An organization decided to invest in new office equipment for $320,000. The estimated useful life of the equipment is four years. The residual value will be $40,000. The depreciation method is straight-line. The new equipment will allow the organization to save $150,000 per year. The estimated tax rate used in the organization is 30 percent. The required rate of return is 15 percent.

The following are present values of $1 during four years for 15 percent:

Year 1 = $0.87

Year 2 = $0.76

Year 3 = $0.66

Year 4 = $0.57

What is net present value of this investment?

Options:

A.

$71,140

B.

$63,160

C.

$40,360

D.

$3,100

Buy Now
Questions 211

An organization has adopted a bring-your-own-device (BYOD) policy, and employees can access organizational data via their smart devices.

Which of the following authentication policy requirements is the most advisable?

Options:

A.

Require a virtual private network (VPN).

B.

Require at least an eight-digit passcode or a complicated swipe pattern.

C.

Require the remote wipe function and encryption of local data.

D.

Require a passcode followed by a response requiring verification message.

Buy Now
Questions 212

When an organization is choosing a new external auditor, which of the following is the most appropriate role for the chief audit executive to undertake?

Options:

A.

Review and acquire the external audit service.

B.

Assess the appraisal and actuarial services.

C.

Determine the selection criteria.

D.

Identify regulatory requirements to be considered.

Buy Now
Questions 213

Which of the following statements is true regarding IT controls within an organization?

Options:

A.

IT risks and controls should be assessed at least once every five years.

B.

Responsibility for effective IT controls rests exclusively with management.

C.

An effective IT control environment should consist of all possible general IT and application controls.

D.

Regardless of how well an IT control is designed it may be subject to error and management override.

Buy Now
Questions 214

Unsecured loans are loans:

Options:

A.

That do not have to be repaid for over one year.

B.

That appear to be too risky for most lenders to consider.

C.

Granted on the basis of a company ' s credit standing.

D.

Backed by mortgaged assets.

Buy Now
Questions 215

Which of the following is a characteristic of using a hierarchical control structure?

Options:

A.

Less use of policies and procedures.

B.

Less organizational commitment by employees.

C.

Less emphasis on extrinsic rewards.

D.

Less employee’s turnover.

Buy Now
Questions 216

According to Herzberg’s Two-Factor Theory of Motivation, which of the following factors are mentioned most often by satisfied employees?

Options:

A.

Salary and status.

B.

Responsibility and advancement.

C.

Work conditions and security.

D.

Peer relationships and personal life.

Buy Now
Questions 217

Which of the following statements is true regarding managerial accounts?

Options:

A.

They must be prepared at least on a monthly basis.

B.

They should be verifiable by external auditors.

C.

They should be easily understandable by all management team members.

D.

They should exclusively meet the needs of the user.

Buy Now
Questions 218

Which of the following would be the best method to collect information about employees ' job satisfaction?

Options:

A.

Online surveys sent randomly to employees.

B.

Direct onsite observations of employees.

C.

Town hall meetings with employees.

D.

Face-to-face interviews with employees.

Buy Now
Questions 219

Which of the following contract concepts is typically given in exchange for the execution of a promise?

Options:

A.

Lawfulness.

B.

Consideration.

C.

Agreement.

D.

Discharge

Buy Now
Questions 220

Which of the following is a characteristic of big data?

Options:

A.

Big data is being generated slowly due to volume.

B.

Big data must be relevant for the purposes of organizations.

C.

Big data comes from a single type of formal.

D.

Big data is always changing

Buy Now
Questions 221

An organization uses a database management system (DBMS) as a repository for data. The DBMS, in turn, supports a number of end-user developed applications which were created using fourth-generation programming languages. Some of the applications update the database. Which of the following is the most important control related to the integrity of the data in the database?

Options:

A.

End users have their read-only applications approved by the information systems department before accessing the database.

B.

Concurrency update controls are in place.

C.

End-user applications are developed on personal computers before being implemented on the mainframe.

D.

A hierarchical database model is adopted so that multiple users can be served at the same time.

Buy Now
Questions 222

When auditing an application change control process, which of the following procedures should be included in the scope of the audit?

    Ensure system change requests are formally initiated, documented, and approved.

    Ensure processes are in place to prevent emergency changes from taking place.

    Ensure changes are adequately tested before being placed into the production environment.

    Evaluate whether the procedures for program change management are adequate.

Options:

A.

1 only

B.

1 and 3 only

C.

2 and 4 only

D.

1, 3, and 4 only

Buy Now
Questions 223

An internal auditor is completing an access control assessment of a telecommunication organization’s offsite facility.

Which of the following physical security measures would best prevent unauthorized access to the facility?

Options:

A.

Proximity badges.

B.

Key locks.

C.

Combination codes.

D.

Biometric locks.

Buy Now
Questions 224

Which is the least effective form of risk management?

Options:

A.

Systems-based preventive control.

B.

People-based preventive control.

C.

Systems-based detective control.

D.

People-based detective control.

Buy Now
Questions 225

An internal auditor found the following information while reviewing the monthly financial siatements for a wholesaler of safety

225

The cost of goods sold was reported at $8,500. Which of the following inventory methods was used to derive this value?

Options:

A.

Average cost method

B.

First-in, first-out (FIFO) method

C.

Specific identification method

D.

Activity-based costing method

Buy Now
Questions 226

Which of the following controls would be most efficient to protect business data from corruption and errors?

Options:

A.

Controls to ensure data is unable to be accessed without authorization.

B.

Controls to calculate batch totals to identify an error before approval.

C.

Controls to encrypt the data so that corruption is likely ineffective.

D.

Controls to quickly identify malicious intrusion attempts.

Buy Now
Questions 227

Which of the following communication characteristics is achieved when the internal audit function avoids redundancies and excludes information that is unnecessary, insignificant, or unrelated to the engagement?

Options:

A.

Constructive communications

B.

Complete communications

C.

Concise communications

D.

Clear communications

Buy Now
Questions 228

A financial institution receives frequent and varied email requests from customers for funds to be wired out of their accounts. Which verification activity would best help the institution avoid falling victim to phishing?

Options:

A.

Reviewing the customer ' s wire activity to determine whether the request is typical.

B.

Calling the customer at the phone number on record to validate the request.

C.

Replying to the customer via email to validate the sender and request.

D.

Reviewing the customer record to verify whether the customer has authorized wire requests from that email address.

Buy Now
Questions 229

An internal audit activity is piloting a data analytics model, which aims to identify anomalies in payments to vendors and potential fraud indicators. Which of the following would be the most appropriate criteria for assessing the success of the piloted model?

Options:

A.

The percentage of cases flagged by the model and confirmed as positives.

B.

The development and maintenance costs associated with the model

C.

The feedback of auditors involved with developing the model.

D.

The number of criminal investigations initiated based on the outcomes of the model

Buy Now
Questions 230

Which of the following represents an inventory costing technique that can be manipulated by management to boost net income by selling units purchased at a low cost?

Options:

A.

First-in. first-out method (FIFO).

B.

Last-in, first-out method (LIFO).

C.

Specific identification method.

D.

Average-cost method

Buy Now
Questions 231

Which of the following attributes of data is most likely to be compromised in an organization with a weak data governance culture?

Options:

A.

Variety.

B.

Velocity.

C.

Volume.

D.

Veracity.

Buy Now
Questions 232

Which of the following statements is true regarding the use of public key encryption to secure data while it is being transmitted across a network?

Options:

A.

Both the key used to encrypt the data and the key used to decrypt the data are made public.

B.

The key used to encrypt the data is kept private but the key used to decrypt the data is made public.

C.

The key used to encrypt the data is made public but the key used to decrypt the data is kept private.

D.

Both the key used to encrypt the data and the key used to decrypt the data are made private.

Buy Now
Questions 233

Which of the following types of date analytics would be used by a hospital to determine which patients are likely to require remittance for additional treatment?

Options:

A.

Predictive analytics.

B.

Prescriptive analytics.

C.

Descriptive analytics.

D.

Diagnostic analytics.

Buy Now
Questions 234

Which of the following conflict resolution methods should be applied when the intention of the parties is to solve the problem by clarifying differences and attaining everyone ' s objectives?

Options:

A.

Accommodating.

B.

Compromising.

C.

Collaborating.

D.

Competing.

Buy Now
Questions 235

According to IIA guidance, which of the following best describes an adequate management (audit) trail application control for the general ledger?

Options:

A.

Report identifying data that is outside of system parameters.

B.

Report identifying general ledger transactions by time and individual.

C.

Report comparing processing results with original input.

D.

Report confirming that the general ledger data was processed without error.

Buy Now
Questions 236

Which of the following IT strategies is most effective for responding to competitive pressures created by the marketplace?

Options:

A.

Promote closer linkage between organizational strategy and information.

B.

Provide users with greater online access to information systems.

C.

Enhance the functionality of application systems.

D.

Expand the use of automated controls.

Buy Now
Questions 237

Which of the following is true regarding reporting on the quality assurance and improvement program (QAIP)?

Options:

A.

The results of ongoing monitoring must be communicated annually to the board and other appropriate stakeholders

B.

The results of any periodic self-assessment and level of conformance with the Global Internal Audit Standards must be reported to the board before completion

C.

The results of any external assessments and level of conformance with the Standards must be reported to the board before completion

D.

The QAIP and the resulting action plan must be made available to external assessors

Buy Now
Exam Code: IIA-CIA-Part3
Exam Name: Internal Audit Function
Last Update: Jul 28, 2026
Questions: 791

PDF + Testing Engine

$59.99 $171.4

Testing Engine

$44.99 $128.55

PDF (Q&A)

$49.99 $142.82