Summer Special Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: spcl70

Practice Free IIA-CIA-Part3 Internal Audit Function Exam Questions Answers With Explanation

We at Crack4sure are committed to giving students who are preparing for the IIA IIA-CIA-Part3 Exam the most current and reliable questions . To help people study, we've made some of our Internal Audit Function exam materials available for free to everyone. You can take the Free IIA-CIA-Part3 Practice Test as many times as you want. The answers to the practice questions are given, and each answer is explained.

Question # 6

An internal auditor has completed the fieldwork of an assurance engagement on the organization ' s business continuity. The most significant finding is that business requirements were left up to the IT function to decide and implement. As a result, the time to recovery for some critical systems following a disruption is too long, while recovery time of non-critical systems is needlessly prioritized at a significant cost. Which of the following is the most appropriate recommendation to include in the engagement report?

A.

Management of business units should review and correct the recovery targets

B.

Conduct an IT function review and correct the recovery targets

C.

Management of the IT function should ensure that the business continuity plan is more realistic

D.

Ensure that in the future business requirements are set by the management of business units

Question # 7

Which stage in the industry life cycle is characterized by many different product variations?

A.

Introduction.

B.

Growth.

C.

Maturity.

D.

Decline.

Question # 8

Which of the following common quantitative techniques used in capital budgeting is best associated with the use of a table that describes the present value of an annuity?

A.

Cash payback technique.

B.

Discounted cash flow technique: net present value.

C.

Annual rate of return

D.

Discounted cash flow technique: internal rate of return.

Question # 9

What security feature would Identity a legitimate employee using her own smart device to gam access to an application run by the organization?

A.

Using a jailbroken or rooted smart device feature.

B.

Using only smart devices previously approved by the organization.

C.

Obtaining written assurance from the employee that security policies and procedures are followed.

D.

Introducing a security question known only by the employee.

Question # 10

An internal audit engagement team found that the risk register of the project under review did not include significant risks identified by the internal audit function. The project manager explained that risk register preparations are facilitated by risk managers and that each project’s risk review follows the same set of questions. Which of the following recommendations will likely add the greatest value to the project management process of the organization?

A.

Update the risk register of the project with the newly identified risks

B.

Train senior management on risk management principles

C.

Revise the methodology of the project risk identification process

D.

Reassign the responsibility of risk register completion to risk managers

Question # 11

A rapidly expanding retail organisation continues to be tightly controlled by its original small management team. Which of the following is a potential risk in this vertically centralized organization?

A.

Lack of coordination among different business units

B.

Operational decisions are inconsistent with organizational goals

C.

Suboptimal decision making

D.

Duplication of business activities

Question # 12

Which of the following is an effective preventive control for data center security?

A.

Motion detectors.

B.

Key card access to the facility.

C.

Security cameras.

D.

Monitoring access to data center workstations

Question # 13

Which of the following best describes the use of predictive analytics?

A.

A supplier of electrical parts analyzed an instances where different types of spare parts were out of stock prior to scheduled deliveries of those parts.

B.

A supplier of electrical parts analyzed sales, applied assumptions related to weather conditions, and identified locations where stock levels would decrease more quickly.

C.

A supplier of electrical parts analyzed all instances of a part being, out of stock poor to its scheduled delivery date and discovered that increases in sales of that part consistently correlated with stormy weather.

D.

A supplier of electrical parts analyzed sales and stock information and modelled different scenarios for making decisions on stock reordering and delivery

Question # 14

Which of the following is a likely result of outsourcing?

A.

Increased dependence on suppliers.

B.

Increased importance of market strategy.

C.

Decreased sensitivity to government regulation

D.

Decreased focus on costs

Question # 15

Which of the following biometric access controls uses the most unique human recognition characteristic?

A.

Facial comparison using photo identification.

B.

Signature comparison.

C.

Voice comparison.

D.

Retinal print comparison.

Question # 16

Which of the following is classified as a product cost using the variable costing method?

1. Direct labor costs.

2. Insurance on a factory.

3. Manufacturing supplies.

4. Packaging and shipping costa.

A.

1 and 2

B.

1 and 3

C.

2 and 4

D.

3 and 4

Question # 17

Which of the following is a cybersecurity monitoring activity intended to deter disruptive codes from being installed on an organizations systems?

A.

Boundary defense

B.

Malware defense.

C.

Penetration tests

D.

Wireless access controls

Question # 18

An organization that relies heavily on IT wants to contain the impact of potential business disruption to a period of approximately four to seven days. Which of the following

business recovery strategies would most efficiently meet this organization ' s needs?

A.

A recovery strategy whereby a separate site has not yet been determined, but hardware has been reserved for purchase and data backups.

B.

A recovery strategy whereby a separate site has been secured and is ready for use, with fully configured hardware and real-time synchronized data

C.

A recovery strategy whereby a separate site has been secured and the necessary funds for hardware and data backups have been reserved.

D.

A recovery strategy whereby a separate site has been secured with configurable hardware and data backups.

Question # 19

According to I1A guidance on IT. which of the following activities regarding information security Is most likely to be the responsibility of line management as opposed to executive management, internal auditors, or the board?

A.

Review and monitor security controls.

B.

Dedicate sufficient security resources.

C.

Provide oversight to the security function.

D.

Assess information control environments.

Question # 20

According to the International Professional Practices Framework, internal auditors who are assessing the adequacy of organizational risk management processes should not:

A.

Recognize that organizations use different techniques for managing risk.

B.

Seek assurance that the key objectives of the risk management processes are being met.

C.

Determine and accept the level of risk for the organization.

D.

Treat the evaluation of risk management processes differently from the risk analysis used to plan audit engagements.

Question # 21

Which of the following statements is most accurate concerning the management and audit of a web server?

A.

The file transfer protocol (FTP) should always be enabled

B.

The simple mail transfer protocol (SMTP) should be operating under the most privileged accounts

C.

The number of ports and protocols allowed to access the web server should be maximized

D.

Secure protocols for confidential pages should be used instead of clear-text protocols such as HTTP or FTP

Question # 22

An organization had three large centralized divisions: one that received customer orders for service work; one that scheduled the service work at customer locations; and one that answered customer calls about service problems. These three divisions were restructured into seven regional groups, each of which performed all three functions. One advantage of this restructuring would be:

A.

Better internal controls.

B.

Greater economies of scale.

C.

Improved workflow.

D.

Increased specialization.

Question # 23

Which of the following is classified as a product cost using the variable costing method?

Direct labor costs.

Insurance on a factory.

Manufacturing supplies.

Packaging and shipping costs.

A.

1 and 2

B.

1 and 3

C.

2 and 4

D.

3 and 4

Question # 24

Which of the following is a distinguishing feature of managerial accounting, which is not applicable to financial accounting?

A.

Managerial accounting uses double-entry accounting and cost data.

B.

Managerial accounting uses general accepted accounting principles.

C.

Managerial accounting involves decision making based on quantifiable economic events.

D.

Managerial accounting involves decision making based on predetermined standards.

Question # 25

Which of the following business practices promotes a culture of high performance?

A.

Reiterating the importance of compliance with established policies and procedures.

B.

Celebrating employees ' individual excellence.

C.

Periodically rotating operational managers.

D.

Avoiding status differences among employees.

Question # 26

An internal audit uncovered high-risk issues that needed to be addressed by the organization. During the exit conference, the audit team discussed the high-risk issues with the manager responsible for addressing them. How should the chief audit executive respond if the manager agrees to correct the issues identified during the audit?

A.

Include in the report that management has agreed to address the issue and set a date for follow-up

B.

Include an assignment in the annual internal audit plan to perform a follow-up audit

C.

Discuss the audit observation with senior management

D.

Solicit input from management and create the action plan

Question # 27

Which of the following is an example of a key systems development control typically found in the in-house development of an application system?

A.

Logical access controls monitor application usage and generate audit trails.

B.

The development process is designed to prevent, detect, and correct errors that may occur.

C.

A record is maintained to track the process of data from input, to output, to storage.

D.

Business users ' requirements are documented, and their achievement is monitored.

Question # 28

Which audit approach should be employed to test the accuracy of information housed in a database on an un-networked computer?

A.

Submit batches of test transactions through the current system and verify with expected results.

B.

Use a test program to simulate the normal data entering process.

C.

Select a sample of records from the database and ensure it matches supporting documentation.

D.

Evaluate compliance with the organization ' s change management process.

Question # 29

An organization that sells products to a foreign subsidiary wants to charge a price that will decrease import tariffs. Which of the following is the best course of action for the organization?

A.

Decrease the transfer price.

B.

Increase the transfer price.

C.

Charge at the arm’s length price.

D.

Charge at the optimal transfer price.

Question # 30

Which of following best demonstrates the application of the cost principle?

A.

A company reports trading and investment securities at their market cost

B.

A building purchased last year for $1 million is currently worth ©1.2 million, but the company still reports the building at $1 million.

C.

A building purchased last year for ©1 million is currently worth £1,2 million , and the company adjusts the records to reflect the current value

D.

A company reports assets at either historical or fair value, depending which is closer to market value.

Question # 31

Which of the following is not a method for implementing a new application system?

A.

Direct cutover.

B.

Parallel.

C.

Pilot.

D.

Test.

Question # 32

Which of the following describes the free trade zone in an e-commerce environment?

A.

Zone that separates an organization ' s servers from outside forces.

B.

Area in which messages are scrutinized to determine if they are authorized.

C.

Area where communication and transactions occur between trusted parties.

D.

Zone where data is encrypted, users are authenticated, and user traffic is filtered.

Question # 33

Which of the following statements is true regarding the use of public key encryption to secure data while it is being transmitted across a network?

A.

Both the key used to encrypt the data and the key used to decrypt the data are made public.

B.

The key used to encrypt the data is kept private but the key used to decrypt the data is made public.

C.

The key used to encrypt the data is made public but the key used to decrypt the data is kept private.

D.

Both the key used to encrypt the data and the key used to decrypt the data are made private.

Question # 34

Which of the following is the most appropriate beginning step of a work program for an assurance engagement involving smart devices?

A.

Train all employees on bring-your-own-device (BYOD) policies.

B.

Understand what procedures are in place for locking lost devices

C.

Obtain a list of all smart devices in use

D.

Test encryption of all smart devices

Question # 35

Which of the following should internal auditors be attentive of when reviewing personal data consent and opt-in/opt-out management process?

A.

Whether customers are asked to renew their consent for their data processing at least quarterly.

B.

Whether private data is processed in accordance with the purpose for which the consent was obtained?

C.

Whether the organization has established explicit and entitywide policies on data transfer to third parties.

D.

Whether customers have an opportunity to opt-out the right to be forgotten from organizational records and systems.

Question # 36

Which of the following physical access control is most likely to be based on ’’something you have " concept?

A.

A retina characteristics reader

B.

A P3M code reader

C.

A card-key scanner

D.

A fingerprint scanner

Question # 37

Which of the following job design techniques would most likely be used to increase employee motivation through job responsibility and recognition?

A.

Job complicating

B.

Job rotation

C.

Job enrichment

D.

Job enlargement

Question # 38

Which of the following best describes the primary objective of cybersecurity?

A.

To protect the effective performance of IT general and application controls.

B.

To regulate users ' behavior it the web and cloud environment.

C.

To prevent unauthorized access to information assets.

D.

To secure application of protocols and authorization routines.

Question # 39

Which of the following purchasing scenarios would gain the greatest benefit from implementing electronic cate interchange?

A.

A just-in-time purchasing environment

B.

A Large volume of custom purchases

C.

A variable volume sensitive to material cost

D.

A currently inefficient purchasing process

Question # 40

An internal auditor is reviewing results from software development integration testing. What is the purpose of integration testing?

A.

To verify that the application meets stated user requirements.

B.

To verify that standalone programs match code specifications.

C.

To verify that the application would work appropriately for the intended number of users.

D.

To verify that all software and hardware components work together as intended.

Question # 41

When auditing the account receivables for the first time, an internal auditor noted that the finance team had not—over many accounting periods—reviewed the accounts receivables for debts that could no longer be collected. How should the auditor proceed?

A.

Escalate the finding to the board, due to the significance of the risk

B.

Recommend that management review the receivables for debts that can no longer be collected and remove them from the cash flow statement

C.

Recommend that management review the receivables for debts that can no longer be collected and write them off

D.

Document the finding and conclude that no immediate action is warranted, as bad debt allowances are merely estimates

Question # 42

In mergers and acquisitions, which of the following is an example of a horizontal combination?

A.

Dairy manufacturing company taking over a large dairy farm.

B.

A movie producer acquires movie theaters.

C.

A petroleum processing company acquires an agro-processing firm.

D.

A baker taking over a competitor.

Question # 43

Which of the following is an indicator of liquidity that is more dependable than working capital?

A.

Acid-test (quick) ratio

B.

Average collection period

C.

Current ratio.

D.

Inventory turnover.

Question # 44

During which phase of the contracting process ere contracts drafted for a proposed business activity?

A.

Initiation phase.

B.

Bidding phase

C.

Development phase

D.

Management phase

Question # 45

A newly established organization wants to use the email service offered by a cloud email provider for its own official email. The organization will use its own domain name for a monthly fee, paid to the cloud provider.

What type of cloud service will fit this organization’s requirements?

A.

Hardware as a Service (HaaS).

B.

Infrastructure as a Service (IaaS).

C.

Platform as a Service (PaaS).

D.

Software as a Service (SaaS).

Question # 46

An internal auditor computed that one of the organization ' s accounting divisions is processing 30 travel reports per hour while another accounting division is processing 22 travel reports per hour. Which of the following efficiency measures did the internal auditor most likely employ?

A.

Operating rate.

B.

Asset efficiency rate.

C.

Resource utilization rate.

D.

Productivity rate.

Question # 47

An organization has 10,000 units of a defect item in stock, per unit, market price is $10$; production cost is $4; and defect selling price is $5. What is the carrying amount (inventory value) of defects at your end?

A.

$0

B.

$4,000

C.

$5,000

D.

$10,000

Question # 48

What impact is there to liabilities on the balance sheet when ending inventory is overstated?

A.

There is no effect on liabilities.

B.

Liabilities are overstated.

C.

Liabilities are understated.

D.

Inventory errors affect income statement only.

Question # 49

What is the primary purpose of an integrity control?

A.

To ensure data processing is complete, accurate, and authorized

B.

To ensure data being processed remains consistent and intact

C.

To monitor the effectiveness of other controls

D.

To ensure the output aligns with the intended result

Question # 50

What kind of strategy would be most effective for an organization to adopt in order to Implement a unique advertising campaign for selling identical product lines across all of its markets?

A.

Export strategy.

B.

Transnational strategy

C.

Multi-domestic strategy

D.

Globalization strategy

Question # 51

The internal auditor concluded there was a high likelihood that a significant wind farm development, worth $200 million, would be delayed from its approved schedule. As a result, electricity production would not start on time, leading to considerable financial penalties. Which of the following should be added to the observation to support its clarity and completeness?

A.

The effect of the observation

B.

The criteria of the observation

C.

The condition of the observation

D.

The cause of the observation

Question # 52

If legal or regulatory standards prohibit conformance with certain parts of The IIA ' s Standards, the auditor should do which of the following?

A.

Conform with all other parts of The IIA ' s Standards and provide appropriate disclosures.

B.

Conform with all other parts of The IIA ' s Standards; there is no need to provide appropriate disclosures.

C.

Continue the engagement without conforming with the other parts of The IIA ' s Standards.

D.

Withdraw from the engagement.

Question # 53

An internal auditor found the following information while reviewing the monthly financial siatements for a wholesaler of safety

IIA-CIA-Part3 question answer

The cost of goods sold was reported at $8,500. Which of the following inventory methods was used to derive this value?

A.

Average cost method

B.

First-in, first-out (FIFO) method

C.

Specific identification method

D.

Activity-based costing method

Question # 54

Which of the following items best describes the strategy of outsourcing?

A.

Contracting the work to Foreign Service providers to obtain lower costs

B.

Contracting functions or knowledge-related work with an external service provider.

C.

Contract -ng operation of some business functions with an internal service provider

D.

Contracting a specific external service provider to work with an internal service provider

Question # 55

Which of the following is true of bond financing, compared to common stock, when alJ other variables are equal?

A.

Lower shareholder control

B.

lower indebtedness

C.

Higher company earnings per share.

D.

Higher overall company earnings

Question # 56

Which of the following scenarios best illustrates a spear phishing attack?

A.

Numerous and consistent attacks on the company ' s website caused the server to crash and service was disrupted.

B.

A person posing as a representative of the company ' s IT help desk called several employees and played a generic prerecorded message requesting password data.

C.

A person received a personalized email regarding a golf membership renewal, and he clicked a hyperlink to enter his credit card data into a fake website.

D.

Many users of a social network service received fake notifications of a unique opportunity to invest in a new product

Question # 57

Which of the following descriptions of the internal control system are indicators that risks are managed effectively?

    Existing controls promote compliance with applicable laws and regulations.

    The control environment is designed to address all identified risks to the organization.

    Key controls for significant risks to the organization remain consistent over time.

    Monitoring systems are in place to alert management to unexpected events.

A.

1 and 3.

B.

1 and 4.

C.

2 and 3.

D.

2 and 4.

Question # 58

According to IIA guidance, which of the following are typical physical and environmental IT controls?

A.

Locating servers in locked rooms with restricted admission.

B.

Applying encryption where confidentiality is a stated requirement.

C.

Allocating and controlling access rights according to the organization ' s stated policy.

D.

Ensuring a tightly controlled process for applying all changes and patches to software, systems, network components, and data.

Question # 59

All of the following are possible explanations for a significant unfavorable material efficiency variance except:

A.

Cutbacks in preventive maintenance.

B.

An inadequately trained and supervised labor force.

C.

A large number of rush orders.

D.

Production of more units than planned for in the master budget.

Question # 60

Listening effectiveness is best increased by:

A.

Resisting both internal and external distractions.

B.

Waiting to review key concepts until the speaker has finished talking.

C.

Tuning out messages that do not seem to fit the meeting purpose.

D.

Factoring in biases in order to evaluate the information being given.

Question # 61

An internal audit team is trialing a data analytics tool. An extract from accounts payable was loaded into the tool and as a result, the tool flagged most of the transactions, thus yielding no meaningful results. After investigating, the audit team determined that the extract contained duplicate entries and spelling issues.

Which of the following should have been performed prior to loading the data into the analytics tool?

A.

Data segregation.

B.

Data stratification.

C.

Data normalization.

D.

Data quantification.

Question # 62

Which of the following statements is true regarding a project life cycle?

A.

Risk and uncertainty increase over the life of the project.

B.

Costs and staffing levels are typically high as the project draws to a close.

C.

Costs related to making changes increase as the project approaches completion.

D.

The project life cycle corresponds with the life cycle of the product produced by or modified by the project.

Question # 63

Which of the following statements is true regarding cost-volume-profit analysis?

A.

Contribution margin is the amount remaining from sales revenue after fixed expenses have been deducted.

B.

Breakeven point is the amount of units sold to cover variable costs.

C.

Breakeven occurs when the contribution margin covers fixed costs.

D.

Following breakover1, he operating income will increase by the excess of fixed costs less the variable costs per units sold.

Question # 64

An internal auditor is assigned to perform data analytics. Which of the following is the next step the auditor should undertake after she has ascertained the value expected from the review?

A.

Normalize the data,

B.

Obtain the data

C.

Identify the risks.Analyze the data.

Question # 65

Management is designing its disaster recovery plan. In the event that there is significant damage to the organization ' s IT systems this plan should enable the organization to resume operations at a recovery site after some configuration and data restoration. Which of the following is the ideal solution for management in this scenario?

A.

A warm recovery plan.

B.

A cold recovery plan.

C.

A hot recovery plan.

D.

A manual work processes plan

Question # 66

Which of the following best explains the matching principle?

A.

Revenues should be recognized when earned.

B.

Revenue recognition is matched with cash.

C.

Expense recognition is tied to revenue recognition.

D.

Expenses are recognized at each accounting period.

Question # 67

Which of the following best describes meaningful recommendations for corrective actions?

A.

Recommendations that address the gap between the condition and consequence and provide at least short-term fixes

B.

Recommendations that address the gap between the criteria and condition and provide at least short-term fixes

C.

Recommendations that address the gap between the criteria and consequence and provide long-term solutions

D.

Recommendations that address the gap between the criteria and condition and provide long-term solutions

Question # 68

Which of the following statements Is true regarding the use of centralized authority to govern an organization?

A.

Fraud committed through collusion is more likely when authority is centralized.

B.

Centralized managerial authority typically enhances certainty and consistency within an organization.

C.

When authority is centralized, the alignment of activities to achieve business goals typically is decreased.

D.

Using separation of duties to mitigate collusion is reduced only when authority is centralized.

Question # 69

Which of the following should the chief audit executive agree upon with the board before starting an external assessment of the internal audit function?

A.

The audit areas that should be reviewed

B.

The level of testing that will be required

C.

The qualifications needed on the external assessment team

D.

The specialized skills that each external assessment team member needs

Question # 70

Which of the following is most appropriate for the chief audit executive to keep in mind when establishing policies and procedures to guide the internal audit function?

A.

The nature of the internal audit function

B.

The size of the organization

C.

The size and maturity of the internal audit function

D.

The structure of the organization

Question # 71

Which of the following organization structures would most likely be able to cope with rapid changes and uncertainties?

A.

Decentralized

B.

Centralized

C.

Departmentalized

D.

Tall structure

Question # 72

An organization uses the management-by-objectives method whereby employee performance is based on defined goals. Which of the following statements is true regarding this approach?

A.

It is particularly helpful to management when the organization is facing rapid change.

B.

It is a more successful approach when adopted by mechanistic organizations.

C.

It is mere successful when goal setting is performed not only by management, but by all team members, including lower-level staff.

D.

It is particularly successful in environments that are prone to having poor employer-employee relations.

Question # 73

What relationship exists between decentralization and the degree, importance, and range of lower-level decision making?

A.

Mutually exclusive relationship.

B.

Direct relationship.

C.

Intrinsic relationship.

D.

Inverse relationship.

Question # 74

Which of the following data analytics techniques is used to identify patterns among groups of data elements?

A.

Stratification of numeric values.

B.

Joining different data sources.

C.

Duplicate testing.

D.

Classification.

Question # 75

Which of the following is on advantage of a decentralized organizational structure, as opposed to a centralized structure?

A.

Greater cost-effectiveness

B.

Increased economies of scale

C.

Larger talent pool

D.

Strong internal controls

Question # 76

Senior management is trying to decide whether to use the direct write-off or allowance method for recording bad debt on accounts receivables. Which of the following would be the best argument for using the direct write-off method?

A.

It is useful when losses are considered insignificant.

B.

It provides a better alignment with revenue.

C.

It is the preferred method according to The IIA.

D.

It states receivables at net realizable value on the balance sheet.

Question # 77

An internal auditor is assessing the risks related to an organization’s mobile device policy. She notes that the organization allows third parties (vendors and visitors) to use outside smart devices to access its proprietary networks and systems. Which of the following types of smart device risks should the internal auditor be most concerned about?

A.

Compliance.

B.

Privacy.

C.

Strategic.

D.

Physical security.

Question # 78

Internal audit observed an increase in defects of newly installed spare parts. An investigation revealed that vendors delivered spare parts of worse quality than required by contract. Which of the following recommendations would most helpfully mitigate this risk?

A.

Add higher level managers to invoice approval process

B.

Request quality-related confirmations from vendors

C.

Conduct random inspections and testing of deliveries

D.

Improve technical specifications of procurement documents

Question # 79

Which of the following is an example of a contingent liability that a company should record?

A.

A potential assessment of additional income tax.

B.

Possible product warranty costs.

C.

The threat of a lawsuit by a competitor.

D.

The remote possibility of a contract breach.

Question # 80

Which of the following best describes a competitive strategy in which the organization focuses on attempts to be more efficient than competitors?

A.

Differentiation strategy.

B.

Cost leadership strategy.

C.

Focus strategy.

D.

Portfolio strategy.

Question # 81

The process of scenario planning begins with which of the following steps?

A.

Determining the trends that will influence key factors in the organization ' s environment.

B.

Selecting the issue or decision that will impact how the organization conducts future business.

C.

Selecting leading indicators to alert the organization of future developments.

D.

Identifying how customers, suppliers, competitors, employees, and other stakeholders will react.

Question # 82

During her annual performance review, a sales manager admits that she experiences significant stress due to her job but stays with the organization because of the high bonuses she earns. Which of the following best describes her primary motivation to remain in the job?

A.

Intrinsic reward.

B.

Job enrichment

C.

Extrinsic reward.

D.

The hierarchy of needs.

Question # 83

Which of the following devices best controls both physical and logical access to information systems?

A.

Plenum.

B.

Biometric lock.

C.

Identification card.

D.

Electromechanical lock.

Question # 84

A line on a spreadsheet includes an employee ' s name, date of hire, job title, and monthly salary. Which of the following correctly describes this line information?

A.

Field.

B.

File.

C.

Record.

D.

Database.

Question # 85

The percentage of sales method, rather than the percentage of receivables method, would be used to estimate uncollectible accounts if an organization seeks to:

A.

Use an aging schedule to more closely estimate uncollectible accounts.

B.

Eliminate the need for an allowance for doubtful accounts.

C.

Emphasize the accuracy of the net realizable value of the receivables on the balance sheet.

D.

Use a method that approximates the matching principle.

Question # 86

An organization created a formalized plan for a large project. Which of the following should be the first step in the project management plan?

A.

Estimate time required to complete the whole project.

B.

Determine the responses to expected project risks.

C.

Break the project into manageable components.

D.

Identify resources needed to complete the project

Question # 87

When preparing the annual internal audit plan, which of the following should the chief audit executive (CAE) consider to optimize efficiency and effectiveness?

A.

The CAE should review the objectives and scope of the external audit plan and consider including audits with the same objectives and scope to ensure thorough coverage of the area

B.

The CAE should review the audit plan prepared by the compliance department and coordinate any audits in the same areas to reduce duplication of objectives and minimize disruption to the area under review

C.

The CAE should avoid reviewing plans by internal or external assurance providers to increase effectiveness and reduce bias in internal audit selection

D.

The CAE should review operational quality assurance audit plans, place reliance on the areas covered, and exclude those areas from final consideration in the annual internal audit plan

Question # 88

An organization ' s board of directors is particularly focused on positioning, the organization as a leader in the industry and beating the competition. Which of the following strategies offers the greatest alignment with the board ' s focus?

A.

Divesting product lines expected to have negative profitability.

B.

Increasing the diversity of strategic business units.

C.

Increasing investment in research and development for a new product.

D.

Relocating the organization ' s manufacturing to another country.

Question # 89

An intruder posing as the organization ' s CEO sent an email and tricked payroll staff into providing employees ' private tax information. What type of attack was perpetrated?

A.

Boundary attack.

B.

Spear phishing attack.

C.

Brute force attack.

D.

Spoofing attack.

Question # 90

Which of the following is a disadvantage in a centralized organizational structure?

A.

Communication conflicts

B.

Slower decision making.

C.

Loss of economies of scale

D.

Vulnerabilities in sharing knowledge

Question # 91

Which of the following statements is accurate regarding the use of Secure Sockets Layer (SSL) as a control?

A.

It supports the authentication of information sent to a server.

B.

It prevents phishing attacks that redirect users to malicious sites.

C.

It prevents malware infections.

D.

It identifies each client-server session using temporary tokens.

Question # 92

Organizations use matrix management to accomplish which of the following?

A.

To improve the chain of command.

B.

To strengthen corporate headquarters.

C.

To focus better on a single market.

D.

To increase lateral communication.

Question # 93

According to IIA guidance, which of the following is an IT project success factor?

A.

Streamlined decision-making, rather than building consensus among users.

B.

Consideration of the facts, rather than consideration of the emotions displayed by project stakeholders.

C.

Focus on flexibility and adaptability, rather than use of a formal methodology.

D.

Inclusion of critical features, rather than inclusion of an array of supplementary features.

Question # 94

Which of the following is generally considered a best practice related to data backup?

    Performing full system backups on weekdays.

    Storing system backups onsite in a secured location.

    Testing system backup media periodically.

    Verifying backup media can be retrieved within seven years.

A.

2 only.

B.

3 only.

C.

1, 2, and 3 only.

D.

2, 3, and 4 only.

Question # 95

Which of the following statements is correct regarding risk analysis?

A.

The extent to which management judgments are required in an area could serve as a risk factor in assisting the auditor in making a comparative risk analysis.

B.

The highest risk assessment should always be assigned to the area with the largest potential loss.

C.

The highest risk assessment should always be assigned to the area with the highest probability of occurrence.

D.

Risk analysis must be reduced to quantitative terms in order to provide meaningful comparisons across an organization.

Question # 96

Which of the following does not provide operational assurance that a computer system is operating properly?

A.

Performing a system audit.

B.

Making system changes.

C.

Testing policy compliance.

D.

Conducting system monitoring.

Question # 97

Which of the following Issues would be a major concern for internal auditors when using a free software to analyze a third-party vendor ' s big data?

A.

The ability to use the software with ease to perform the data analysis to meet the engagement objectives.

B.

The ability to purchase upgraded features of the software that allow for more In-depth analysis of the big data.

C.

The ability to ensure that big data entered into the software is secure from potential compromises or loss.

D.

The ability to download the software onto the appropriate computers for use in analyzing the big data.

Question # 98

Which of the following accurately describes a difference between phishing and spear phishing?

A.

Phishing targets individuals indiscriminately, while spear phishing targets specific individuals.

B.

Phishing uses emails in attacks, while spear phishing uses other methods.

C.

Phishing requires unauthorized access to a system, while spear phishing requires successful social engineering attempts.

D.

Phishing aims to acquire personal information, while spear phishing aims to send unsolicited notifications or advertisements.

Question # 99

Internal audit discovered that several loads of pellets were deleted from the scaling database and consequently had no sales invoices, significantly affecting financial statements. An investigation revealed that technicians had deleted the pellet loads accidentally, with no evidence of fraud. Which of the following actions should management implement first?

A.

Address root causes by launching a project to understand and revise the methods for granting database access rights

B.

Address the condition by limiting technicians ' access to live database data

C.

Address potential risks by reconciling all sales invoices against scaling data

D.

Address investigation results by dismissing technicians who caused the disruption

Question # 100

Which of the following is a product-oriented definition of a business rather than a market-oriented definition of a business?

A.

We are a people-and-goods mover.

B.

We supply energy.

C.

We make movies.

D.

We provide climate control in the home.

Question # 101

An internal auditor is completing an access control assessment of a telecommunication organization’s offsite facility.

Which of the following physical security measures would best prevent unauthorized access to the facility?

A.

Proximity badges.

B.

Key locks.

C.

Combination codes.

D.

Biometric locks.

Question # 102

How do data analysis technologies affect internal audit testing?

A.

They improve the effectiveness of spot check testing techniques

B.

They allow greater insight into high-risk areas

C.

They reduce the overall scope of the audit engagement

D.

They increase the internal auditor’s objectivity

Question # 103

Which of the following is most important for an internal auditor to check with regard to the database version?

A.

Verify whether the organization uses the most recent database software version.

B.

Verify whether the database software version is supported by the vendor.

C.

Verify whether the database software version has been recently upgraded.

D.

Verify whether access to database version information is appropriately restricted.

Question # 104

Which of the following would provide the most relevant assurance that the application under development will provide maximum value to the organization?

A.

Use of a formal systems development lifecycle.

B.

End-user involvement.

C.

Adequate software documentation.

D.

Formalized non-regression testing phase.

Question # 105

An organization is planning to outsource its payroll function to an external service provider. The internal auditors advised management of the risks related to outsourcing and the typical controls that should be provided by the external service provider.

Which of the following statements is true regarding the internal auditors’ advice?

A.

Independence was compromised by recommending internal controls, as the internal auditors will be testing the same controls in the future.

B.

Objectivity was compromised by intervening before the outsourcing procedures and controls were established.

C.

The internal auditors should work directly with the external service provider to ensure basic controls are in place and working as intended.

D.

The external service provider controls recommended by the internal auditors may be insufficient to protect the organization.

Question # 106

Which of the following attributes of data analytics relates to the growing number of sources from which data is being generated?

A.

Volume.

B.

Velocity.

C.

Variety.

D.

Veracity.

Question # 107

The finance department of an organization recently undertook an asset verification exercise. The internal audit function scheduled a review of the IT department’s operations, which includes verifying the existence of computers distributed and their assignment. Can the internal audit function consider relying on the asset verification work performed by the finance department?

A.

Yes, in order to be efficient and make better use of internal audit resources

B.

No, as the finance department is an internal department of the organization

C.

Yes, but the finance manager would be responsible for supporting the conclusions of the work

D.

No, the internal audit function should do its own verification and should not rely on the work of finance

Question # 108

An organization has an agreement with a third-party vendor to have a fully operational facility, duplicate of the original site and configured to the organization ' s needs, in order to quickly recover operational capability in the event of a disaster, Which of the following best describes this approach to disaster recovery planning?

A.

Cold recovery plan,

B.

Outsourced recovery plan.

C.

Storage area network recovery plan.

D.

Hot recovery plan

Question # 109

A third party who provides payroll services to the organization was asked to create audit or “read-only 1 functionalities in their systems. Which of the following statements is true regarding this request?

A.

This will support execution of the right-to-audit clause.

B.

This will enforce robust risk assessment practices

C.

This will address cybersecurity considerations and concerns.

D.

This will enhance the third party ' s ability to apply data analytics

Question # 110

Which of the following statements is true regarding multi-report summaries for members of senior management and the board?

A.

Multi-report summaries should be used to describe the work performed by the internal audit function

B.

In developing multi-report summaries, internal auditors should use multi-row and multi-column tables

C.

Multi-report summaries are not useful to boards that see every engagement report

D.

Multi-report summaries are readily developed if each finding is rated

Question # 111

Which of the following statements is accurate when planning for an external quality assurance assessment of the internal audit function?

A.

The external assessment would include the audit function’s compliance with laws and regulations

B.

The selected qualified assessor can be from the organization’s shared services team

C.

The external assessment team members must work for an accounting firm

D.

The frequency of the performance of assessments should be considered by the assessor

Question # 112

Which of the following facilitates data extraction from an application?

A.

Application program code.

B.

Database system.

C.

Operating system.

D.

Networks.

Question # 113

Which of the following distinguishes the added-value negotiation method from traditional negotiating methods?

A.

Each party ' s negotiator presents a menu of options to the other party.

B.

Each party adopts one initial position from which to start.

C.

Each negotiator minimizes the information provided to the other party.

D.

Each negotiator starts with an offer, which is optimal from the negotiator ' s perspective.

Question # 114

Which of the following are the most appropriate measures for evaluating the change in an organization ' s liquidity position?

A.

Times interest earned, return on assets, and inventory turnover.

B.

Accounts receivable turnover, inventory turnover in days, and the current ratio.

C.

Accounts receivable turnover, return on assets, and the current ratio.

D.

Inventory turnover in days, the current ratio, and return on equity.

Question # 115

Preferred stock is less risky for investors than is common stock because:

A.

Common stock pays dividends as a stated percentage of face value.

B.

Common stock has priority over preferred stock with regard to earnings and assets.

C.

Preferred dividends are usually cumulative.

D.

Preferred stock with no conversion feature has a higher dividend yield than does convertible preferred stock.

Question # 116

According to IIA guidance, which of the following would be the best first stop to manage risk when a third party is overseeing the organization ' s network and data?

A.

Creating a comprehensive reporting system for vendors to demonstrate their ongoing due diligence in network operations.

B.

Drafting a strong contract that requires regular vendor control reports end a right-to-audit clause.

C.

Applying administrative privileges to ensure right to access controls are appropriate.

D.

Creating a standing cyber-security committee to identify and manage risks related to data security

Question # 117

At what point during the systems development process should an internal auditor verify that the new application ' s connectivity to the organization ' s other systems has been established correctly?

A.

Prior to testing the new application.

B.

During testing of the new application.

C.

During implementation of the new application.

D.

During maintenance of the new application.

Question # 118

According to IIA guidance on IT, which of the following best describes a situation where data backup plans exist to ensure that critical data can be restored at some point in the future, but recovery and restore processes have not been defined?

A.

Hot recovery plan

B.

Warm recovery plan

C.

Cold recovery plan

D.

Absence of recovery plan

Question # 119

While conducting ' audit procedures at the organization ' s data center an internal auditor noticed the following:

- Backup media was located on data center shelves.

- Backup media was organized by date.

- Backup schedule was one week in duration.

The system administrator was able to present restore logs.

Which of the following is reasonable for the internal auditor to conclude?

A.

Backup media is not properly stored, as the storage facility should be off-site.

B.

Backup procedures are adequate and appropriate according to best practices.

C.

Backup media is not properly indexed, as backup media should be indexed by system, not date.

D.

Backup schedule is not sufficient, as full backup should be conducted daily.

Question # 120

Which of the following are the most common characteristics of big data?

A.

Visibility, validity, vulnerability

B.

Velocity, variety, volume

C.

Complexity, completeness, constancy

D.

Continuity, control, convenience

Question # 121

An organization has a declining inventory turnover but an Increasing gross margin rate, Which of the following statements can best explain this situation?

A.

The organization ' s operating expenses are increasing.

B.

The organization has adopted just-in-time inventory.

C.

The organization is experiencing Inventory theft

D.

The organization ' s inventory is overstated.

Question # 122

Which of the following is a primary driver behind the creation and prioritization of new strategic initiatives established by an organization?

A.

Risk tolerance.

B.

Performance.

C.

Threats and opportunities.

D.

Governance.

Question # 123

At an organization that uses a periodic inventory system, the accountant accidentally understated the organization s beginning inventory. How would the accountant ' s accident impact the income statement?

A.

Cost of goods sold will be understated and net income will be overstated.

B.

Cost of goods sold will be overstated and net income will be understated

C.

Cost of goods sold will be understated and there Wi-Fi be no impact on net income.

D.

There will be no impact on cost of goods sold and net income will be overstated

Question # 124

An internal auditor for a pharmaceutical company as planning a cybersecurity audit and conducting a risk assessment. Which of the following would be considered the most significant cyber threat to the organization?

A.

Cybercriminals hacking into the organization ' s time and expense system to collect employee personal data.

B.

Hackers breaching the organization ' s network to access research and development reports

C.

A denial-of-service attack that prevents access to the organization ' s website.

D.

A hacker accessing she financial information of the company

Question # 125

A new manager received computations of the internal rate of return regarding his project proposal. What should the manager compare the computation results to in order to determine whether the project is potentially acceptable?

A.

Compare to the annual cost of capital.

B.

Compare to the annual interest rate.

C.

Compare to the required rate of return.

D.

Compare to the net present value.

Question # 126

Which of the following physical security controls is able to serve as both a detective and preventive control?

A.

Authentication logs.

B.

Card key readers.

C.

Biometric devices

D.

Video surveillance.

Question # 127

International marketing activities often begin with:

A.

Standardization.

B.

Global marketing.

C.

Limited exporting.

D.

Domestic marketing.

Question # 128

While performing an audit of a car tire manufacturing plant, an internal auditor noticed a significant decrease in the number of tires produced from the previous operating

period. To determine whether worker inefficiency caused the decrease, what additional information should the auditor request?

A.

Total tire production labor hours for the operating period.

B.

Total tire production costs for the operating period.

C.

Plant production employee headcount average for the operating period.

D.

The production machinery utilization rates.

Question # 129

Which of the following describes a benefit of using data analytics during an audit engagement?

A.

An increased number of data extracts obtained from IT personnel.

B.

A reduced audit risk by focusing risk assessment and stratifying the population.

C.

A broadened scope of assurance services through the increase of audit staff.

D.

An increased performance level of data analysis that enables reduced time for audit planning.

Question # 130

A manager has difficulty motivating staff to improve productivity, despite establishing a lucrative individual reward system. Which of the following is most likely the cause of the difficulty?

A.

High degree of masculinity.

B.

Low uncertainty avoidance.

C.

High collectivism.

D.

Low long-term orientation.

Question # 131

Which of the following capital budgeting techniques considers the expected total net cash flows from investment?

A.

Cash payback

B.

Annual rate of return

C.

Incremental analysis

D.

Net present value

Question # 132

An organization that soils products to a foreign subsidiary wants to charge a price that wilt decrease import tariffs. Which of the following is the best course of action for the organization?

A.

Decrease the transfer price

B.

Increase the transfer price

C.

Charge at the arm ' s length price

D.

Charge at the optimal transfer price

Question # 133

An organization buys equity securities for trading purposes and sells them within a short time period. Which of the following is the correct way to value and report those securities at a financial statement date?

A.

At fair value with changes reported in the shareholders ' equity section.

B.

At fair value with changes reported in net income.

C.

At amortized cost in the income statement.

D.

As current assets in the balance sheet

Question # 134

An internal auditor has finalized an engagement of the vendor master file. The results of the current engagement do not differ significantly from that of last year, in which several significant weaknesses in internal controls were reported. The internal auditor states in the final communication that the internal controls are as effective as that of the previous year. Which of the following elements of quality of communication could be improved?

A.

Conciseness

B.

Constructiveness

C.

Objectivity

D.

Accuracy

Question # 135

Which of the following security controls would be me most effective in preventing security breaches?

A.

Approval of identity request

B.

Access logging.

C.

Monitoring privileged accounts

D.

Audit of access rights

Question # 136

An IT auditor is evaluating IT controls of a newly purchased information system. The auditor discovers that logging is not configured al database and application levels. Operational management explains that they do not have enough personnel to manage the logs and they see no benefit in keeping logs. Which of the fallowing responses best explains risks associated with insufficient or absent logging practices?

A.

The organization will be unable to develop preventative actions based on analytics.

B.

The organization will not be able to trace and monitor the activities of database administers.

C.

The organization will be unable to determine why intrusions and cyber incidents took place.

D.

The organization will be unable to upgrade the system to newer versions.

Question # 137

According to IIA guidance on IT, which of the following plans would pair the identification of critical business processes with recovery time objectives?

A.

The business continuity management charter

B.

The business continuity risk assessment plan

C.

The business impact analysis plan

D.

The business case for business continuity planning

Question # 138

Which of the following should be included in a data privacy poky?

1. Stipulations for deleting certain data after a specified period of time.

2. Guidance on acceptable methods for collecting personal data.

3. A requirement to retain personal data indefinitely to ensure a complete audit trail,

4. A description of what constitutes appropriate use of personal data.

A.

1 and 2 only

B.

2 and 3 only

C.

1, 2 and 4 only

D.

2, 3, and 4 only

Question # 139

According to IIA guidance, which of the following best describes an adequate management (audit) trail application control for the general ledger?

A.

Report identifying data that is outside of system parameters.

B.

Report identifying general ledger transactions by time and individual.

C.

Report comparing processing results with original input.

D.

Report confirming that the general ledger data was processed without error.

Question # 140

A manager at a publishing company received an email that appeared to be from one of her vendors with an attachment that contained malware embedded in an Excel spreadsheet . When the spreadsheet was opened, the cybercriminal was able to attack the company ' s network and gain access to an unpublished and highly anticipated book. Which of the following controls would be most effective to prevent such an attack?

A.

Monitoring network traffic.

B.

Using whitelists and blacklists to manage network traffic.

C.

Restricting access and blocking unauthorized access to the network

D.

Educating employees throughout the company to recognize phishing attacks.

Question # 141

Which of the following are likely indicators of ineffective change management?

    IT management is unable to predict how a change will impact interdependent systems or business processes.

    There have been significant increases in trouble calls or in support hours logged by programmers.

    There is a lack of turnover in the systems support and business analyst development groups.

    Emergency changes that bypass the normal control process frequently are deemed necessary.

A.

1 and 3 only

B.

2 and 4 only

C.

1, 2, and 4 only

D.

1, 2, 3, and 4

Question # 142

Which of the following is true of matrix organizations?

A.

A unity-of-command concept requires employees to report technically, functionally, and administratively to the same manager.

B.

A combination of product and functional departments allows management to utilize personnel from various Junctions.

C.

Authority, responsibility and accountability of the units Involved may vary based on the project ' s life, or the organization ' s culture

D.

It is best suited for firms with scattered locations or for multi-line, Large-scale firms.

Question # 143

Which of the following would be the best method to collect information about employees ' job satisfaction?

A.

Online surveys sent randomly to employees.

B.

Direct onsite observations of employees.

C.

Town hall meetings with employees.

D.

Face-to-face interviews with employees.

Question # 144

A financial technology startup consists of self-managed teams. Although each team can make proposals to other teams, decision-making lies within each individual team.

Which of the following risks could arise from this organizational structure?

A.

Processes are bureaucratic.

B.

Decision-making is slow.

C.

Resources are duplicated.

D.

Power is overconcentrated.

Question # 145

An internal auditor observed that the organization ' s disaster recovery solution will make use of a cold site in a town several miles away. Which of the following is likely to be a characteristic of this disaster recover/ solution?

A.

Data is synchronized in real time

B.

Recovery time is expected to be less than one week

C.

Servers are not available and need to be procured

D.

Recovery resources end data restore processes have not been defined.

Question # 146

Which of the following differentiates a physical access control from a logical access control?

A.

Physical access controls secure tangible IT resources, whereas logical access controls secure software and data internal to the IT system.

B.

Physical access controls secure software and data internal to the IT system, whereas logical access controls secure tangible IT resources.

C.

Physical access controls include firewalls, user IDs, and passwords, whereas logical access controls include locks and security guards.

D.

Physical access controls include input processing and output controls, whereas logical access controls include locked doors and security guards.

Question # 147

According to IIA guidance, which of the following statements is true regarding analytical procedures?

A.

Data relationships are assumed to exist and to continue where no known conflicting conditions exist

B.

Analytical procedures are intended primarily to ensure the accuracy of the information being examined

C.

Data relationships cannot include comparisons between operational and statistical data

D.

Analytical procedures can be used to identify differences, but cannot be used to identify the absence of differences

Question # 148

An organization decided to install a motion detection system in its warehouse to protect against after-hours theft. According to the COSO enterprise risk management framework, which of the following best describes this risk management strategy?

A.

Avoidance.

B.

Reduction.

C.

Elimination.

D.

Sharing.

Question # 149

When developing an effective risk-based plan to determine audit priorities, an internal audit activity should start by:

A.

Identifying risks to the organization ' s operations.

B.

Observing and analyzing controls.

C.

Prioritizing known risks.

D.

Reviewing organizational objectives.

Question # 150

Which of the following is an advantage of a decentralized organizational structure, as opposed to a centralized structure?

A.

Greater cost-effectiveness

B.

Increased economies of scale

C.

Larger talent pool

D.

Strong internal controls

Question # 151

Which of the following techniques is the most relevant when an internal auditor conducts a valuation of an organization ' s physical assets?

A.

Observation.

B.

Inspection.

C.

Original cost.

D.

Vouching.

Question # 152

Which of the following statements regarding database management systems is not correct?

A.

Database management systems handle data manipulation inside the tables, rather than it being done by the operating system itself in files.

B.

The database management system acts as a layer between the application software and the operating system.

C.

Applications pass on the instructions for data manipulation which are then executed by the database management system.

D.

The data within the database management system can only be manipulated directly by the database management system administrator.

Question # 153

Which of the following are appropriate functions for an IT steering committee?

    Assess the technical adequacy of standards for systems design and programming.

    Continually monitor the adequacy and accuracy of software and hardware in use.

    Assess the effects of new technology on the organization ' s IT operations.

    Provide broad oversight of implementation, training, and operation of new systems.

A.

1, 2, and 3

B.

1, 2, and 4

C.

1, 3, and 4

D.

2, 3, and 4

Question # 154

Which of the following is improved by the use of smart devices?

A.

Version control

B.

Privacy

C.

Portability

D.

Secure authentication

Question # 155

Which of the following authentication controls combines what a user knows with the unique characteristics of the user, respectively?

A.

Voice recognition and token

B.

Password and fingerprint

C.

Fingerprint and voice recognition

D.

Password and token

Question # 156

Which of the following is a key factor in the development of a production budget for a manufacturing organization?

A.

Direct materials units required.

B.

Estimated ending unit inventory.

C.

Projected sales revenue.

D.

Variable overhead costs.

Question # 157

An internal auditor discovered that the organization was not in full compliance with a regulatory labeling requirement for one of its products. The responsible manager indicated that the current product labeling has been in use for several years without any problems. If discovered, this regulatory breach could result in significant fines for the organization. What should be the chief audit executive ' s next course of action?

A.

Discuss the matter with the CEO and other senior management

B.

Recommend that disciplinary action be taken against the manager for exposing the company to such risk

C.

Communicate to the board the current situation, including the risk exposure to the company

D.

Take on the initiative of implementing corrective actions to mitigate the identified risks

Question # 158

A financial institution receives frequent and varied email requests from customers for funds to be wired out of their accounts. Which verification activity would best help the institution avoid falling victim to phishing?

A.

Reviewing the customer ' s wire activity to determine whether the request is typical.

B.

Calling the customer at the phone number on record to validate the request.

C.

Replying to the customer via email to validate the sender and request.

D.

Reviewing the customer record to verify whether the customer has authorized wire requests from that email address.

Question # 159

An IT auditor tested management of access rights and uncovered 48 instances where employees moved to a new position within the organization, but their former access rights were not revoked. System administrators explained that they did not receive information regarding employees’ new positions. Which of the following would be the best recommendation to address the root causes of the audit observation?

A.

Conduct an inventory of access rights of all employees who have changed their position within the last year

B.

Remove unneeded access rights for uncovered instances and reprimand system administrators for carelessness

C.

Provide system administrators with job descriptions of employees and let them determine relevant access rights

D.

Require that access rights to IT systems be ordered by process owners based on user role descriptions

Question # 160

When granting third parties temporary access to an entity ' s computer systems, which of the following is the most effective control?

A.

Access is approved by the supervising manager.

B.

User accounts specify expiration dates and are based on services provided.

C.

Administrator access is provided for a limited period.

D.

User accounts are deleted when the work is completed.

Question # 161

Which of the following price adjustment strategies encourages prompt payment?

A.

Cash discounts.

B.

Quantity discounts.

C.

Functional discounts.

D.

Seasonal discounts.

Question # 162

Which of the following attributes of data are cybersecurity controls primarily designed to protect?

A.

Veracity, velocity, and variety.

B.

Integrity, availability, and confidentiality.

C.

Accessibility, accuracy, and effectiveness.

D.

Authorization, logical access, and physical access.

Question # 163

Which of the following accurately describes the proper order of steps for an internal auditor to use when analyzing data?

A.

Obtain the data, clean and normalize the data, define the question, analyze the data.

B.

Define the question, obtain the data, analyze the data, clean and normalize the data.

C.

Define the question, obtain the data, clean and normalize the data, analyze the data.

D.

Obtain the data, analyze the data, clean and normalize the data, define the question.

Question # 164

An internal auditor discovered that several unauthorized modifications were made to the production version of an organization ' s accounting application. Which of the following best describes this deficiency?

A.

Production controls weakness.

B.

Application controls weakness.

C.

Authorization controls weakness.

D.

Change controls weakness.

Question # 165

Which of the following authentication device credentials is the most difficult to revoke when an employee ' s access rights need to be removed?

A.

A traditional key lock.

B.

A biometric device.

C.

A card-key system.

D.

A proximity device.

Question # 166

An organization ' s technician was granted a role that enables him to prioritize projects throughout the organization. Which type of authority will the technician most likely be exercising?

A.

Legitimate authority

B.

Coercive authority.

C.

Referent authority.

D.

Expert authority.

Question # 167

A manager decided to build his team ' s enthusiasm by giving encouraging talks about employee empowerment, hoping to change the perception that management should make all decisions in the department.

The manager is most likely trying to impact which of the following components of his team ' s attitude?

A.

Affective component.

B.

Cognition component.

C.

Thinking component.

D.

Behavioral component.

Question # 168

During an audit of the payroll system, the internal auditor identifies and documents the following condition:

" Once a user is logged into the system, the user has access to all functionality within the system. "

What is the most likely root cause for tins issue?

A.

The authentication process relies on a simple password only, which is a weak method of authorization.

B.

The system authorization of the user does not correctly reflect the access rights intended.

C.

There was no periodic review to validate access rights.

D.

The application owner apparently did not approve the access request during the provisioning process.

Question # 169

Upon completing a follow-up audit engagement, the chief audit executive (CAE) noted that management has not implemented any mitigation measures to address the high risks that were reported in the initial audit report. What initial step must the CAE take to address this situation?

A.

Communicate the issue to senior management

B.

Discuss the issue with members of management responsible for the risk area

C.

Report the situation to the external auditors

D.

Escalate the issue to the board

Question # 170

How do data analysis technologies affect internal audit testing?

A.

They improve the effectiveness of spot check testing techniques.

B.

They allow greater insight into high risk areas.

C.

They reduce the overall scope of the audit engagement,

D.

They increase the internal auditor ' s objectivity.

Question # 171

Which of the following situations best illustrates a " false positive " in the performance of a spam filter?

A.

The spam filter removed Incoming communication that included certain keywords and domains.

B.

The spam filter deleted commercial ads automatically, as they were recognized as unwanted.

C.

The spam filter routed to the " junk|r folder a newsletter that appeared to include links to fake websites.

D.

The spam filter blocked a fitness club gift card that coworkers sent to an employee for her birthday.

Question # 172

Which of the following is not a potential area of concern when an internal auditor places reliance on spreadsheets developed by users?

A.

Increasing complexity over time.

B.

Interface with corporate systems.

C.

Ability to meet user needs.

D.

Hidden data columns or worksheets.

Question # 173

Which of the following principles is shared by both hierarchical and open organizational structures?

A superior can delegate the authority to make decisions but cannot delegate the ultimate responsibility for the results of those decisions.

A supervisor ' s span of control should not exceed seven subordinates.

Responsibility should be accompanied by adequate authority.

Employees at all levels should be empowered to make decisions.

A.

1 and 3 only

B.

1 and 4 only

C.

2 and 3 only

D.

3 and 4 only

Question # 174

Which of the following is a characteristic of just-in-time inventory management systems?

A.

Users determine the optimal level of safety stocks.

B.

They are applicable only to large organizations.

C.

They do not really increase overall economic efficiency because they merely shift inventory levels further up the supply chain.

D.

They rely heavily on high-quality materials.

Question # 175

Which of the following is a systems software control?

A.

Restricting server room access to specific individuals

B.

Housing servers with sensitive software away from environmental hazards

C.

Ensuring that all user requirements are documented

D.

Performing of intrusion testing on a regular basis

Question # 176

A retail organization mistakenly did not include $10,000 of inventory in the physical count at the end of the year. What was the impact to the organization’s financial statements?

A.

Cost of sales and net income are understated

B.

Cost of sales and net income are overstated

C.

Cost of sales is understated and net income is overstated

D.

Cost of sales is overstated and net income is understated

Question # 177

Which of the following measures would best protect an organization from automated attacks whereby the attacker attempts to identify weak or leaked passwords in order to log into employees ' accounts?

A.

Requiring users to change their passwords every two years.

B.

Requiring two-step verification for all users

C.

Requiring the use of a virtual private network (VPN) when employees are out of the office.

D.

Requiring the use of up-to-date antivirus, security, and event management tools.

Question # 178

Which of the following is an example of internal auditors applying data mining techniques for exploratory purposes?

A.

Internal auditors perform reconciliation procedures to support an external audit of financial reporting.

B.

Internal auditors perform a systems-focused analysis to review relevant controls.

C.

Internal auditors perform a risk assessment to identify potential audit subjects as input for the annual internal audit plan

D.

Internal auditors test IT general controls with regard to operating effectiveness versus design

Question # 179

Which of the following is considered a physical security control?

A.

Transaction logs are maintained to capture a history of system processing.

B.

System security settings require the use of strong passwords and access controls.

C.

Failed system login attempts are recorded and analyzed to identify potential security incidents.

D.

System servers are secured by locking mechanisms with access granted to specific individuals.

Question # 180

Which of the following is likely to have an expiration date and may contain stored clear text passwords?

A.

Cookie.

B.

Universal resource locator (URL).

C.

Hypertext transport protocol (HTTP).

D.

Browser.

Question # 181

When writing a business memorandum, the writer should choose a writing style that achieves all of the following except:

A.

Draws positive attention to the writing style.

B.

Treats all receivers with respect.

C.

Suits the method of presentation and delivery.

D.

Develops ideas without overstatement.

Question # 182

Which of the following best describes the purpose of fixed manufacturing costs?

A.

To ensure availability of production facilities.

B.

To decrease direct expenses related to production.

C.

To incur stable costs despite operating capacity.

D.

To increase the total unit cost under absorption costing

Question # 183

Which of the following is a potential risk for an organization that allows employees to use their personal devices to conduct business?

A.

Less efficiency.

B.

Lower employee satisfaction.

C.

Higher organizational costs on devices.

D.

Increased exposure to malware attacks.

Question # 184

A company records income from an investment in common stock when it does which of the following?

A.

Purchases bonds.

B.

Receives interest.

C.

Receives dividends

D.

Sells bonds.

Question # 185

Which of the following physical security controls would most likely be used as a corrective control?

A.

Monitored closed circuit televisions.

B.

Doors that lock automatically.

C.

Biometric locks.

D.

Identification badges.

Question # 186

Which of the following should be established by management during implementation of big data systems to enable ongoing production monitoring?

A.

Key performance indicators.

B.

Reports of software customization.

C.

Change and patch management.

D.

Master data management

Question # 187

Which of the following is true regarding the use of remote wipe for smart devices?

A.

It can restore default settings and lock encrypted data when necessary.

B.

It enables the erasure and reformatting of secure digital (SD) cards.

C.

It can delete data backed up to a desktop for complete protection if required.

D.

It can wipe data that is backed up via cloud computing

Question # 188

Which of the following situations best applies to an organisation that uses a project, rather than a process, to accomplish its business activities?

A.

Clothing company designs, makes, and sells a new item.

B.

A commercial construction company is hired to build a warehouse.

C.

A city department sets up a new firefighter training program.

D.

A manufacturing organization acquires component parts from a contracted vendor

Question # 189

According to IIA guidance, which of the following steps are most important for an internal auditor to perform when evaluating an organization ' s social and environmental impact on the local community?

    Determine whether previous incidents have been reported, managed, and resolved.

    Determine whether a business contingency plan exists.

    Determine the extent of transparency in reporting.

    Determine whether a cost/benefit analysis was performed for all related projects.

A.

1 and 3.

B.

1 and 4.

C.

2 and 3.

D.

2 and 4.

Question # 190

Which of the following techniques would best detect an inventory fraud scheme?

A.

Analyze Invoice payments just under individual authorization limits.

B.

Analyze stratification of inventory adjustments by warehouse location.

C.

Analyze inventory invoice amounts and compare with approved contract amounts.

D.

Analyze differences discovered during duplicate payment testing

Question # 191

An organization prepares a statement of privacy to protect customers ' personal information. Which of the following might violate the privacy principles?

A.

Customers can access and update personal information when needed.

B.

The organization retains customers ' personal information indefinitely.

C.

Customers reserve the right to reject sharing personal information with third parties.

D.

The organization performs regular maintenance on customers ' personal information.

Question # 192

Which of the following is an example of a physical control designed to prevent security breaches?

A.

Preventing database administrators from initiating program changes

B.

Blocking technicians from getting into the network room.

C.

Restricting system programmers ' access to database facilities

D.

Using encryption for data transmitted over the public internet

Question # 193

A significant project is nearing its development stage end, and line management intends to apply for a final investment decision from senior management at an upcoming meeting. The internal audit function is at the fieldwork stage of an assurance engagement related to this project and discovers that tenders conducted for the project were not carried out transparently by line management. The audit report will not be ready by the upcoming senior management meeting. Which of the following actions is the most appropriate next step for the chief audit executive?

A.

Escalate the issue to the chief risk officer

B.

Raise the issue with senior management

C.

Continue with the assurance engagement as planned

D.

Place the assurance engagement on hold due to inappropriate timing

Question # 194

Which of the following should software auditors do when reporting internal audit findings related to enterprisewide resource planning?

A.

Draft separate audit reports for business and IT management.

B.

Conned IT audit findings to business issues.

C.

Include technical details to support IT issues.

D.

Include an opinion on financial reporting accuracy and completeness.

Question # 195

Which of the following best describes owner ' s equity?

A.

Assets minus liabilities.

B.

Total assets.

C.

Total liabilities.

D.

Owners contribution plus drawings.

Question # 196

A bond that matures after one year has a face value of S250,000 and a coupon of $30,000. if the market price of the bond is 5265,000, which of the following would be the market interest rate?

A.

Less than 12 percent.

B.

12 percent.

C.

Between 12.01 percent and 12.50 percent.

D.

More than 12 50 percent.

Question # 197

The internal audit activity completed an initial risk analysis of the organization ' s data storage center and found several areas of concern. Which of the following is the most appropriate next step?

A.

Risk response.

B.

Risk identification.

C.

Identification of context.

D.

Risk assessment.

Question # 198

Which of the following risks is best addressed by encryption?

A.

Information integrity risk.

B.

Privacy risk.

C.

Access risk.

D.

Software risk.

Question # 199

An internal auditor observed that the organization ' s disaster recovery solution will make use of a cold site in a town several miles away. Which of the following is likely to be a characteristic of this disaster recovery solution?

A.

Data is synchronized in real time.

B.

Recovery time is expected to be less than one week.

C.

Servers are not available and need to be procured.

D.

Recovery resources and data restore processes have been defined.

Question # 200

Which of the following best describes a transformational leader, as opposed to a transactional leader?

A.

The leader searches for deviations from the rules and standards and intervenes when deviations exist.

B.

The leader intervenes only when performance standards are not met.

C.

The leader intervenes to communicate high expectations.

D.

The leader does not intervene to promote problem-solving

Question # 201

Which of the following best describes a cyberattacK in which an organization faces a denial-of-service threat created through malicious data encryption?

A.

Phishing.

B.

Ransomware.

C.

Hacking.

D.

Makvare

Question # 202

Which of the following methods has the lowest risk of inaccurate authentication?

A.

Fingerprint identification.

B.

Complex passwords.

C.

Signature verification.

D.

Personal security questions.

Question # 203

Which of the following backup methodologies would be most efficient in backing up a database in the production environment?

A.

Disk mirroring of the data being stored on the database.

B.

A differential backup that is performed on a weekly basis.

C.

An array of independent disks used to back up the database.

D.

An incremental backup of the database on a daily basis.

Question # 204

The economic order quantity for inventory is higher for an organization that has:

A.

Lower annual unit sales.

B.

Higher fixed inventory ordering costs.

C.

Higher annual carrying costs as a percentage of inventory value.

D.

A higher purchase price per unit of inventory.

Question # 205

According to 11A guidance on IT, which of the following spreadsheets is most likely to be considered a high-risk user-developed application?

A.

A revenue calculation spreadsheet supported with price and volume reports from the production department.

B.

An asset retirement calculation spreadsheet comprised of multiple formulas and assumptions.

C.

An ad-hoc inventory listing spreadsheet comprising details of written-off inventory quantities.

D.

An accounts receivable reconciliation spreadsheet used by the accounting manager to verify balances

Question # 206

Focus An organization has decided to have all employees work from home. Which of the following network types would securely enable this approach?

A.

A wireless local area network (WLAN ).

B.

A personal area network (PAN).

C.

A wide area network (WAN).

D.

A virtual private network (VPN)

Question # 207

According to internal organizational rules, procurement specialists are responsible for carrying out procurement procedures in accordance with legal acts, but have little knowledge of the equipment and services being procured. Business unit engineers are responsible for preparing the technical descriptions of the desired equipment.

Which of the following controls should be implemented to mitigate potential fraud risks that may occur in the described arrangement?

A.

Require technical descriptions to be reviewed by a group of internal experts.

B.

Require procurement specialists to obtain higher education in a technical field.

C.

Assign the task of writing technical descriptions to procurement specialists.

D.

Assign the task of writing technical descriptions to potential bidders.

Question # 208

When initiating international ventures, an organization should consider cultural dimensions in order to prevent misunderstandings. Which of the following does not represent a recognized cultural dimension in a work environment?

A.

Self-control.

B.

Power distance.

C.

Masculinity versus femininity.

D.

Uncertainty avoidance.

Question # 209

The cost to enter a foreign market would be highest in which of the following methods of global expansion?

A.

Joint ventures.

B.

Licensing.

C.

Exporting.

D.

Overseas production.

Question # 210

Which of the following activities would come last in the development and implementation of a privacy and data protection program?

A.

Selecting the privacy and data protection framework.

B.

Establishing an assessment and communication format.

C.

Defining the scope of implementation procedures.

D.

Defining the privacy and data protection risks.

Question # 211

Which component of an organization ' s cybersecurity risk assessment framework would allow management to implement user controls based on a user ' s role?

A.

Prompt response and remediation policy

B.

Inventory of information assets

C.

Information access management

D.

Standard security configurations

Question # 212

According to IIA guidance, which of the following corporate social responsibility activities is appropriate for the internal audit activity to perform?

A.

Determine the optimal amount of resources for the organization to invest in corporate social responsibility.

B.

Align corporate social responsibility program objectives with the organization ' s strategic plan.

C.

Integrate corporate social responsibility activities into the organization ' s decision-making process.

D.

Determine whether the organization has an appropriate policy governing its corporate social responsibility activities.

Question # 213

Which of the following principles are common to both hierarchical and open organizational structures?

    Employees at all levels should be empowered to make decisions.

    A supervisor ' s span of control should not exceed seven subordinates.

    Responsibility should be accompanied by adequate authority.

    A superior cannot delegate the ultimate responsibility for results.

A.

1 and 2

B.

1 and 4

C.

2 and 3

D.

3 and 4

Question # 214

Which of the following types of data analytics would be used by a hospital to determine which patients are likely to require readmittance for additional treatment?

A.

Predictive analytics

B.

Prescriptive analytics

C.

Descriptive analytics

D.

Diagnostic analytics

Question # 215

Which of the following is true regarding bonds?

A.

Bondholders do not have voting rights but obtain corporate control via interest pay-outs.

B.

Debenture bonds are rarely used by organizations with good credit ratings.

C.

Using bonds involves paying interest on a periodic basis and repaying the principal at the due date.

D.

Debenture bonds have specific assets pledged by the organization as collateral for the bonds.

Question # 216

Which of the following is a benefit from the concept of Internet of Things?

A.

Employees can choose from a variety of devices they want to utilize to privately read work emails without their employer’s knowledge.

B.

Physical devices, such as thermostats and heat pumps, can be set to react to electricity market changes and reduce costs.

C.

Information can be extracted more efficiently from databases and transmitted to relevant applications for in-depth analytics.

D.

Data mining and data collection from internet and social networks is easier, and the results are more comprehensive

Question # 217

Which of the following is required in effective IT change management?

A.

The sole responsibility for change management is assigned to an experienced and competent IT team

B.

Change management follows a consistent process and is done in a controlled environment.

C.

Internal audit participates in the implementation of change management throughout the organisation.

D.

All changes to systems must be approved by the highest level of authority within an organization.

Question # 218

Which of the following best explains why an organization would enter into a capital lease contract?

A.

To increase the ability to borrow additional funds from creditors

B.

To reduce the organization ' s free cash flow from operations

C.

To Improve the organization ' s free cash flow from operations

D.

To acquire the asset at the end of the lease period at a price lower than the fair market value

Question # 219

An organization produces finished lumber for the construction industry.

Which of the following inventory valuation methods will lead to the highest profit, assuming all other variables remain the same in a period of rising material costs?

A.

Average-cost method.

B.

Weighted cost method.

C.

First-in, first-out (FIFO).

D.

Specific identification.

Question # 220

Which of the following purchasing scenarios would gain the greatest benefit from implementing electronic data interchange?

A.

A time-sensitive just-in-time purchase environment.

B.

A large volume of custom purchases.

C.

A variable volume sensitive to material cost.

D.

A currently inefficient purchasing process.

Question # 221

Which of the following is an example of a smart device security control intended to prevent unauthorized users from gaining access to a device’s data or applications?

A.

Anti-malware software

B.

Authentication

C.

Spyware

D.

Rooting

Question # 222

An organization is considering mirroring the customer data for one regional center at another center. A disadvantage of such an arrangement would be:

A.

Lack of awareness of the state of processing.

B.

Increased cost and complexity of network traffic.

C.

Interference of the mirrored data with the original source data.

D.

Confusion about where customer data are stored.

Question # 223

With increased cybersecurity threats, which of the following should management consider to ensure that there is strong security governance in place?

A.

Inventory of information assets

B.

Limited sharing of data files with external parties.

C.

Vulnerability assessment

D.

Clearly defined policies

Question # 224

Which of the following cost of capital methods identifies the time period required to recover She cost of the capital investment from the annual inflow produced?

A.

Cash payback technique

B.

Annual rate of return technique.

C.

Internal rate of return method.

D.

Net present value method.

Question # 225

Which of the following statements is true regarding the resolution of interpersonal conflict?

A.

Unrealized expectations can be avoided with open and honest discussion.

B.

Reorganization would probably not help ambiguous or overlapping jurisdictions.

C.

Deferring action should be used until there is sufficient time to fully deal with the issue.

D.

Timely and unambiguous clarification of roles and responsibilities will eliminate most interpersonal conflict.

Question # 226

Which of the following risks would involve individuals attacking an oil company’s IT system as a sign of solidarity against drilling in a local area?

A.

Tampering

B.

Hacking

C.

Phishing

D.

Piracy

Question # 227

Which observations should the chief audit executive include in the executive summary of the final engagement communication?

A.

All observations

B.

Only observations with an action plan

C.

Only significant observations

D.

Only observations agreed with management

Question # 228

Given the information below, which organization is in the weakest position to pay short-term debts?

Organization A: Current assets constitute $1,200,000; Current liabilities are $400,000

Organization B: Current assets constitute $1,000,000; Current liabilities are $1,000,000

Organization C: Current assets constitute $900,000; Current liabilities are $300,000

Organization D: Current assets constitute $1,000,000; Current liabilities are $250,000

A.

Organization A

B.

Organization B

C.

Organization C

D.

Organization D

Question # 229

Which of the following statements regarding the necessary resources to achieve the internal audit plan is true?

A.

Ultimate oversight and responsibility for the internal audit function can be outsourced

B.

Relying upon the work of other assurance providers decreases the efficiency with which to retain auditors with high knowledge and experience

C.

Internal audit resources can be obtained entirely from outside the organization

D.

Co-sourcing, where experts from outside the organization perform specialized work, must be used by chief audit executives instead of outsourcing

Question # 230

Which of the following strategies is most appropriate for an industry that is in decline?

A.

Invest in marketing.

B.

Invest in research and development.

C.

Control costs.

D.

Shift toward mass production.

Question # 231

One change control function that is required in client/server environments, but is not required in mainframe environments, is to ensure that:

A.

Program versions are synchronized across the network.

B.

Emergency move procedures are documented and followed.

C.

Appropriate users are involved in program change testing.

D.

Movement from the test library to the production library is controlled.

Question # 232

An organization is testing its data recovery plan. The crisis scenario includes disruption to the internet and mobile connections and the need to recover the production management information system from a backup server. Since it is not possible to call a third-party service provider, an employee was sent to receive backup hard drives. However, the office of the service provider was closed, and the organization had to abort testing.

Which of the following has the organization failed to foresee in its recovery plan?

A.

Offline backup retrieval process.

B.

Online backup recovery process.

C.

Mobile connection recovery process.

D.

Onsite backup preservation process.

Question # 233

Which of the following serves as a safeguard to protect the confidentiality of information being transmitted from an internal network to an external network?

A.

A cloud network.

B.

A mobile network.

C.

An intranet.

D.

A virtual private network.

Question # 234

Senior management has decided to implement the Three Lines of Defense model for risk management. Which of the following best describes senior management ' s duties with regard to this model?

A.

Ensure compliance with the model.

B.

Identify management functions.

C.

Identify emerging issues.

D.

Set goals for implementation.

Question # 235

An internal auditor considers the financial statement of an organization as part of a financial assurance engagement. The auditor expresses the organization ' s electricity and depreciation expenses as a percentage of revenue to be 10% and 7% respectively. Which of the following techniques was used by the internal auditor In this calculation?

A.

Horizontal analysis

B.

Vertical analysis

C.

Ratio analysis

D.

Trend analysis

Question # 236

The decision to implement enhanced failure detection and backup systems to improve data integrity is an example of which risk response?

A.

Risk acceptance.

B.

Risk sharing.

C.

Risk avoidance.

D.

Risk reduction.

Question # 237

Import quotas that limit the quantities of goods that a domestic subsidiary can buy from its foreign parent company represent which type of barrier to the parent company?

A.

Political.

B.

Financial.

C.

Social.

D.

Tariff.

IIA-CIA-Part3 PDF

$33

$109.99

3 Months Free Update

  • Printable Format
  • Value of Money
  • 100% Pass Assurance
  • Verified Answers
  • Researched by Industry Experts
  • Based on Real Exams Scenarios
  • 100% Real Questions

IIA-CIA-Part3 PDF + Testing Engine

$52.8

$175.99

3 Months Free Update

  • Exam Name: Internal Audit Function
  • Last Update: Aug 24, 2026
  • Questions and Answers: 791
  • Free Real Questions Demo
  • Recommended by Industry Experts
  • Best Economical Package
  • Immediate Access

IIA-CIA-Part3 Engine

$39.6

$131.99

3 Months Free Update

  • Best Testing Engine
  • One Click installation
  • Recommended by Teachers
  • Easy to use
  • 3 Modes of Learning
  • State of Art Technology
  • 100% Real Questions included