Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium IIA IIA-CIA-Part3 Dumps Questions Answers

Internal Audit Function Questions and Answers

Question 1

Which of the following describes a third-party network that connects an organization specifically with its trading partners?

Options:

A.

Value-added network (VAN).

B.

Local area network (LAN).

C.

Metropolitan area network (MAN).

D.

Wide area network (WAN).

Buy Now
Question 2

An intruder posing as the organization ' s CEO sent an email and tricked payroll staff into providing employees ' private tax information. What type of attack was perpetrated?

Options:

A.

Boundary attack.

B.

Spear phishing attack.

C.

Brute force attack.

D.

Spoofing attack.

Question 3

Which of the following statements is true regarding data backup?

Options:

A.

System backups should always be performed in real-time.

B.

Backups should be stored in a secured location onsite for easy access.

C.

The tape rotation schedule affects how long data is retained.

D.

Backup media should be restored only in case of a hardware or software failure.

Question 4

Which of the following is an element of effective negotiating?

Options:

A.

Ensuring that the other party has a personal stake in the agreement.

B.

Focusing on interests rather than on obtaining a winning position.

C.

Considering a few select choices during the settlement phase.

D.

Basing the agreement on negotiating power and positioning leverage.

Question 5

Which of the following items represents a limitation with an impact the chief audit executive should report to the board?

Options:

A.

Audit procedures

B.

Reporting forms

C.

Available skills

D.

Available methods

Question 6

Which of the following statements is true concerning the basic accounting treatment of a partnership?

Options:

A.

The initial investment of each partner should be recorded at book value.

B.

The ownership ratio identifies the basis for dividing net income and net toss.

C.

A partner ' s capital only changes due to net income or net loss.

D.

The basis for sharing net incomes or net kisses must be fixed.

Question 7

An organization engages in questionable financial reporting practices due to pressure to meet unrealistic performance targets. Which internal control component is most negatively affected?

Options:

A.

Monitoring.

B.

Control activities.

C.

Risk assessment.

D.

Control environment.

Question 8

Internal auditors used a video recorder to document interviews with control executors.

Which form of big data would the verbal answers represent?

Options:

A.

Structured data.

B.

Semi-structured data.

C.

Unstructured data.

D.

Quasi-structured data.

Question 9

An organization decided to invest in new office equipment for $320,000. The estimated useful life of the equipment is four years. The residual value will be $40,000. The depreciation method is straight-line. The new equipment will allow the organization to save $150,000 per year. The estimated tax rate used in the organization is 30 percent. The required rate of return is 15 percent.

The following are present values of $1 during four years for 15 percent:

Year 1 = $0.87

Year 2 = $0.76

Year 3 = $0.66

Year 4 = $0.57

What is net present value of this investment?

Options:

A.

$71,140

B.

$63,160

C.

$40,360

D.

$3,100

Question 10

Which of the following is a product-oriented definition of a business rather than a market-oriented definition of a business?

Options:

A.

We are a people-and-goods mover.

B.

We supply energy.

C.

We make movies.

D.

We provide climate control in the home.

Question 11

An internal auditor is reviewing physical and environmental controls for an IT organization. Which control activity should not be part of this review?

Options:

A.

Develop and test the organization ' s disaster recovery plan.

B.

Install and test fire detection and suppression equipment.

C.

Restrict access to tangible IT resources.

D.

Ensure that at least one developer has access to both systems and operations.

Question 12

The internal auditor concluded there was a high likelihood that a significant wind farm development, worth $200 million, would be delayed from its approved schedule. As a result, electricity production would not start on time, leading to considerable financial penalties. Which of the following should be added to the observation to support its clarity and completeness?

Options:

A.

The effect of the observation

B.

The criteria of the observation

C.

The condition of the observation

D.

The cause of the observation

Question 13

In accounting, which of the following statements is true regarding the terms debit and credit?

Options:

A.

Debit indicates the right side of an account and credit the left side

B.

Debit means an increase in an account and credit means a decrease.

C.

Credit indicates the right side of an account and debit the left side.

D.

Credit means an increase in an account and debit means a decrease

Question 14

The profile of an internal auditor ' s personality traits reveals that the auditor is most motivated by self-actualization needs.

Given this, which of the following is likely to serve as the best motivator for this auditor?

Options:

A.

Rotate the auditor to work within a multi-disciplinary audit team.

B.

Assign the auditor to work on complex and challenging audits.

C.

Reassure the auditor that the internal audit budget is stable and the auditor ' s job is secure.

D.

Offer increased benefits in the auditor ' s compensation package.

Question 15

Management is designing its disaster recovery plan. In the event that there is significant damage to the organization ' s IT systems this plan should enable the organization to resume operations at a recovery site after some configuration and data restoration. Which of the following is the ideal solution for management in this scenario?

Options:

A.

A warm recovery plan.

B.

A cold recovery plan.

C.

A hot recovery plan.

D.

A manual work processes plan

Question 16

At one organization, the specific terms of a contract require both the promisor end promise to sign the contract in the presence of an independent witness.

What is the primary role to the witness to these signatures?

Options:

A.

A witness verifies the quantities of the copies signed.

B.

A witness verifies that the contract was signed with the free consent of the promisor and promise.

C.

A witness ensures the completeness of the contract between the promisor and promise.

D.

A witness validates that the signatures on the contract were signed by tire promisor and promise.

Question 17

Which of the following responsibilities would ordinary fall under the help desk function of an organization?

Options:

A.

Maintenance service items such as production support.

B.

Management of infrastructure services, including network management.

C.

Physical hosting of mainframes and distributed servers

D.

End-to -end security architecture design.

Question 18

Which of the following controls is the most effective in mitigating activities of bots that continuously attempt to access a user’s account?

Options:

A.

Password length.

B.

User session timeout.

C.

User account lockout.

D.

Password aging.

Question 19

What is the primary purpose of data and systems backup?

Options:

A.

To restore all data and systems immediately after the occurrence of an incident.

B.

To set the maximum allowable downtime to restore systems and data after the occurrence of an incident.

C.

To set the point in time to which systems and data must be recovered after the occurrence of an incident.

D.

To restore data and systems to a previous point in time after the occurrence of an incident

Question 20

An internal auditor computed that one of the organization ' s accounting divisions is processing 30 travel reports per hour while another accounting division is processing 22 travel reports per hour. Which of the following efficiency measures did the internal auditor most likely employ?

Options:

A.

Operating rate.

B.

Asset efficiency rate.

C.

Resource utilization rate.

D.

Productivity rate.

Question 21

The manager of the sales department wants to Increase the organization ' s net profit margin by 7% (from 43% in the prior year to 50% in the current year). Given the information provided in the table below, what would be the targeted sales amount for the current year?

Options:

A.

$20,000,000

B.

$24.500.000

C.

$30.000.000

D.

$35.200.000

Question 22

An organization has adopted a bring-your-own-device (BYOD) policy, and employees can access organizational data via their smart devices.

Which of the following authentication policy requirements is the most advisable?

Options:

A.

Require a virtual private network (VPN).

B.

Require at least an eight-digit passcode or a complicated swipe pattern.

C.

Require the remote wipe function and encryption of local data.

D.

Require a passcode followed by a response requiring verification message.

Question 23

A manager has difficulty motivating staff to improve productivity, despite establishing a lucrative individual reward system. Which of the following is most likely the cause of the difficulty?

Options:

A.

High degree of masculinity.

B.

Low uncertainty avoidance.

C.

High collectivism.

D.

Low long-term orientation.

Question 24

A rapidly expanding retail organisation continues to be tightly controlled by its original small management team. Which of the following is a potential risk in this vertically centralized organization?

Options:

A.

Lack of coordination among different business units

B.

Operational decisions are inconsistent with organizational goals

C.

Suboptimal decision making

D.

Duplication of business activities

Question 25

When auditing databases, which of the following risks would an Internal auditor keep In mind In relation to database administrators?

Options:

A.

The risk that database administrators will disagree with temporarily preventing user access to the database for auditing purposes.

B.

The risk that database administrators do not receive new patches from vendors that support database software in a timely fashion.

C.

The risk that database administrators set up personalized accounts for themselves, making the audit time consuming.

D.

The risk that database administrators could make hidden changes using privileged access.

Question 26

An organization that produces backpacks of standard quality is considering manufacturing high-quality packs. Which of the following costs is most relevant when deciding whether to manufacture the new product?

Options:

A.

Fixed costs.

B.

Variable costs.

C.

Conversion costs.

D.

Incremental costs.

Question 27

According to IIA guidance, which of the following would be the best first step to manage risk when a third party is overseeing the organization’s network and data?

Options:

A.

Creating a comprehensive reporting system for vendors to demonstrate their ongoing due diligence in network operations

B.

Drafting a strong contract that requires regular vendor control reports and a right-to-audit clause

C.

Applying administrative privileges to ensure right-to-access controls are appropriate

D.

Creating a standing cybersecurity committee to identify and manage risks related to data security

Question 28

Which of the following is true regarding bonds?

Options:

A.

Bondholders do not have voting rights but obtain corporate control via interest pay-outs.

B.

Debenture bonds are rarely used by organizations with good credit ratings.

C.

Using bonds involves paying interest on a periodic basis and repaying the principal at the due date.

D.

Debenture bonds have specific assets pledged by the organization as collateral for the bonds.

Question 29

An organization was forced to stop production unexpectedly, as raw materials could not be delivered due to a military conflict in the region. Which of the following plans have most likely failed to support the organization?

Options:

A.

Just-in-time delivery plans.

B.

Backup plans.

C.

Contingency plans.

D.

Standing plans.

Question 30

An internal auditor discovered that the organization was not in full compliance with a regulatory labeling requirement for one of its products. The responsible manager indicated that the current product labeling has been in use for several years without any problems. If discovered, this regulatory breach could result in significant fines for the organization. What should be the chief audit executive ' s next course of action?

Options:

A.

Discuss the matter with the CEO and other senior management

B.

Recommend that disciplinary action be taken against the manager for exposing the company to such risk

C.

Communicate to the board the current situation, including the risk exposure to the company

D.

Take on the initiative of implementing corrective actions to mitigate the identified risks

Question 31

Which of the following is an example of a phishing attack?

Options:

A.

An organization’s website becomes flooded with malicious traffic on the first day of the online shopping season, causing the website to crash and preventing customers from purchasing deals online

B.

The employees of a retail organization responded to emails with a link to malware that enabled a hacker to access the point-of-sale system and obtain customers’ credit card information

C.

An organization’s employees clicked on a link that allowed a worm to infiltrate and encrypt the organization’s operating system, rendering it unusable. A group of hackers is demanding payment to unlock the encryption

D.

A group of online activists hacked into the private email and confidential records of the local police department and released the information online to expose the corrupt practices of the department

Question 32

Which of the following assessments will assist in evaluating whether the internal audit function is consistently delivering quality engagements?

Options:

A.

Periodic assessments

B.

Ongoing monitoring

C.

Full external assessments

D.

Self-Assessment with Independent Validation (SAIV)

Question 33

An internal auditor has completed the fieldwork of an assurance engagement on the organization ' s business continuity. The most significant finding is that business requirements were left up to the IT function to decide and implement. As a result, the time to recovery for some critical systems following a disruption is too long, while recovery time of non-critical systems is needlessly prioritized at a significant cost. Which of the following is the most appropriate recommendation to include in the engagement report?

Options:

A.

Management of business units should review and correct the recovery targets

B.

Conduct an IT function review and correct the recovery targets

C.

Management of the IT function should ensure that the business continuity plan is more realistic

D.

Ensure that in the future business requirements are set by the management of business units

Question 34

What kind of strategy would be most effective for an organization to adopt in order to implement a unique advertising campaign for selling identical products across all of its markets?

Options:

A.

Export strategy.

B.

Transnational strategy.

C.

Multi-domestic strategy.

D.

Globalization strategy.

Question 35

The finance department of an organization recently undertook an asset verification exercise. The internal audit function scheduled a review of the IT department’s operations, which includes verifying the existence of computers distributed and their assignment. Can the internal audit function consider relying on the asset verification work performed by the finance department?

Options:

A.

Yes, in order to be efficient and make better use of internal audit resources

B.

No, as the finance department is an internal department of the organization

C.

Yes, but the finance manager would be responsible for supporting the conclusions of the work

D.

No, the internal audit function should do its own verification and should not rely on the work of finance

Question 36

Which of the following best describes the job design strategy used by the chief audit executive that encourages internal auditors to manage engagements from the beginning to the end?

Options:

A.

Job sharing.

B.

Job shadowing.

C.

Job enrichment.

D.

Job rotation.

Question 37

An organization uses the management-by-objectives method whereby employee performance is based on defined goals. Which of the following statements is true regarding this approach?

Options:

A.

It is particularly helpful to management when the organization is facing rapid change.

B.

It is a more successful approach when adopted by mechanistic organizations.

C.

It is mere successful when goal setting is performed not only by management, but by all team members, including lower-level staff.

D.

It is particularly successful in environments that are prone to having poor employer-employee relations.

Question 38

Which of the following describes a mechanistic organizational structure?

Options:

A.

Primary direction of communication tends to be lateral.

B.

Definition of assigned tasks tends to be broad and general.

C.

Type of knowledge required tends to be broad and professional.

D.

Reliance on self-control tends to be low.

Question 39

Which of the following authentication controls combines what a user knows with the unique characteristics of the user, respectively?

Options:

A.

Voice recognition and token

B.

Password and fingerprint

C.

Fingerprint and voice recognition

D.

Password and token

Question 40

An organization that relies heavily on IT wants to contain the impact of potential business disruption to a period of approximately four to seven days. Which of the following

business recovery strategies would most efficiently meet this organization ' s needs?

Options:

A.

A recovery strategy whereby a separate site has not yet been determined, but hardware has been reserved for purchase and data backups.

B.

A recovery strategy whereby a separate site has been secured and is ready for use, with fully configured hardware and real-time synchronized data

C.

A recovery strategy whereby a separate site has been secured and the necessary funds for hardware and data backups have been reserved.

D.

A recovery strategy whereby a separate site has been secured with configurable hardware and data backups.

Question 41

Which of the following scenarios best illustrates a spear phishing attack?

Options:

A.

Numerous and consistent attacks on the company ' s website caused the server to crash and service was disrupted.

B.

A person posing as a representative of the company ' s IT help desk called several employees and played a generic prerecorded message requesting password data.

C.

A person received a personalized email regarding a golf membership renewal, and he clicked a hyperlink to enter his credit card data into a fake website.

D.

Many users of a social network service received fake notifications of a unique opportunity to invest in a new product

Question 42

A new manager received computations of the internal rate of return regarding his project proposal. What should the manager compare the computation results to in order to determine whether the project is potentially acceptable?

Options:

A.

Compare to the annual cost of capital.

B.

Compare to the annual interest rate.

C.

Compare to the required rate of return.

D.

Compare to the net present value.

Question 43

Which of the following management statements illustrates how natural bias can lead to poor decision making?

Options:

A.

" Although we previously agreed that we would launch a new product this year, we changed our minds and decided to terminate the launch. "

B.

" Due to the crisis that arose last week, we are not prepared to provide the board with an estimate of next year ' s revenue. "

C.

" We will continue manufacturing the same products in the same way that we always have, because this tradition has made our organization successful. "

D.

" We decided to postpone expanding into the new market because of high uncertainty at this time. "

Question 44

An organization ' s account for office supplies on hand had a balance of $9,000 at the end of year one. During year two. The organization recorded an expense of $45,000 for purchasing office supplies. At the end of year two. a physical count determined that the organization has $11 ,500 in office supplies on hand. Based on this Information, what would he recorded in the adjusting entry an the end of year two?

Options:

A.

A debit to office supplies on hand for S2.500

B.

A debit to office supplies on hand for $11.500

C.

A debit to office supplies on hand for $20,500

D.

A debit to office supplies on hand for $42,500

Question 45

Which of the following is true of matrix organizations?

Options:

A.

A unity-of-command concept requires employees to report technically, functionally, and administratively to the same manager.

B.

A combination of product and functional departments allows management to utilize personnel from various functions.

C.

Authority, responsibility, and accountability of the units involved may vary based on the project ' s life or the organization ' s culture.

D.

It is best suited for firms with scattered locations or for multi-line, large-scale firms.

Question 46

A chief audit executive (CAE) is developing a strategic plan for the internal audit function. In the last two years, the organization has faced significant IT risks, but the internal audit function has not been able to audit those areas due to a lack of knowledge. How could the CAE address this in the strategic plan?

Options:

A.

Purchase a data analytics program for the internal audit function

B.

Hold listening sessions to receive management ' s input on the strategic plan

C.

Develop a succession plan for the internal audit function to avoid staffing deficiencies

D.

Identify relevant training resources to strengthen staff skillsets

Question 47

A new chief audit executive (CAE) reviews long overdue audit recommendations, which have been repeatedly reported to senior management but have not been implemented, and is unsure which issues should be escalated to the board. Which of the following would serve as the best guide in this scenario?

Options:

A.

The CAE ' s personal judgment

B.

The organization ' s code of conduct

C.

The organization ' s risk acceptance policy

D.

The organization ' s internal audit charter

Question 48

When applied to international economics, the theory of comparative advantage proposes that total worldwide output will be greatest when:

Options:

A.

Each nation ' s total imports approximately equal its total exports.

B.

Each good is produced by the nation that has the lowest opportunity cost for that good.

C.

Goods that contribute to a nation ' s balance-of-payments deficit are no longer imported.

D.

International trade is unrestricted and tariffs are not imposed.

Question 49

Which of the following concepts of managerial accounting is focused on achieving a point of low or no inventory?

Options:

A.

Theory of constraints.

B.

Just-in-time method.

C.

Activity-based costing.

D.

Break-even analysis

Question 50

Which of the following should software auditors do when reporting internal audit findings related to enterprisewide resource planning?

Options:

A.

Draft separate audit reports for business and IT management.

B.

Conned IT audit findings to business issues.

C.

Include technical details to support IT issues.

D.

Include an opinion on financial reporting accuracy and completeness.

Question 51

The chief audit executive (CAE) identified an unacceptable risk and believes that the risk is not being mitigated to an acceptable level. Which of the following is the CAE ' s next step in this situation?

Options:

A.

Escalate the concern to senior management

B.

Send a letter to responsible management and provide a deadline to accept the risk

C.

Escalate the concern to the board

D.

Discuss the issue with the members of responsible management

Question 52

An organization with global headquarters in the United States has subsidiaries in eight other nations. If the organization operates with an ethnocentric attitude, which of the following statements is true?

Options:

A.

Standards used for evaluation and control are determined at local subsidiaries, not set by headquarters.

B.

Orders, commands, and advice are sent to the subsidiaries from headquarters.

C.

Poop o of local nationality are developed for the best positions within their own country.

D.

There is a significant amount of collaboration between headquarters and subs diaries.

Question 53

According to IIA guidance on IT, which of the following plans would pair the identification of critical business processes with recovery time objectives?

Options:

A.

The business continuity management charter

B.

The business continuity risk assessment plan

C.

The business impact analysis plan

D.

The business case for business continuity planning

Question 54

Which of the following are likely indicators of ineffective change management?

    IT management is unable to predict how a change will impact interdependent systems or business processes.

    There have been significant increases in trouble calls or in support hours logged by programmers.

    There is a lack of turnover in the systems support and business analyst development groups.

    Emergency changes that bypass the normal control process frequently are deemed necessary.

Options:

A.

1 and 3 only

B.

2 and 4 only

C.

1, 2, and 4 only

D.

1, 2, 3, and 4

Question 55

An internal auditor has finalized an engagement of the vendor master file. The results of the current engagement do not differ significantly from that of last year, in which several significant weaknesses in internal controls were reported. The internal auditor states in the final communication that the internal controls are as effective as that of the previous year. Which of the following elements of quality of communication could be improved?

Options:

A.

Conciseness

B.

Constructiveness

C.

Objectivity

D.

Accuracy

Question 56

An organization had a gross profit margin of 40 percent in year one and in year two. The net profit margin was 18 percent in year one and 13 percent in year two. Which of the following could be the reason for the decline in the net profit margin for year two?

Options:

A.

Cost of sales increased relative to sales.

B.

Total sales increased relative to expenses.

C.

The organization had a higher dividend payout rate in year two.

D.

The government increased the corporate tax rate

Question 57

An employee ' s mobile device used for work was stolen in a home burglary. Which control, if already implemented by the organization, would best prevent unauthorized access to organizational data stored on the employee ' s device?

Options:

A.

Access control via biometric authentication.

B.

Access control via passcode authentication.

C.

Access control via swipe pattern authentication.

D.

Access control via security question authentication.

Question 58

What would be the most relevant risk related to a bring-your-own-device policy?

Options:

A.

Data leakage due to the devices having access to the network.

B.

Lack of understanding of the technology and concept of the tool.

C.

Missing noncurrent assets capitalization.

D.

Financial losses due to smart device theft.

Question 59

An organization ' s internal audit activity is performing an audit of human resources. As part of the audit a survey of employees was conducted. The survey indicated that employees were concerned about IT security when working outside of the office. The IT department suggested implementing a network that allows employees to send and receive data as if they were connected to a private network.

Which of the following networks is IT recommending?

Options:

A.

Global area network (GAN).

B.

Wide area network (WAN).

C.

Virtual private network (VPN).

D.

Local area network (LAN).

Question 60

Which of the following is most appropriately placed in the financing section of an organization ' s cash budget?

Options:

A.

Collections from customers

B.

Sale of securities.

C.

Purchase of trucks.

D.

Payment of debt, including interest

Question 61

An internal auditor discovered that several unauthorized modifications were made to the production version of an organization ' s accounting application. Which of the following best describes this deficiency?

Options:

A.

Production controls weakness.

B.

Application controls weakness.

C.

Authorization controls weakness.

D.

Change controls weakness.

Question 62

Which of the following statements is true regarding the use of public key encryption to secure data while it is being transmitted across a network?

Options:

A.

Both the key used to encrypt the data and the key used to decrypt the data are made public.

B.

The key used to encrypt the data is kept private but the key used to decrypt the data is made public.

C.

The key used to encrypt the data is made public but the key used to decrypt the data is kept private.

D.

Both the key used to encrypt the data and the key used to decrypt the data are made private.

Question 63

According to IIA guidance, which of the following statements is true regarding penetration testing?

Options:

A.

Testing should not be announced to anyone within the organization to solicit a real-life response.

B.

Testing should take place during heavy operational time periods to test system resilience.

C.

Testing should be wide in scope and primarily address detective management controls for identifying potential attacks.

D.

Testing should address the preventive controls and management ' s response.

Question 64

Which of the following functions of access control systems involves keeping logs of a user ' s activity in a system?

Options:

A.

Identification.

B.

Authentication.

C.

Authorization.

D.

Accountability.

Question 65

Which of the following is the starting point for a chief audit executive to prioritize engagements to be included in the internal audit plan?

Options:

A.

A risk management maturity model

B.

A risk matrix

C.

An annual assurance map

D.

An internal control framework

Question 66

A chief audit executive (CAE) joined an organization in the middle of the financial year. A risk-based annual audit plan has been approved by the board and is already underway. However, after discussions with key stakeholders, the CAE realizes that some significant key risk areas have not been covered in the original audit plan. How should the CAE respond?

Options:

A.

Commit to delivering the original annual audit plan as it has already been approved by the board

B.

Revise the plan to incorporate the newly identified risks, and communicate significant interim changes to senior management and the board for review and approval

C.

Ensure that the newly identified risks are included in the next year ' s annual audit plan

D.

Assign internal auditors to immediately perform assurance engagements in the areas where the new risks have been identified, due to their significance

Question 67

During a payroll audit, the internal auditor is assessing the security of the local area network of the payroll department computers. Which of the following IT controls should the auditor test?

Options:

A.

IT application-based controls

B.

IT systems development controls

C.

Environmental controls

D.

IT governance controls

Question 68

At one organization, the specific terms of a contract require both the promisor and promisee to sign the contract in the presence of an independent witness. What is the primary role to the witness to these signatures?

Options:

A.

A witness verifies the quantities of the copies signed.

B.

A witness verifies that the contract was signed with the free consent of the promisor and promisee.

C.

A witness ensures the completeness of the contract between the promisor and promisee.

D.

A witness validates that the signatures on the contract were signed by the promisor and promisee.

Question 69

Which of the following controls is the most effective for ensuring confidentially of transmitted information?

Options:

A.

Firewall.

B.

Antivirus software.

C.

Passwords.

D.

Encryption.

Question 70

An internal auditor was assigned to test for ghost employees using data analytics. The auditor extracted employee data from human resources and payroll. Using spreadsheet functions, the auditor matched data sets by name and assumed that employees who were not present in each data set should be investigated further. However, the results seemed erroneous, as very few employees matched across all data sets. Which of the following data analytics steps has the auditor most likely omitted?

Options:

A.

Data analysis.

B.

Data diagnostics.

C.

Data velocity.

D.

Data normalization.

Question 71

Which of the following is true regarding the use of remote wipe for smart devices?

Options:

A.

It can restore default settings and lock encrypted data when necessary.

B.

It enables the erasure and reformatting of secure digital (SD) cards.

C.

It can delete data backed up to a desktop for complete protection if required.

D.

It can wipe data that is backed up via cloud computing

Question 72

Which of the following is a typical activity performed by the help desk?

Options:

A.

Monitoring the network

B.

Troubleshooting

C.

Backing up data

D.

Assigning authorizations to a user, a role, or profile

Question 73

The chief audit executive (CAE) has embraced a total quality management approach to improving the internal audit activity ' s (lAArs) processes. He would like to reduce the time to complete audits and improve client ratings of the IAA. Which of the following staffing approaches is the CAE most likely lo select?

Options:

A.

Assign a team with a trained audit manager to plan each audit and distribute field work tasks to various staff auditors.

B.

Assign a team of personnel who have different specialties to each audit and empower Team members to participate fully in key decisions

C.

Assign a team to each audit, designate a single person to be responsible for each phase of the audit, and limit decision making outside of their area of responsibility.

D.

Assign a team of personnel who have similar specialties to specific engagements that would benefit from those specialties and limit Key decisions to the senior person.

Question 74

A significant project is nearing its development stage end, and line management intends to apply for a final investment decision from senior management at an upcoming meeting. The internal audit function is at the fieldwork stage of an assurance engagement related to this project and discovers that tenders conducted for the project were not carried out transparently by line management. The audit report will not be ready by the upcoming senior management meeting. Which of the following actions is the most appropriate next step for the chief audit executive?

Options:

A.

Escalate the issue to the chief risk officer

B.

Raise the issue with senior management

C.

Continue with the assurance engagement as planned

D.

Place the assurance engagement on hold due to inappropriate timing

Question 75

Which of the following is an example of internal auditors applying data mining techniques for exploratory purposes?

Options:

A.

Internal auditors perform reconciliation procedures to support an external audit of financial reporting.

B.

Internal auditors perform a systems-focused analysis to review relevant controls.

C.

Internal auditors perform a risk assessment to identify potential audit subjects as input for the annual internal audit plan

D.

Internal auditors test IT general controls with regard to operating effectiveness versus design

Question 76

International marketing activities often begin with:

Options:

A.

Standardization.

B.

Global marketing.

C.

Limited exporting.

D.

Domestic marketing.

Question 77

Given the information below, which organization is in the weakest position to pay short-term debts?

Organization A: Current assets constitute $1,200,000; Current liabilities are $400,000

Organization B: Current assets constitute $1,000,000; Current liabilities are $1,000,000

Organization C: Current assets constitute $900,000; Current liabilities are $300,000

Organization D: Current assets constitute $1,000,000; Current liabilities are $250,000

Options:

A.

Organization A

B.

Organization B

C.

Organization C

D.

Organization D

Question 78

Which of the following is required in effective IT change management?

Options:

A.

The sole responsibility for change management is assigned to an experienced and competent IT team

B.

Change management follows a consistent process and is done in a controlled environment.

C.

Internal audit participates in the implementation of change management throughout the organisation.

D.

All changes to systems must be approved by the highest level of authority within an organization.

Question 79

Which of the following would best prevent unauthorized external changes to an organization ' s data?

Options:

A.

Antivirus software, firewall, data encryption.

B.

Firewall, data encryption, backup procedures.

C.

Antivirus software, firewall, backup procedures.

D.

Antivirus software, data encryption, change logs.

Question 80

When writing a business memorandum, the writer should choose a writing style that achieves all of the following except:

Options:

A.

Draws positive attention to the writing style.

B.

Treats all receivers with respect.

C.

Suits the method of presentation and delivery.

D.

Develops ideas without overstatement.

Question 81

Which of the following best describes the chief audit executive ' s responsibility for assessing the organization ' s residual risk?

Options:

A.

Create an action plan to mitigate the risk

B.

Incorporate management acceptance of risk in the workpapers as internal audit evidence

C.

Report deviations immediately to the board

D.

Communicate the matter with senior management

Question 82

What must be monitored in order to manage the risk of consumer product inventory obsolescence?

    Inventory balances.

    Market share forecasts.

    Sales returns.

    Sales trends.

Options:

A.

1 only

B.

4 only

C.

1 and 4 only

D.

1, 2, and 3 only

Question 83

Which of the following Issues would be a major concern for internal auditors when using a free software to analyze a third-party vendor ' s big data?

Options:

A.

The ability to use the software with ease to perform the data analysis to meet the engagement objectives.

B.

The ability to purchase upgraded features of the software that allow for more In-depth analysis of the big data.

C.

The ability to ensure that big data entered into the software is secure from potential compromises or loss.

D.

The ability to download the software onto the appropriate computers for use in analyzing the big data.

Question 84

Which of the following analytical techniques would an internal auditor use to verify that none of an organization ' s employees are receiving fraudulent invoice payments?

Options:

A.

Perform gap testing.

B.

Join different data sources.

C.

Perform duplicate testing.

D.

Calculate statistical parameters.

Question 85

Which of the following dimensions relates to the quality of big data?

Options:

A.

Veracity.

B.

Validity.

C.

Value.

D.

Variety.

Question 86

A line on a spreadsheet includes an employee ' s name, date of hire, job title, and monthly salary. Which of the following correctly describes this line information?

Options:

A.

Field.

B.

File.

C.

Record.

D.

Database.

Question 87

Which of the following characteristics applies to an organization that adopts a flat structure?

Options:

A.

The structure is dispersed geographically

B.

The hierarchy levels are more numerous.

C.

The span of control is wide

D.

The tower-level managers are encouraged to exercise creativity when solving problems

Question 88

A holding company set up a centralized group technology department, using a local area network with a mainframe computer to process accounting information for all companies within the group. An internal auditor would expect to find all of the following controls within the technology department except:

Options:

A.

Adequate segregation of duties between data processing controls and file security controls.

B.

Documented procedures for remote job entry and for local data file retention.

C.

Emergency and disaster recovery procedures and maintenance agreements in place to ensure continuity of operations.

D.

Established procedures to prevent and detect unauthorized changes to data files.

Question 89

Which of the following steps should an internal auditor take during an audit of an organization ' s business continuity plans?

    Evaluate the business continuity plans for adequacy and currency.

    Prepare a business impact analysis regarding the loss of critical business.

    Identify key personnel who will be required to implement the plans.

    Identify and prioritize the resources required to support critical business processes.

Options:

A.

1 only

B.

2 and 4 only

C.

1, 3, and 4 only

D.

1, 2, 3, and 4

Question 90

Which of the following authentication device credentials is the most difficult to revoke when an employee ' s access rights need to be removed?

Options:

A.

A traditional key lock.

B.

A biometric device.

C.

A card-key system.

D.

A proximity device.

Question 91

In mergers and acquisitions, which of the following is an example of a horizontal combination?

Options:

A.

Dairy manufacturing company taking over a large dairy farm.

B.

A movie producer acquires movie theaters.

C.

A petroleum processing company acquires an agro-processing firm.

D.

A baker taking over a competitor.

Question 92

Which stage in the industry life cycle is characterized by many different product variations?

Options:

A.

Introduction.

B.

Growth.

C.

Maturity.

D.

Decline.

Question 93

Which of the following bring-your-own-device (BYOD) practices is likely to increase the risk of infringement on local regulations, such as copyright or privacy laws?

Options:

A.

Not installing anti-malware software.

B.

Updating operating software in a haphazard manner.

C.

Applying a weak password for access to a mobile device.

D.

Jailbreaking a locked smart device.

Question 94

Which of the following physical access controls often functions as both a preventive and detective control?

Options:

A.

Locked doors.

B.

Firewalls.

C.

Surveillance cameras.

D.

Login IDs and passwords.

Question 95

According to Herzberg ' s Two-Factor Theory of Motivation, which of the following factors arc mentioned most often by satisfied employees?

Options:

A.

Salary and status

B.

Responsibility and advancement

C.

Work conditions and security

D.

Peer relationships and personal life

Question 96

Which of the following physical access controls is most likely to be based on the " something you have " concept?

Options:

A.

A retina characteristics reader.

B.

A PIN code reader.

C.

A card-key scanner.

D.

A fingerprint scanner.

Question 97

An organization is planning to outsource its payroll function to an external service provider. The internal auditors advised management of the risks related to outsourcing and the typical controls that should be provided by the external service provider.

Which of the following statements is true regarding the internal auditors’ advice?

Options:

A.

Independence was compromised by recommending internal controls, as the internal auditors will be testing the same controls in the future.

B.

Objectivity was compromised by intervening before the outsourcing procedures and controls were established.

C.

The internal auditors should work directly with the external service provider to ensure basic controls are in place and working as intended.

D.

The external service provider controls recommended by the internal auditors may be insufficient to protect the organization.

Question 98

According to the waterfall cycle approach to systems development, which of the following sequence of events is correct?

Options:

A.

Program design, system requirements, software design, analysis, coding, testing, operations.

B.

System requirements, software design, analysis, program design, testing, coding, operations.

C.

System requirements, software design, analysis, program design, coding, testing, operations.

D.

System requirements, analysis, coding, software design, program design, testing, operations.

Question 99

A organization finalized a contract in which a vendor is expected to design, procure, and construct a power substation for $3,000,000. In this scenario, the organization agreed to which of the following types of contracts?

Options:

A.

A cost-reimbursable contract.

B.

A lump-sum contract.

C.

A time and material contract.

D.

A bilateral contract.

Question 100

Data analysis indicates that a hospital pharmacy disbursed higher levels of controlled drugs than similar pharmacies in the area. The hospital ' s internal auditor discusses the risk with the head of the hospital pharmacy, who believes that the risk is appropriately mitigated by controls and feels comfortable with the number of prescriptions written.

What should the auditor do next?

Options:

A.

Document that the head of the pharmacy has accepted the risk and believes it is sufficiently mitigated, and conclude the risk assessment.

B.

Request that an independent third party re-perform the data analysis to verify the accuracy of the initial findings.

C.

Investigate the risk by requesting pharmacy policies, procedures, and detailed reports.

D.

Add an audit of the hospital pharmacy to the annual audit plan to fully investigate the risk later in the year.

Question 101

For a multinational organization, which of the following is a disadvantage of an ethnocentric staffing policy?

    It significantly raises compensation and staffing costs.

    It produces resentment among the organization ' s employees in host countries.

    It limits career mobility for parent-country nationals.

    It can lead to cultural myopia.

Options:

A.

1 and 4 only

B.

2 and 3 only

C.

1, 2, and 3 only

D.

1, 2, and 4 only

Question 102

Which of the following is the most appropriate way to record each partner’s initial investment in a partnership?

Options:

A.

At the value agreed upon by the partners

B.

At book value

C.

At fair value

D.

At the original cost

Question 103

Which of the following is an indicator of liquidity that is more dependable than working capital?

Options:

A.

Acid-test (quick) ratio

B.

Average collection period

C.

Current ratio.

D.

Inventory turnover.

Question 104

Which of the following IT strategies is most effective for responding to competitive pressures created by the marketplace?

Options:

A.

Promote closer linkage between organizational strategy and information.

B.

Provide users with greater online access to information systems.

C.

Enhance the functionality of application systems.

D.

Expand the use of automated controls.

Question 105

Which of the following can be viewed as a potential benefit of an enterprisewide resource planning system?

Options:

A.

Real-time processing of transactions and elimination of data redundancies.

B.

Fewer data processing errors and more efficient data exchange with trading partners.

C.

Exploitation of opportunities and mitigation of risks associated with e-business.

D.

Integration of business processes into multiple operating environments and databases.

Question 106

A newly hired chief audit executive (CAE) reviews and will revise the existing internal audit strategy. What should the CAE initially refer to when revising the internal audit strategy?

Options:

A.

Legal and regulatory requirements

B.

Organization-wide risk assessment results

C.

Key internal control activities

D.

Organizational business objectives

Question 107

An internal audit function has commenced its annual follow-up activity. An internal auditor has been assigned to verify whether the recommendations from an audit engagement completed three months ago were implemented by the business unit. The auditor had not participated in that audit engagement. What should the auditor do first?

Options:

A.

Conduct interviews with senior management of the business unit

B.

Request information from the business unit regarding the corrective actions taken

C.

Review the previous audit findings and management ' s response

D.

Conduct a walkthrough of the business unit

Question 108

When granting third parties temporary access to an entity ' s computer systems, which of the following is the most effective control?

Options:

A.

Access is approved by the supervising manager.

B.

User accounts specify expiration dates and are based on services provided.

C.

Administrator access is provided for a limited period.

D.

User accounts are deleted when the work is completed.

Question 109

Which of the following is a characteristic of big data?

Options:

A.

Big data is being generated slowly due to volume.

B.

Big data must be relevant for the purposes of organizations.

C.

Big data comes from a single type of formal.

D.

Big data is always changing

Question 110

As part of internal audit ' s risk assessment, a chief audit executive is determining certain factors as part of planning the areas to audit within an organization that makes silicon chips. Which of the following would be considered a subjective factor as part of the risk assessment?

Options:

A.

The number of vendors able to meet the supply demand request from the organization

B.

The quality of the staff supervision of silicon chips produced by the organization

C.

The length of time since the last audit of the organization ' s manufacturing facilities

D.

The asset value of the silicon chips that the organization did not produce because of a shortage in raw materials

Question 111

An organization and its trading partner rely on a computer-to-computer exchange of digital business documents. Which of the following best describes this scenario?

Options:

A.

Use of a central processing unit

B.

Use of a database management system

C.

Use of a local area network

D.

Use of electronic data Interchange

Question 112

The IT department maintains logs of user identification and authentication for all requests for access to the network. What is the primary purpose of these logs?

Options:

A.

To ensure proper segregation of duties

B.

To create a master repository of user passwords

C.

To enable monitoring for systems efficiencies

D.

To enable tracking of privileges granted to users over time

Question 113

Which of the following best describes owner ' s equity?

Options:

A.

Assets minus liabilities.

B.

Total assets.

C.

Total liabilities.

D.

Owners contribution plus drawings.

Question 114

According to IIA guidance, which of the following statements is true regarding analytical procedures?

Options:

A.

Data relationships are assumed to exist and to continue where no known conflicting conditions exist.

B.

Analytical procedures are intended primarily to ensure the accuracy of the information being examined.

C.

Data relationships cannot include comparisons between operational and statistical data

D.

Analytical procedures can be used to identify unexpected differences, but cannot be used to identify the absence of differences

Question 115

The chief audit executive hired a consultant to update the internal audit function’s methodologies. Which of the following would best ensure that the internal audit function will adhere to the updated methodologies?

Options:

A.

Placing the updated methodologies in an easily accessible location for reference

B.

Requiring a signed acknowledgment that each auditor will comply with the updated methodologies

C.

Preparing a recorded training that reviews the updated methodologies

D.

Sharing a one-page summary of the updated methodologies during an internal audit function meeting

Question 116

Which of the following factors would reduce dissatisfaction for a management trainee but would not particularly motivate the trainee?

Options:

A.

A sense of achievement.

B.

Promotion.

C.

Recognition.

D.

An incremental increase in salary.

Question 117

Which of the following differentiates a physical access control from a logical access control?

Options:

A.

Physical access controls secure tangible IT resources, whereas logical access controls secure software and data internal to the IT system.

B.

Physical access controls secure software and data internal to the IT system, whereas logical access controls secure tangible IT resources.

C.

Physical access controls include firewalls, user IDs, and passwords, whereas logical access controls include locks and security guards.

D.

Physical access controls include input processing and output controls, whereas logical access controls include locked doors and security guards.

Question 118

Which of the following best describes the type of control provided by a firewall?

Options:

A.

Corrective

B.

Detective

C.

Preventive

D.

Discretionary

Question 119

Which of the following responsibilities would ordinarily fall under the help desk function of an organization?

Options:

A.

Maintenance service items such as production support

B.

Management of infrastructure services, including network management

C.

Physical hosting of mainframes and distributed servers

D.

End-to-end security architecture design

Question 120

The comparable uncontrolled price (CUP) method may be used when setting transfer prices in an organization.

What is a common limitation of the CUP method?

Options:

A.

It may be difficult to find a transaction between independent companies that is similar enough to a controlled transaction.

B.

The CUP method is likely to lead to management decisions that are not optimal for the company.

C.

This approach to setting transfer prices is not flexible, as the CUP method does not allow for adjustments.

D.

It offers only an indirect way of ascertaining an arm’s-length price of a controlled transaction.

Question 121

The engagement supervisor prepares the final engagement communication for dissemination. Since the chief audit executive (CAE) is on leave, the supervisor is delegated to disseminate the final engagement communication to all relevant parties. Who should be accountable for the final engagement communication?

Options:

A.

Engagement supervisor

B.

Chief audit executive

C.

The board

D.

The internal audit team

Question 122

Which of the following statements is true regarding the capital budgeting procedure known as the discounted payback period?

Options:

A.

It calculates the overall value of a project.

B.

It ignores the time value of money.

C.

It calculates the time a project takes to break even.

D.

It begins at time zero for the project.

Question 123

An organization has instituted a bring-your-own-device (BYOD) work environment. Which of the following policies best addresses the increased risk to the organization’s network incurred by this environment?

Options:

A.

Limit the use of the employee devices for personal use to mitigate the risk of exposure to organizational data

B.

Ensure that relevant access to key applications is strictly controlled through an approval and review process

C.

Institute detection and authentication controls for all devices used for network connectivity and data storage

D.

Use management software to scan and then prompt patch reminders when devices connect to the network

Question 124

Which type of bond sells at & discount from face value, then increases in value annually until it reaches maturity and provides the owner with the total payoff?

Options:

A.

High-yield bonds

B.

Commodity-backed bonds

C.

Zero coupon bonds

D.

Junk bonds

Question 125

During the process of setting the annual audit plan, the chief audit executive receives a request from senior management to conduct an assurance engagement on the cybersecurity controls of the organization. Which of the following is a reason cybersecurity should be included in the annual internal audit plan?

Options:

A.

In order to maintain good relationships with senior management

B.

Cybersecurity is a new area for auditors to learn

C.

Cybersecurity has been identified as a high risk during the annual risk assessment

D.

The Global Internal Audit Standards require that all management-requested engagements be included in the annual internal audit plan

Question 126

Which of the following is the most appropriate beginning step of a work program for an assurance engagement involving smart devices?

Options:

A.

Train all employees on bring-your-own-device (BYOD) policies.

B.

Understand what procedures are in place for locking lost devices

C.

Obtain a list of all smart devices in use

D.

Test encryption of all smart devices

Question 127

Which of these instances accurately describes the responsibilities for big data governance?

Options:

A.

Management must ensure information storage systems are appropriately defined and processes to update critical data elements are clear.

B.

External auditors must ensure that analytical models are periodically monitored and maintained.

C.

The board must implement controls around data quality dimensions to ensure that they are effective.

D.

Internal auditors must ensure the quality and security of data, with a heightened focus on the riskiest data elements.

Question 128

According to IIA guidance, which of the following is a typical risk associated with the tender process and contracting stage of an organization ' s IT outsourcing life cycle?

Options:

A.

The process is not sustained and is not optimized as planned.

B.

There is a lack of alignment to organizational strategies.

C.

The operational quality is less than projected.

D.

There is increased potential for loss of assets.

Question 129

Which of the following is a characteristic of an emerging industry?

Options:

A.

Established strategy of players.

B.

Low number of new firms.

C.

High unit costs.

D.

Technical expertise.

Question 130

According to IIA guidance, which of the following steps are most important for an internal auditor to perform when evaluating an organization ' s social and environmental impact on the local community?

    Determine whether previous incidents have been reported, managed, and resolved.

    Determine whether a business contingency plan exists.

    Determine the extent of transparency in reporting.

    Determine whether a cost/benefit analysis was performed for all related projects.

Options:

A.

1 and 3.

B.

1 and 4.

C.

2 and 3.

D.

2 and 4.

Question 131

The activity that involves a trial run of a product in a typical segment of the market before proceeding to a national launch is referred to as:

Options:

A.

Test marketing

B.

Experimentation

C.

Segmentation

D.

Positioning

Question 132

Which of the following principles are common to both hierarchical and open organizational structures?

    Employees at all levels should be empowered to make decisions.

    A supervisor ' s span of control should not exceed seven subordinates.

    Responsibility should be accompanied by adequate authority.

    A superior cannot delegate the ultimate responsibility for results.

Options:

A.

1 and 2

B.

1 and 4

C.

2 and 3

D.

3 and 4

Question 133

Which of the following best describes the concept of relevant cost?

Options:

A.

A future cost that is the same among alternatives.

B.

A future cost that differs among alternatives.

C.

A past cost that is the same among alternatives.

D.

A past cost that differs among alternatives.

Question 134

An internal auditor found that several employees of a vendor were authorized to remotely access the internal assets management system.

Which of the following should the auditor determine next?

Options:

A.

Whether there is a documented business need for the access.

B.

Whether access rights granted to vendor employees are read-only.

C.

Who to inform regarding the need to remove vendor employees’ access rights.

D.

Who manages vendor employees’ devices used to access the system.

Question 135

An organization has instituted a bring-your-own-device (BYOD) work environment. Which of the following policies best addresses the increased risk to the organization ' s network incurred by this environment?

Options:

A.

Limit the use of the employee devices for personal use to mitigate the risk of exposure to organizational data.

B.

Ensure that relevant access to key applications is strictly controlled through an approval and review process.

C.

Institute detection and authentication controls for all devices used for network connectivity and data storage.

D.

Use management software scan and then prompt parch reminders when devices connect to the network

Question 136

A rapidly expanding retail organization continues to be tightly controlled by its original small management team. Which of the following is a potential risk in this vertically centralized organization?

Options:

A.

Lack of coordination among different business units

B.

Operational decisions are inconsistent with organizational goals

C.

Suboptimal decision-making

D.

Duplication of business activities

Question 137

Which of the following financial statements provides the best disclosure of how a company ' s money was used during a particular period?

Options:

A.

Income statement.

B.

Owner ' s equity statement.

C.

Balance sheet.

D.

Statement of cash flows.

Question 138

An employee was promoted within the organization and relocated to a new office in a different building. A few months later, security personnel discovered that the employee ' s smart card was being used to access the building where she previously worked. Which of the following security controls could prevent such an incident from occurring?

Options:

A.

Regular review of logs.

B.

Two-level authentication.

C.

Photos on smart cards.

D.

Restriction of access hours.

Question 139

Which of the following is an example of a key systems development control typically found in the in-house development of an application system?

Options:

A.

Logical access controls monitor application usage and generate audit trails.

B.

The development process is designed to prevent, detect, and correct errors that may occur.

C.

A record is maintained to track the process of data from input, to output, to storage.

D.

Business users ' requirements are documented, and their achievement is monitored.

Question 140

Which of the following describes the free trade zone in an e-commerce environment?

Options:

A.

Zone that separates an organization ' s servers from outside forces.

B.

Area in which messages are scrutinized to determine if they are authorized.

C.

Area where communication and transactions occur between trusted parties.

D.

Zone where data is encrypted, users are authenticated, and user traffic is filtered.

Question 141

Which of the following describes how human resources can best assist in recruitment efforts for the internal audit function?

Options:

A.

Prepare competency-based interview questions and interview potential candidates

B.

Leverage the organization ' s intranet and recruiting agencies to search for potential candidates

C.

Forward all applications to the chief audit executive for review

D.

Select the most qualified candidate for the vacant position

Question 142

An organization ' s board of directors is particularly focused on positioning, the organization as a leader in the industry and beating the competition. Which of the following strategies offers the greatest alignment with the board ' s focus?

Options:

A.

Divesting product lines expected to have negative profitability.

B.

Increasing the diversity of strategic business units.

C.

Increasing investment in research and development for a new product.

D.

Relocating the organization ' s manufacturing to another country.

Question 143

Several organizations have developed a strategy to open co-owned shopping malls. What would be the primary purpose of this strategy?

Options:

A.

To exploit core competence.

B.

To increase market synergy.

C.

To deliver enhanced value.

D.

To reduce costs.

Question 144

Which of the following IT disaster recovery plans includes a remote site designated for recovery with available space for basic services, such as internet and telecommunications, but does not have servers or infrastructure equipment?

Options:

A.

Frozen site

B.

Cold site

C.

Warm site

D.

Hot site

Question 145

Which of the following statements about assurance maps is true?

Options:

A.

They help identify gaps and duplications in an organization’s assurance coverage

B.

They allow the board to coordinate activities of internal and external assurance providers

C.

They help identify which assurance provider is responsible for performing each audit listed in the annual internal audit plan

D.

They allow internal auditors to map competencies and specialty areas of the assurance providers in an organization

Question 146

Which of the following information security controls has the primary function of preventing unauthorized outside users from accessing an organization ' s data through the organization ' s network?

Options:

A.

Firewall.

B.

Encryption.

C.

Antivirus.

D.

Biometrics.

Question 147

Which of the following business practices promotes a culture of high performance?

Options:

A.

Reiterating the importance of compliance with established policies and procedures.

B.

Celebrating employees ' individual excellence.

C.

Periodically rotating operational managers.

D.

Avoiding status differences among employees.

Question 148

A company records income from an investment in common stock when it does which of the following?

Options:

A.

Purchases bonds.

B.

Receives interest.

C.

Receives dividends

D.

Sells bonds.

Question 149

Which of the following would best contribute to the success of a guest auditor program that allows people from other areas of the organization to serve as subject matter experts?

Options:

A.

Selecting guest auditors whose work has recently been audited by the internal audit function

B.

Recommending the guest auditor to design the internal audit program and perform testing procedures

C.

Soliciting feedback from the guest auditor once the engagement is complete

D.

Enabling the guest auditor to interact with internal audit staff to identify mutually beneficial opportunities

Question 150

Which of the following describes a benefit of using data analytics during an audit engagement?

Options:

A.

An increased number of data extracts obtained from IT personnel.

B.

A reduced audit risk by focusing risk assessment and stratifying the population.

C.

A broadened scope of assurance services through the increase of audit staff.

D.

An increased performance level of data analysis that enables reduced time for audit planning.

Question 151

Which of the following are the most appropriate measures for evaluating the change in an organization ' s liquidity position?

Options:

A.

Times interest earned, return on assets, and inventory turnover.

B.

Accounts receivable turnover, inventory turnover in days, and the current ratio.

C.

Accounts receivable turnover, return on assets, and the current ratio.

D.

Inventory turnover in days, the current ratio, and return on equity.

Question 152

Which of the following principles is shared by both hierarchical and open organizational structures?

A superior can delegate the authority to make decisions but cannot delegate the ultimate responsibility for the results of those decisions.

A supervisor ' s span of control should not exceed seven subordinates.

Responsibility should be accompanied by adequate authority.

Employees at all levels should be empowered to make decisions.

Options:

A.

1 and 3 only

B.

1 and 4 only

C.

2 and 3 only

D.

3 and 4 only

Question 153

Which mindset promotes the most comprehensive risk management strategy?

Options:

A.

Increase shareholder value.

B.

Maximize market share.

C.

Improve operational efficiency.

D.

Mitigate losses.

Question 154

Which of the following database components stores metadata regarding the database’s own configuration, setup, and objects?

Options:

A.

Database table.

B.

Program files.

C.

Backup system.

D.

Data dictionary.

Question 155

Which of the following controls would be most efficient to protect business data from corruption and errors?

Options:

A.

Controls to ensure data is unable to be accessed without authorization.

B.

Controls to calculate batch totals to identify an error before approval.

C.

Controls to encrypt the data so that corruption is likely ineffective.

D.

Controls to quickly identify malicious intrusion attempts.

Question 156

An organization requires an average of 58 days to convert raw materials into finished products to sell. An additional 42 days is required to collect receivables. If the organization takes an average of 10 days to pay for raw materials, how long is its total cash conversion cycle?

Options:

A.

26 days.

B.

90 days.

C.

100 days.

D.

110 days.

Question 157

Which of the following network types should an organization choose if it wants to allow access only to its own personnel?

Options:

A.

An extranet.

B.

A local area network (LAN).

C.

An intranet.

D.

The internet.

Question 158

Unsecured loans are loans:

Options:

A.

That do not have to be repaid for over one year.

B.

That appear to be too risky for most lenders to consider.

C.

Granted on the basis of a company ' s credit standing.

D.

Backed by mortgaged assets.

Question 159

Which of the following best explains why an organization would enter into a capital lease contract?

Options:

A.

To increase the ability to borrow additional funds from creditors

B.

To reduce the organization ' s free cash flow from operations

C.

To Improve the organization ' s free cash flow from operations

D.

To acquire the asset at the end of the lease period at a price lower than the fair market value

Question 160

Which of the following activities would come last in the development and implementation of a privacy and data protection program?

Options:

A.

Selecting the privacy and data protection framework.

B.

Establishing an assessment and communication format.

C.

Defining the scope of implementation procedures.

D.

Defining the privacy and data protection risks.

Question 161

According to IIA guidance, which of the following statements is true regarding the chief audit executive ' s (CAE’s) responsibility for following up on management action plans?

Options:

A.

Follow-up activities must be performed on an ongoing basis, such as quarterly, rather than being scheduled as specific assignments in the internal audit plan

B.

The primary purpose of the CAE’s follow-up activities is to verify whether the audit issues raised in the audit report are valid

C.

The CAE may plan follow-up activities on a selective basis, depending on risk significance, to verify whether management action plans were completed

D.

Where management believes certain action plans are no longer necessary, the CAE must resolve the matter with the board and if the matter remains unresolved, communicate to senior management

Question 162

Which of the following are typical audit considerations for a review of authentication?

    Authentication policies and evaluation of controls transactions.

    Management of passwords, independent reconciliation, and audit trail.

    Control self-assessment tools used by management.

    Independent verification of data integrity and accuracy.

Options:

A.

1, 2, and 3

B.

1, 2, and 4

C.

1, 3, and 4

D.

2, 3, and 4

Question 163

Which of the following data security policies is most likely to be the result of a data privacy law?

Options:

A.

Access to personally identifiable information is limited to those who need it to perform their job.

B.

Confidential data must be backed up and recoverable within a 24-hour period.

C.

Updates to systems containing sensitive data must be approved before being moved to production.

D.

A record of employees with access to insider information must be maintained, and those employees may not trade company stock during blackout periods.

Question 164

According to 11A guidance on it; which of the following statements is true regarding websites used in e-commerce transactions?

Options:

A.

HTTP sites provide sufficient security to protect customers ' credit card information.

B.

Web servers store credit cardholders ' information submitted for payment.

C.

Database servers send cardholders’ information for authorization in clear text.

D.

Payment gatewaysauthorizecredit cardonlinepayments.

Question 165

Capacity overbuilding is most likely to occur when management is focused on which of the following?

Options:

A.

Marketing.

B.

Finance.

C.

Production.

D.

Diversification.

Question 166

An organization has a declining inventory turnover but an Increasing gross margin rate, Which of the following statements can best explain this situation?

Options:

A.

The organization ' s operating expenses are increasing.

B.

The organization has adopted just-in-time inventory.

C.

The organization is experiencing Inventory theft

D.

The organization ' s inventory is overstated.

Question 167

Which of the following application controls is the most dependent on the password owner?

Options:

A.

Password selection.

B.

Password aging.

C.

Password lockout.

D.

Password rotation.

Question 168

Which of the following borrowing options is an unsecured loan?

Options:

A.

Second-mortgage financing from a bank.

B.

An issue of commercial paper.

C.

Pledged accounts receivable.

D.

Asset-based financing.

Question 169

What impact is there to liabilities on the balance sheet when ending inventory is overstated?

Options:

A.

There is no effect on liabilities.

B.

Liabilities are overstated.

C.

Liabilities are understated.

D.

Inventory errors affect income statement only.

Question 170

Which of the following is an example of a physical control designed to prevent security breaches?

Options:

A.

Preventing database administrators from initiating program changes

B.

Blocking technicians from getting into the network room.

C.

Restricting system programmers ' access to database facilities

D.

Using encryption for data transmitted over the public internet

Question 171

Which of the following is a key factor in the development of a production budget for a manufacturing organization?

Options:

A.

Direct materials units required.

B.

Estimated ending unit inventory.

C.

Projected sales revenue.

D.

Variable overhead costs.

Question 172

According to lIA guidance on IT, which of the following plans would pair the identification of critical business processes with recovery time objectives?

Options:

A.

The business continuity management charter.

B.

The business continuity risk assessment plan.

C.

The business Impact analysis plan

D.

The business case for business continuity planning

Question 173

An organization moving its sales conversion rate from 5% to 12% indicates which of the following?

Options:

A.

Worse sales activity.

B.

Better inventory usage.

C.

Better sales activity.

D.

Worse inventory usage.

Question 174

All of the following are possible explanations for a significant unfavorable material efficiency variance except:

Options:

A.

Cutbacks in preventive maintenance.

B.

An inadequately trained and supervised labor force.

C.

A large number of rush orders.

D.

Production of more units than planned for in the master budget.

Question 175

Refer to the exhibit. If the profit margin of an organization decreases, and all else remains equal, which of the following describes how the “Funds Needed” line in the graph below will shift?

Options:

A.

The “Funds Needed” line will remain pointed upward, but will become less steep.

B.

The “Funds Needed” line will remain pointed upward, but will become more steep.

C.

The “Funds Needed” line will point downward with a minimal slope.

D.

The “Funds Needed” line will point downward with an extreme slope.

Question 176

Which of the following networks is suitable for an organization that has operations In multiple cities and countries?

Options:

A.

Wide area network.

B.

Local area network

C.

Metropolitan area network.

D.

Storage area network.

Question 177

Which of the following can be classified as debt investments?

Options:

A.

Investments in the capital stock of a corporation

B.

Acquisition of government bonds.

C.

Contents of an investment portfolio,

D.

Acquisition of common stock of a corporation

Question 178

What security feature would Identity a legitimate employee using her own smart device to gam access to an application run by the organization?

Options:

A.

Using a jailbroken or rooted smart device feature.

B.

Using only smart devices previously approved by the organization.

C.

Obtaining written assurance from the employee that security policies and procedures are followed.

D.

Introducing a security question known only by the employee.

Question 179

With increased cybersecurity threats, which of the following should management consider to ensure that there is strong security governance in place?

Options:

A.

Inventory of information assets

B.

Limited sharing of data files with external parties.

C.

Vulnerability assessment

D.

Clearly defined policies

Question 180

In an analysis of alternative credit-management policies, which of the following components will cause the net present value of receivables on credit sales to increase, if everything else remains constant?

Options:

A.

A tougher collections policy that reduces the bad debt loss ratio.

B.

A higher cost per unit sold.

C.

A longer average collection period.

D.

An increase in the cost of capital.

Question 181

The project manager responsible for overseeing a controversial project decides to accept the risks associated with the project launch. These risks might have a significant impact on the organization meeting its environmental sustainability goals. Which of the following is the most appropriate next step for the chief audit executive to take in response to the decision?

Options:

A.

Educate employees working on the project launch about the risks

B.

Notify the board about the significant risks the organization might face

C.

Communicate the risks to senior management

D.

Instruct the project manager to stop the controversial project development

Question 182

An organization uses the management-by-objectives method, whereby employee performance is based on defined goals. Which of the following statements is true regarding this approach?

Options:

A.

It is particularly helpful to management when the organization is facing rapid change

B.

It is a more successful approach when adopted by mechanistic organizations

C.

It is more successful when goal-setting is performed not only by management, but by all team members, including lower-level staff

D.

It is particularly successful in environments that are prone to having poor employer-employee relations

Question 183

Which of the following would most likely be found in an organization that uses a decentralized organizational structure?

Options:

A.

There is a higher reliance on organizational culture.

B.

There are clear expectations set for employees.

C.

There are electronic monitoring techniques employed.

D.

There is a defined code for employee behavior.

Question 184

An organization had three large centralized divisions: one that received customer orders for service work; one that scheduled the service work at customer locations; and one that answered customer calls about service problems. These three divisions were restructured into seven regional groups, each of which performed all three functions. One advantage of this restructuring would be:

Options:

A.

Better internal controls.

B.

Greater economies of scale.

C.

Improved workflow.

D.

Increased specialization.

Question 185

According to IIA guidance, which of the following best describes an adequate management (audit) trail application control for the general ledger?

Options:

A.

Report identifying data that is outside of system parameters.

B.

Report identifying general ledger transactions by time and individual.

C.

Report comparing processing results with original input.

D.

Report confirming that the general ledger data was processed without error.

Question 186

Which of the following issues is a concern that a database administrator may face when integrating an organization’s applications that were once operated separately?

Options:

A.

The integrity of the data created by the applications may be compromised by the integration.

B.

The number of users with access to the applications may decrease as a result of the integration.

C.

The cost of maintaining the integration of the applications may increase at the start of the process.

D.

The implementation of more security protocols on the applications may slow down user productivity.

Question 187

Which of the following controls would be the most effective in preventing the disclosure of an organization ' s confidential electronic information?

Options:

A.

Nondisclosure agreements between the firm and its employees.

B.

Logs of user activity within the information system.

C.

Two-factor authentication for access into the information system.

D.

limited access so information, based on employee duties

Question 188

According to IIA guidance, which of the following corporate social responsibility activities is appropriate for the internal audit activity to perform?

Options:

A.

Determine the optimal amount of resources for the organization to invest in corporate social responsibility.

B.

Align corporate social responsibility program objectives with the organization ' s strategic plan.

C.

Integrate corporate social responsibility activities into the organization ' s decision-making process.

D.

Determine whether the organization has an appropriate policy governing its corporate social responsibility activities.

Question 189

Which of the following would provide the most relevant assurance that the application under development will provide maximum value to the organization?

Options:

A.

Use of a formal systems development lifecycle.

B.

End-user involvement.

C.

Adequate software documentation.

D.

Formalized non-regression testing phase.

Question 190

The head of the research arid development department at a manufacturing organization believes that his team lacks expertise in some areas, and he decides to hire more experienced researchers to assist in the development of a new product. Which of the following variances are likely to occur as the result of this decision?

1. Favorable labor efficiency variance.

2. Adverse labor rate variance.

3. Adverse labor efficiency variance.

4. Favorable labor rate variance.

Options:

A.

1 and 2

B.

1 and 4

C.

3 and A

D.

2 and 3

Question 191

Which of the following actions would senior management need to consider as part of new IT guidelines regarding the organization ' s cybersecurity policies?

Options:

A.

Assigning new roles and responsibilities for senior IT management.

B.

Growing use of bring your own devices for organizational matters.

C.

Expansion of operations into new markets with limited IT access.

D.

Hiring new personnel within the IT department for security purposes.

Question 192

An analytical model determined that on Friday and Saturday nights the luxury brands stores should be open for extended hours and with a doubled number of employees

present; while on Mondays and Tuesdays costs can be minimized by reducing the number of employees to a minimum and opening only for evening hours Which of the

following best categorizes the analytical model applied?

Options:

A.

Descriptive.

B.

Diagnostic.

C.

Prescriptive.

D.

Prolific.

Question 193

The first stage in the development of a crisis management program is to:

Options:

A.

Formulate contingency plans.

B.

Conduct a risk analysis.

C.

Create a crisis management team.

D.

Practice the response to a crisis.

Question 194

Which of the following serves as a safeguard to protect the confidentiality of information being transmitted from an internal network to an external network?

Options:

A.

A cloud network.

B.

A mobile network.

C.

An intranet.

D.

A virtual private network.

Question 195

Senior management is trying to decide whether to use the direct write-off or allowance method for recording bad debt on accounts receivables. Which of the following would be the best argument for using the direct write-off method?

Options:

A.

It is useful when losses are considered insignificant.

B.

It provides a better alignment with revenue.

C.

It is the preferred method according to The IIA.

D.

It states receivables at net realizable value on the balance sheet.

Question 196

A multinational organization allows its employees to access work email via personal smart devices. However, users are required to consent to the installation of mobile device management (MDM) software that will remotely wipe data in case of theft or other incidents. Which of the following should the organization ensure in exchange for the employees ' consent?

Options:

A.

That those employees who do not consent to MDM software cannot have an email account.

B.

That personal data on the device cannot be accessed and deleted by system administrators.

C.

That monitoring of employees ' online activities is conducted in a covert way to avoid upsetting them.

D.

That employee consent includes appropriate waivers regarding potential breaches to their privacy.

Question 197

Which of the following is a disadvantage in a centralized organizational structure?

Options:

A.

Communication conflicts

B.

Slower decision making.

C.

Loss of economies of scale

D.

Vulnerabilities in sharing knowledge

Question 198

How do data analysis technologies affect internal audit testing?

Options:

A.

They improve the effectiveness of spot check testing techniques.

B.

They allow greater insight into high risk areas.

C.

They reduce the overall scope of the audit engagement,

D.

They increase the internal auditor ' s objectivity.

Question 199

Which of the following is a project planning methodology that involves a complex series of required simulations to provide information about schedule risk?

Options:

Question 200

Which of the following best describes a potential benefit of using data analyses?

Options:

A.

It easily aligns with existing internal audit competencies to reduce expenses

B.

It provides a more holistic view of the audited area.

C.

Its outcomes can be easily interpreted into audit: conclusions.

D.

Its application increases internal auditors ' adherence to the Standards

Question 201

An organization with global headquarters in the United States has subsidiaries in eight other nations. If the organization operates with an ethnocentric attitude, which of the following statements is true?

Options:

A.

Standards used for evaluation and control are determined at local subsidiaries, not set by headquarters

B.

Orders, commands, and advice are sent to the subsidiaries from headquarters

C.

People of local nationality are developed for the best positions within their own country

D.

There is a significant amount of collaboration between headquarters and subsidiaries

Question 202

Which of the following best describes a cyberattacK in which an organization faces a denial-of-service threat created through malicious data encryption?

Options:

A.

Phishing.

B.

Ransomware.

C.

Hacking.

D.

Makvare

Question 203

At what stage of project integration management would a project manager and project management team typically coordinate the various technical and organizational interfaces that exist in the project?

Options:

A.

Project plan development.

B.

Project plan execution

C.

Integrated change control.

D.

Project quality planning

Question 204

Which stage of group development is characterized by a decrease in conflict and hostility among group members and an increase in cohesiveness?

Options:

A.

Forming stage.

B.

Norming stage.

C.

Performing stage.

D.

Storming stage.

Question 205

Which of the following items best describes the strategy of outsourcing?

Options:

A.

Contracting the work to Foreign Service providers to obtain lower costs

B.

Contracting functions or knowledge-related work with an external service provider.

C.

Contract -ng operation of some business functions with an internal service provider

D.

Contracting a specific external service provider to work with an internal service provider

Question 206

Which of the following best describes a man-in-the-middle cyber-attack?

Options:

A.

The perpetrator is able to delete data on the network without physical access to the device.

B.

The perpetrator is able to exploit network activities for unapproved purposes.

C.

The perpetrator is able to take over control of data communication in transit and replace traffic.

D.

The perpetrator is able to disable default security controls and introduce additional vulnerabilities

Question 207

An internal auditor is reviewing the sales and collections processes of an e-commerce organization that is facing budget constraints. The auditor found that the accountant did not perform reconciliations of cash collections in a timely manner. The auditor determined that the reason was timing errors in the interfacing process between the customer payments portal and the accounting system. The current customer payments portal was recently implemented to replace a legacy system. The finance manager is in charge of the customer payments portal. Which of the following recommendations is the most appropriate to address the root cause of this deficiency?

Options:

A.

The accountant, in view of the budget constraints, should consider a manual workaround to include unposted transactions into the accounting system in a timely manner

B.

Management should consider investing in a new customer payments portal, as the existing portal is unable to interface accurately with the accounting system

C.

The finance manager should work with IT and the vendor of the customer payments portal to rectify the interfacing errors

D.

The accountant should perform reconciliations of cash collections to customer payment records and investigate exceptions in a timely manner

Question 208

A chief audit executive wants to implement an enterprisewide resource planning software. Which of the following internal audit assessments could provide overall assurance on the likelihood of the software implementation ' s success?

Options:

A.

Readiness assessment.

B.

Project risk assessment.

C.

Post-implementation review.

D.

Key phase review.

Question 209

The decision to implement enhanced failure detection and backup systems to improve data integrity is an example of which risk response?

Options:

A.

Risk acceptance.

B.

Risk sharing.

C.

Risk avoidance.

D.

Risk reduction.

Question 210

The internal audit activity completed an initial risk analysis of the organization ' s data storage center and found several areas of concern. Which of the following is the most appropriate next step?

Options:

A.

Risk response.

B.

Risk identification.

C.

Identification of context.

D.

Risk assessment.

Question 211

Which of the following communication characteristics is achieved when the internal audit function avoids redundancies and excludes information that is unnecessary, insignificant, or unrelated to the engagement?

Options:

A.

Constructive communications

B.

Complete communications

C.

Concise communications

D.

Clear communications

Question 212

With regard to disaster recovery planning, which of the following would most likely involve stakeholders from several departments?

Options:

A.

Determining the frequency with which backups will be performed.

B.

Prioritizing the order in which business systems would be restored.

C.

Assigning who in the IT department would be involved in the recovery procedures.

D.

Assessing the resources needed to meet the data recovery objectives.

Question 213

During which phase of the contracting process are contracts drafted for a proposed business activity?

Options:

A.

Initiation phase.

B.

Bidding phase.

C.

Development phase.

D.

Management phase.

Question 214

Which of the following is the best example of IT governance controls?

Options:

A.

Controls that focus on segregation of duties, financial, and change management,

B.

Personnel policies that define and enforce conditions for staff in sensitive IT areas.

C.

Standards that support IT policies by more specifically defining required actions

D.

Controls that focus on data structures and the minimum level of documentation required

Question 215

Which of the following is a security feature that Involves the use of hardware and software to filter or prevent specific Information from moving between the inside network and the outs de network?

Options:

A.

Authorization

B.

Architecture model

C.

Firewall

D.

Virtual private network

Question 216

According to the Standards, the internal audit activity must evaluate risk exposures relating to which of the following when examining an organization ' s risk management process?

    Organizational governance.

    Organizational operations.

    Organizational information systems.

    Organizational structure.

Options:

A.

1 and 3 only

B.

2 and 4 only

C.

1, 2, and 3 only

D.

1, 2, and 4 only

Question 217

Which of the following is a key performance indicator of the efficiency of the internal audit function?

Options:

A.

The number of audits completed

B.

The number of significant audit observations

C.

The percentage of recommendations implemented

D.

The number of training hours per auditor

Question 218

Which of the following bring-your-own-device (BYOD) practices is likely to increase the risk of Infringement on local regulations, such as copyright or privacy laws?

Options:

A.

Not installing anti-malware software

B.

Updating operating software in a haphazard manner,

C.

Applying a weak password for access to a mobile device.

D.

JoIIbreaking a locked smart device

Question 219

Which of the following activities most significantly increases the risk that a bank will make poor-quality loans to its customers?

Options:

A.

Borrowers may not sign all required mortgage loan documentation.

B.

Fees paid by the borrower at the time of the loan may not be deposited in a timely manner.

C.

The bank ' s loan documentation may not meet the government ' s disclosure requirements.

D.

Loan officers may override the lending criteria established by senior management.

Question 220

During an internal audit engagement, numerous deficiencies in the organization ' s management of customer data were discovered, entailing the risk of breaching personal data protection legislation. An improvement plan was approved by senior management. Which of the following conditions observed during the periodic follow-up process best justifies the chief audit executive ' s decision to escalate the issue to the board?

Options:

A.

The organization ' s customer satisfaction index does not show any signs of improvement

B.

No budget or resources have been allocated to implement corrective measures

C.

The board has not been informed about the planned improvements approved by senior management

D.

Employees responsible for improvements are resisting any additional workload

Question 221

Which audit approach should be employed to test the accuracy of information housed in a database on an un-networked computer?

Options:

A.

Submit batches of test transactions through the current system and verify with expected results.

B.

Use a test program to simulate the normal data entering process.

C.

Select a sample of records from the database and ensure it matches supporting documentation.

D.

Evaluate compliance with the organization ' s change management process.

Question 222

According to Porter ' s model of competitive strategy, which of the following is a generic strategy?

    Differentiation.

    Competitive advantage.

    Focused differentiation.

    Cost focus.

Options:

A.

2 only

B.

3 and 4 only

C.

1, 3, and 4 only

D.

1, 2, 3, and 4

Question 223

An organization ' s financial statements indicate a note that the financial statements have been prepared on the basis of the organization continuing operations for the foreseeable future. Which of the following accounting principles has been applied based on this note?

Options:

A.

Monetary unit assumption.

B.

Going concern assumption.

C.

Time period assumption.

D.

Economic entity assumption.

Question 224

An organization decided to install a motion detection system in its warehouse to protect against after-hours theft. According to the COSO enterprise risk management framework, which of the following best describes this risk management strategy?

Options:

A.

Avoidance.

B.

Reduction.

C.

Elimination.

D.

Sharing.

Question 225

Which of the following facilitates data extraction from an application?

Options:

A.

Application program code.

B.

Database system.

C.

Operating system.

D.

Networks.

Question 226

Employees at an events organization use a particular technique to solve problems and improve processes. The technique consists of five steps: define, measure, analyze,

improve, and control. Which of the following best describes this approach?

Options:

A.

Six Sigma,

B.

Quality circle.

C.

Value chain analysis.

D.

Theory of constraints.

Question 227

When using the absorption costing approach, which of the following should be categorized as a period cost?

Options:

A.

Selling expenses.

B.

Fixed manufacturing overhead.

C.

Direct labor.

D.

Variable manufacturing overhead.

Question 228

A bond that matures after one year has a face value of S250,000 and a coupon of $30,000. if the market price of the bond is 5265,000, which of the following would be the market interest rate?

Options:

A.

Less than 12 percent.

B.

12 percent.

C.

Between 12.01 percent and 12.50 percent.

D.

More than 12 50 percent.

Question 229

For which of the following scenarios would the most recent backup of the human resources database be the best source of information to use?

Options:

A.

An incorrect program fix was implemented just prior to the database backup.

B.

The organization is preparing to train all employees on the new self-service benefits system.

C.

There was a data center failure that requires restoring the system at the backup site.

D.

There is a need to access prior year-end training reports for all employees in the human resources database

Question 230

According to the COSO enterprise risk management framework, which of the following is not a typical responsibility of the chief risk officer?

Options:

A.

Establishing risk category definitions and a common risk language for likelihood and impact measures.

B.

Defining enterprise risk management roles and responsibilities.

C.

Providing the board with an independent, objective risk perspective on financial reporting.

D.

Guiding integration of enterprise risk management with other management activities.

Question 231

An organization wants to offer a standard product across all markets but also wants to differentiate the product to fit local demands in different geographic markets and to meet government regulations.

Which of the following strategies may help the organization achieve its goal?

Options:

A.

Globalization strategy.

B.

Transnational strategy.

C.

Multidomestic strategy.

D.

Export strategy.

Question 232

During which phase of disaster recovery planning should an organization identify the business units, assets, and systems that are critical to continuing an acceptable level of operations?

Options:

A.

Scope and initiation phase.

B.

Business impact analysis.

C.

Plan development.

D.

Testing.

Question 233

With regard to project management, which of the following statements about project crashing Is true?

Options:

A.

It leads to an increase in risk and often results in rework.

B.

It is an optimization technique where activities are performed in parallel rather than sequentially.

C.

It involves a revaluation of project requirements and/or scope.

D.

It is a compression technique in which resources are added so the project.

Question 234

An organization allows employees to use their personal mobile devices to access its database. Which of the following best maintains the confidentiality of different records within the database?

Options:

A.

Regular remote wiping of the mobile devices accessing the database.

B.

Encrypted data transmissions between mobile devices and the database.

C.

Restrictions on the access permissions when mobile devices are used.

D.

The use of two-factor authentication algorithms for those who use remote access.

Question 235

Which of the following actions should an internal auditor take to clean the data obtained for analytics purposes?

Options:

A.

Deploys data visualization tool.

B.

Adopt standardized data analysis software.

C.

Define analytics objectives and establish outcomes.

D.

Eliminate duplicate records.

Question 236

With regard to project management, which of the following statements about project crashing is true?

Options:

A.

It leads to an increase in risk and often results in rework.

B.

It is an optimization technique where activities are performed in parallel rather than sequentially.

C.

It involves a revaluation of project requirements and/or scope.

D.

It is a compression technique in which resources are added to the project.

Question 237

When developing an effective risk-based plan to determine audit priorities, an internal audit activity should start by:

Options:

A.

Identifying risks to the organization ' s operations.

B.

Observing and analyzing controls.

C.

Prioritizing known risks.

D.

Reviewing organizational objectives.

Exam Detail
Vendor: IIA
Certification: CIA
Exam Code: IIA-CIA-Part3
Last Update: Jul 21, 2026
IIA-CIA-Part3 Question Answers