IIA IIA-CIA-Part3 Internal Audit Function Exam Practice Test
Internal Audit Function Questions and Answers
Internal auditors are reviewing change management processes involving the organization’s IT department.
Which of the following is a characteristic of an ineffective change management process that would impact the organization’s clients?
Which of the following measures would best protect an organization from automated attacks whereby the attacker attempts to identify weak or leaked passwords in order to log into employees ' accounts?
Which of the following responsibilities would ordinary fall under the help desk function of an organization?
Which of the following measures the operating success of a company for a given period of time?
A new clerk in the managerial accounting department applied the high-low method and computed the difference between the high and low levels of maintenance costs. Which type of maintenance costs did the clerk determine?
Which of the following devices best controls both physical and logical access to information systems?
Which of the following statements is true regarding user-developed applications (UDAs)?
Which of the following information security controls has the primary function of preventing unauthorized outside users from accessing an organization ' s data through the organization ' s network?
Which of the following are likely indicators of ineffective change management?
IT management is unable to predict how a change will impact interdependent systems or business processes.
There have been significant increases in trouble calls or in support hours logged by programmers.
There is a lack of turnover in the systems support and business analyst development groups.
Emergency changes that bypass the normal control process frequently are deemed necessary.
Which of the following is a characteristic of using a hierarchical control structure?
Which of the following situations best applies to an organisation that uses a project, rather than a process, to accomplish its business activities?
When determining the level of physical controls required for a workstation, which of the following factors should be considered?
During a routine bank branch audit, the internal audit function observed that the sole security guard at the branch only worked part time. The chief audit executive (CAE) believed that this increased the risk of loss of property and life in the event of a robbery. The branch security manager informed the CAE that a full-time guard was not needed because the branch was in close proximity to a police station. Still, the CAE found this to be an unacceptable risk due to the recent increase in robberies in that area. Which of the following is the most appropriate next step for the CAE to take?
Which of the following documents would provide an internal auditor with information on the length of time to maintain documents after the completion of an engagement?
A chief audit executive (CAE) joined an organization in the middle of the financial year. A risk-based annual audit plan has been approved by the board and is already underway. However, after discussions with key stakeholders, the CAE realizes that some significant key risk areas have not been covered in the original audit plan. How should the CAE respond?
According to IIA guidance, which of the following would be a primary reason for an internal auditor to test the organization ' s IT contingency plan?
According to IIA guidance, which of the following is a typical risk associated with the tender process and contracting stage of an organization ' s IT outsourcing life cycle?
How do data analysis technologies affect internal audit testing?
International marketing activities often begin with:
Which of the following management statements illustrates how natural bias can lead to poor decision making?
Which of the following controls is the most effective for ensuring confidentially of transmitted information?
As part of internal audit ' s risk assessment, a chief audit executive is determining certain factors as part of planning the areas to audit within an organization that makes silicon chips. Which of the following would be considered a subjective factor as part of the risk assessment?
Which of the following can be classified as debt investments?
Which of the following would most likely serve as a foundation for individual operational goats?
During the second half of the audit year, the chief audit executive (CAE) identified significant negative variances to the approved audit budget required to complete the internal audit plan. Which of the following actions should the CAE take?
Which of the following is a characteristic of big data?
What relationship exists between decentralization and the degree, importance, and range of lower-level decision making?
An organization has an agreement with a third-party vendor to have a fully operational facility, duplicate of the original site and configured to the organization ' s needs, in order to quickly recover operational capability in the event of a disaster, Which of the following best describes this approach to disaster recovery planning?
What is the primary risk associated with an organization adopting a decentralized structure?
In an organization with a poor control environment, which of the following indicators would help an internal audit function measure its ability to provide risk-based assurance?
Which of the following is an example of a nonfinancial internal failure quality cost?
Which of the following is not included in the process of user authentication?
Which of the following actions illustrates the use of electronic data interchange?
Which of the following statements is true regarding user developed applications (UDAs) and traditional IT applications?
According to IIA guidance, which of the following steps are most important for an internal auditor to perform when evaluating an organization ' s social and environmental impact on the local community?
Determine whether previous incidents have been reported, managed, and resolved.
Determine whether a business contingency plan exists.
Determine the extent of transparency in reporting.
Determine whether a cost/benefit analysis was performed for all related projects.
An organization uses the management-by-objectives method whereby employee performance is based on defined goals. Which of the following statements is true regarding this approach?
Which of the following assessments will assist in evaluating whether the internal audit function is consistently delivering quality engagements?
Which of the following would be classified as IT general controls?
Which of the following is most appropriate for the chief audit executive to keep in mind when establishing policies and procedures to guide the internal audit function?
An internal audit uncovered high-risk issues that needed to be addressed by the organization. During the exit conference, the audit team discussed the high-risk issues with the manager responsible for addressing them. How should the chief audit executive respond if the manager agrees to correct the issues identified during the audit?
Which of the following bring-your-own-device (BYOD) practices is likely to increase the risk of infringement on local regulations, such as copyright or privacy laws?
Which of the following IT strategies is most effective for responding to competitive pressures created by the marketplace?
Management has decided to change the organizational structure from one that was previously decentralized to one that is now highly centralized. As such: which of the
following would be a characteristic of the now highly centralized organization?
An organization is projecting sales of 100,000 units, at a unit price of $12. Unit variable costs are $7. If fixed costs are $350,000, what is the projected total contribution margin?
An internal auditor identified a database administrator with an incompatible dual role. Which of the following duties should not be performed by the identified administrator?
Which of the following lists best describes the classification of manufacturing costs?
Which of the following IT layers would require the organization to maintain communication with a vendor in a tightly controlled and monitored manner?
Which of the following would be the best method to collect information about employees ' job satisfaction?
Which of the following best describes the concept of relevant cost?
Which of the following performance measures includes both profits and investment base?
When auditing databases, which of the following risks would an Internal auditor keep In mind In relation to database administrators?
Employees at an events organization use a particular technique to solve problems and improve processes. The technique consists of five steps: define, measure, analyze,
improve, and control. Which of the following best describes this approach?
Which of the following is an effective preventive control for data center security?
Import quotas that limit the quantities of goods that a domestic subsidiary can buy from its foreign parent company represent which type of barrier to the parent company?
Organizational activities that complement each other and create a competitive advantage are called a:
Which of the following assumptions regarding cost-volume-profit analysis is true?
An organization selected a differentiation strategy to compete at the business level. Which of the following structures best fits this strategic choice?
Which of the following is the most appropriate action an internal auditor would perform during an audit of his organization ' s IT change management process?
Which of the following types of accounts must be closed at the end of the period?
Which of the following best describes the job design strategy used by the chief audit executive that encourages internal auditors to manage engagements from the beginning to the end?
Which of the following local area network physical layouts is subject to the greatest risk of failure if one device fails?
Which of the following sites would an Internet service provider most likely use to restore operations after its servers were damaged by a natural disaster?
An organization has instituted a bring-your-own-device (BYOD) work environment. Which of the following policies best addresses the increased risk to the organization ' s network incurred by this environment?
An organization that soils products to a foreign subsidiary wants to charge a price that wilt decrease import tariffs. Which of the following is the best course of action for the organization?
Which audit approach should be employed to test the accuracy of information housed in a database on an un-networked computer?
What is the primary purpose of data and systems backup?
Which of the following employee survey questions would be most effective to measure organizational commitment?
Which type of bond sells at a discount from face value, then increases in value annually until it reaches maturity and provides the owner with the total payoff?
Which stage of group development is characterized by a decrease in conflict and hostility among group members and an increase in cohesiveness?
Which of the following data analytics techniques is used to identify patterns among groups of data elements?
Which of the following statements is accurate regarding the use of Secure Sockets Layer (SSL) as a control?
The internal audit activity has identified accounting errors that resulted in the organization overstating its net income for the fiscal year. Which of the following is the most likely cause of this overstatement?
A multinational organization allows its employees to access work email via personal smart devices. However, users are required to consent to the installation of mobile device management (MDM) software that will remotely wipe data in case of theft or other incidents. Which of the following should the organization ensure in exchange for the employees ' consent?
Which type of bond sells at & discount from face value, then increases in value annually until it reaches maturity and provides the owner with the total payoff?
Which of the following is an example of a contingent liability that a company should record?
Which of the following purchasing scenarios would gain the greatest benefit from implementing electronic data interchange?
Which of the following statements about assurance maps is true?
Which of the following attributes of data analytics relates to the growing number of sources from which data is being generated?
A financial institution receives frequent and varied email requests from customers for funds to be wired out of their accounts. Which verification activity would best help the institution avoid falling victim to phishing?
Which of the following statements Is true regarding the use of centralized authority to govern an organization?
The internal auditor concluded there was a high likelihood that a significant wind farm development, worth $200 million, would be delayed from its approved schedule. As a result, electricity production would not start on time, leading to considerable financial penalties. Which of the following should be added to the observation to support its clarity and completeness?
Which of the following borrowing options is an unsecured loan?
Which of the following is most appropriately placed in the financing section of an organization ' s cash budget?
According to Maslow’s hierarchy of needs theory, which of the following best describes a strategy where a manager offers an assignment to a subordinate specifically to support his professional growth and future advancement?
An organization filters data packets from public networks to send to an internal private network.
Which of the following devices would accomplish this?
Which of the following roles would be least appropriate for the internal audit activity to undertake with regard to an organization ' s corporate social responsibility program?
When executive compensation is based on the organization ' s financial results, which of the following situations is most likely to arise?
Which of the following IT professionals is responsible for providing maintenance to switches and routers to keep IT systems running as intended?
A organization finalized a contract in which a vendor is expected to design, procure, and construct a power substation for $3,000,000. In this scenario, the organization agreed to which of the following types of contracts?
The internal audit function of a manufacturing organization is conducting an advisory engagement. The engagement team identifies a gap in procedures: there is no documentation for the activities that take place when new site construction projects are completed. In practice, these activities include the transfer of assets from the development department to the production department. What is the most appropriate action for the engagement team?
Which of the following is the best example of IT governance controls?
According to Herzberg ' s Two-Factor Theory of Motivation, which of the following is a factor mentioned most often by satisfied employees?
A company that uses the accrual basis of accounting can recognize revenue under which of the following conditions?
Which of the following attributes of data are cybersecurity controls primarily designed to protect?
Which of the following is a key performance indicator of the efficiency of the internal audit function?
Which of the following situations best applies to an organization that uses a project, rather than a process, to accomplish its business activities?
When management uses the absorption costing approach, fixed manufacturing overhead costs are classified as which of the following types of costs?
An organization sells 1,000 shares of its treasury stock at $15 per share previously acquired at $10 per share.
Which of the following statements is true?
Which of the following is generally considered a best practice related to data backup?
Performing full system backups on weekdays.
Storing system backups onsite in a secured location.
Testing system backup media periodically.
Verifying backup media can be retrieved within seven years.
Which of the following best describes owner ' s equity?
According to IIA guidance, which of the following statements is true with regard to workstation computers that access company information stored on the network?
Refer to the exhibit. If the profit margin of an organization decreases, and all else remains equal, which of the following describes how the “Funds Needed” line in the graph below will shift?
During her annual performance review, a sales manager admits that she experiences significant stress due to her job but stays with the organization because of the high bonuses she earns. Which of the following best describes her primary motivation to remain in the job?
Which of the following physical access controls is most likely to be based on the " something you have " concept?
When granting third parties temporary access to an entity ' s computer systems, which of the following is the most effective control?
Which of the following is the most appropriate beginning step of a work program for an assurance engagement involving smart devices?
Which of the following best describes the benefit of an organization adopting a business continuity and disaster recovery plan for responding to natural disasters?
The chief audit executive (CAE) has embraced a total quality management approach to improving the internal audit activity ' s (lAArs) processes. He would like to reduce the time to complete audits and improve client ratings of the IAA. Which of the following staffing approaches is the CAE most likely lo select?
According to IIA guidance, which of the following would be the best first stop to manage risk when a third party is overseeing the organization ' s network and data?
Which of the following accurately describes a difference between phishing and spear phishing?
In accounting, which of the following statements is true regarding the terms debit and credit?
An internal auditor has requested the organizational chart in order to evaluate the control environment of an organization. Which of the following is a disadvantage of using the organizational chart?
Which of the following is an example of a physical control?
The board and senior management agree to outsource the internal audit function. Which of the following is true regarding the company’s quality assurance and improvement program (QAIP)?
According to the International Professional Practices Framework, internal auditors who are assessing the adequacy of organizational risk management processes should not:
Which of the following is an example of a phishing attack?
Which of the following describes the most appropriate set of tests for auditing a workstation ' s logical access controls?
Which of the following is a characteristic of an emerging industry?
When examining; an organization ' s strategic plan, an internal auditor should expect to find which of the following components?
Management is pondering the following question:
" How does our organization compete? "
This question pertains to which of the following levels of strategy?
Listening effectiveness is best increased by:
Which of the following is a project planning methodology that involves a complex series of required simulations to provide information about schedule risk?
The first step in determining product price is:
An internal auditor reviews consolidated financial statements for a group of organizations.
Which of the following risks should the auditor consider?
An internal auditor is auditing their organization’s termination process. A primary objective of this engagement is to verify that exit interviews were conducted for all terminated employees over the last two years. The auditor discovered that not all employees received exit interviews.
Which of the following risks could this lead to?
According to IIA guidance on IT, which of the following best describes a logical access control?
According to the Standards, the internal audit activity must evaluate risk exposures relating to which of the following when examining an organization ' s risk management process?
Organizational governance.
Organizational operations.
Organizational information systems.
Organizational structure.
Which of the following is a role of the board of directors in the governance process?
Which of the following is the best example of a compliance risk that is likely to arise when adopting a bring-your-own-device (BYOD) policy?
Which of the following statements is true regarding data backup?
Which of the following best describes a potential benefit of using data analyses?
Which of the following data analytics methods involves analyzing event trends to determine what happened?
Which of the following conflict resolution methods should be applied when the intention of the parties is to solve the problem by clarifying differences and attaining everyone ' s objectives?
Which of the following statements regarding the necessary resources to achieve the internal audit plan is true?
What kind of strategy would be most effective for an organization to adopt in order to Implement a unique advertising campaign for selling identical product lines across all of its markets?
An organization decided to install a motion detection system in its warehouse to protect against after-hours theft. According to the COSO enterprise risk management framework, which of the following best describes this risk management strategy?
Which of the following is a distinguishing feature of managerial accounting, which is not applicable to financial accounting?
Which of the following engagement observations would provide the least motivation for management to amend or replace an existing cost accounting system?
An internal auditor discovered that the organization was not in full compliance with a regulatory labeling requirement for one of its products. The responsible manager indicated that the current product labeling has been in use for several years without any problems. If discovered, this regulatory breach could result in significant fines for the organization. What should be the chief audit executive ' s next course of action?
Which mindset promotes the most comprehensive risk management strategy?
At what point during the systems development process should an internal auditor verify that the new application ' s connectivity to the organization ' s other systems has been established correctly?
The cost to enter a foreign market would be highest in which of the following methods of global expansion?
Which of the following controls would an internal auditor consider the most relevant to reduce risks of project cost overruns?
An organization uses the management-by-objectives method, whereby employee performance is based on defined goals. Which of the following statements is true regarding this approach?
An organization decided to reorganize into a flatter structure. Which of the following changes would be expected with this new structure?
Which of the following statements is accurate when planning for an external quality assurance assessment of the internal audit function?
What is the primary purpose of an integrity control?
Which of the following statements about matrix organizations is false?
A capital investment project will have a higher net present value, everything else being equal, if it has:
An internal auditor is using data analytics to focus on high-risk areas during an engagement. The auditor has obtained data and is working to eliminate redundancies in the data. Which of the following statements is true regarding this scenario?
Which of the following principles s shared by both hierarchies and open organizational structures?
1. A superior can delegate the authority to make decisions but cannot delegate the ultimate responsibility for the results of those decisions.
2. A supervisor ' s span of control should not exceed seven subordinates.
3. Responsibility should be accompanied by adequate authority.
4. Employees at all levels should be empowered to make decisions.
A holding company set up a centralized group technology department, using a local area network with a mainframe computer to process accounting information for all companies within the group. An internal auditor would expect to find all of the following controls within the technology department except:
An internal auditor discusses user-defined default passwords with the database administrator. Such passwords will be reset as soon as the user logs in for the first time, but the initial value of the password is set as " 123456. " Which of the following are the auditor and the database administrator most likely discussing in this situation?
The project manager responsible for overseeing a controversial project decides to accept the risks associated with the project launch. These risks might have a significant impact on the organization meeting its environmental sustainability goals. Which of the following is the most appropriate next step for the chief audit executive to take in response to the decision?
Which of the following scenarios best illustrates a spear phishing attack?
Which of the following is a necessary action for an internal audit function if senior management chooses not to take action to remediate the finding and accepts the risk?
Which of the following is an indicator of liquidity that is more dependable than working capital?
An organization has 10,000 units of a defect item in stock, per unit, market price is $10$; production cost is $4; and defect selling price is $5. What is the carrying amount (inventory value) of defects at your end?
Which of the following can be viewed as a potential benefit of an enterprisewide resource planning system?
Which of the following describes the most effective control that restricts access to secure areas?
Which of the following network types should an organization choose if it wants to allow access only to its own personnel?
An organization has an immediate need for servers, but no time to complete capital acquisitions. Which of the following cloud services would assist with this situation?
During which of the following phases of contracting does the organization analyze whether the market is aligned with organizational objectives?
Which of the following is the most important contract term to audit, because it typically impacts business efficiency?
An internal auditor conducts a preliminary privacy and data protection risk assessment. Which of the following is the most essential question to start the assessment?
Which of the following should be included in a data privacy poky?
1. Stipulations for deleting certain data after a specified period of time.
2. Guidance on acceptable methods for collecting personal data.
3. A requirement to retain personal data indefinitely to ensure a complete audit trail,
4. A description of what constitutes appropriate use of personal data.
An organization suffered significant damage to its local: file and application servers as a result of a hurricane. Fortunately, the organization was able to recover all information backed up by its overseas third-party contractor. Which of the following approaches has been used by the organization?
During an internal audit engagement, numerous deficiencies in the organization ' s management of customer data were discovered, entailing the risk of breaching personal data protection legislation. An improvement plan was approved by senior management. Which of the following conditions observed during the periodic follow-up process best justifies the chief audit executive ' s decision to escalate the issue to the board?
An internal auditor found that several employees of a vendor were authorized to remotely access the internal assets management system.
Which of the following should the auditor determine next?
Employees of an organization noticed that an exterior surface of the office building was deteriorating. Upon investigation, it was found that the deterioration was caused by harsh cleaning chemicals used to remove excessive bird droppings, and that the birds were drawn to the building to feed from a spider infestation. Which of the following best represents a root cause-based recommendation for this situation?
Which of the following is a security feature that Involves the use of hardware and software to filter or prevent specific Information from moving between the inside network and the outs de network?
Internal audit discovered that several loads of pellets were deleted from the scaling database and consequently had no sales invoices, significantly affecting financial statements. An investigation revealed that technicians had deleted the pellet loads accidentally, with no evidence of fraud. Which of the following actions should management implement first?
An internal auditor uses a risk and control questionnaire as part of the preliminary survey for an audit of the organization ' s anti-bribery and corruption program. What is the primary purpose of using this approach?
Senior management of a dairy organization asks the internal audit function to undertake an advisory service within the finance function and the internal audit function subsequently issues a report. Which of the following is aligned with IIA guidance on monitoring the results of such an engagement?
An organization decided to outsource its human resources function. As part of its process migration, the organization is implementing controls over sensitive employee data.
What would be the most appropriate directive control in this area?
Which of the following accounting methods is an investor organization likely to use when buying 40 percent of the stock of another organization?
Which of the following data privacy concerns can be attributed specifically to blockchain technologies?
A major IT project is scheduled to be implemented over a three-month period during the year. The chief audit executive (CAE) scheduled significant audit resources to provide consultation. Due to technical challenges from a supplier, the project is postponed until the following year. What should the CAE do in this case?
According to lIA guidance on IT, which of the following plans would pair the identification of critical business processes with recovery time objectives?
According to Porter ' s model of competitive strategy, which of the following is a generic strategy?
Differentiation.
Competitive advantage.
Focused differentiation.
Cost focus.
Which of the following statements regarding flat and hierarchical internal audit functions is true?
According to IIA guidance, which of the following statements is true regarding the chief audit executive ' s (CAE’s) responsibility for following up on management action plans?
Which of the following controls would enable management to receive timely feedback and help mitigate unforeseen risks?
Which of the following capital budgeting techniques considers the expected total net cash flows from investment?
Which of the following dimensions relates to the quality of big data?
During an internal audit engagement, it was found that several vendors were on a government sanctions list and must no longer be traded with. Which of the following would most effectively mitigate the risk of noncompliance with sanctions lists that are updated regularly?
At one organization, the specific terms of a contract require both the promisor end promise to sign the contract in the presence of an independent witness.
What is the primary role to the witness to these signatures?
Which of the following networks is best for an organization to use when employees are granted access rights to authenticate themselves to the IT resources from outside the organization?
Which of the following is an example of two-factor authentication?
An organization engages in questionable financial reporting practices due to pressure to meet unrealistic performance targets. Which internal control component is most negatively affected?
As it relates to the data analytics process, which of the following best describes the purpose of an internal auditor who cleaned and normalized cate?
Which of the following responsibilities would ordinarily fall under the help desk function of an organization?
Which of the following is an advantage of a decentralized organizational structure, as opposed to a centralized structure?
Which of the following statements regarding organizational governance is not correct?
An internal auditor reviewed Finance Department records to obtain a list of current vendor addresses. The auditor then compared the vendor addresses to a record of employee addresses maintained by the Payroll Department Which of the following types of data analysis did the auditor perform?
According to IIA guidance on IT, which of the following best describes a situation where data backup plans exist to ensure that critical data can be restored at some point in the future, but recovery and restore processes have not been defined?
Which of the following performance measures disincentives engaging in earnings management?
Under a value-added taxing system:
Which of the following data security policies is most likely to be the result of a data privacy law?
An organization ' s IT systems can only be accessed using the organization ' s virtual private network. However, organizational emails, videoconferencing, and file-sharing tools are cloud-based and can be accessed using multi-factor authentication via any device. Which of the following risks should the organization acknowledge?
Which of the following statements is true regarding a project life cycle?
An investor has acquired an organization that has a dominant position in a mature, slow-growth industry and consistently creates positive financial income. Which of the following terms would the investor most likely label this investment in her portfolio?
When an organization is choosing a new external auditor, which of the following is the most appropriate role for the chief audit executive to undertake?
A motivational technique generally used to overcome monotony and job-related boredom is:
While performing an audit of a car tire manufacturing plant, an internal auditor noticed a significant decrease in the number of tires produced from the previous operating
period. To determine whether worker inefficiency caused the decrease, what additional information should the auditor request?
Which of the following would provide the most relevant assurance that the application under development will provide maximum value to the organization?
Senior management has decided to implement the Three Lines of Defense model for risk management. Which of the following best describes senior management ' s duties with regard to this model?
According to 11A guidance on it; which of the following statements is true regarding websites used in e-commerce transactions?
When preparing the annual internal audit plan, which of the following should the chief audit executive (CAE) consider to optimize efficiency and effectiveness?
The process of scenario planning begins with which of the following steps?
An internal auditor was asked to review an equal equity partnership. In one sampled transaction, Partner A transferred equipment into the partnership with a self-declared value of $10,000, and Partner B contributed equipment with a self-declared value of $15,000. The capital accounts of each partner were subsequently credited with $12,500. Which of the following statements is true regarding this transaction?
A rapidly expanding retail organization continues to be tightly controlled by its original small management team. Which of the following is a potential risk in this vertically centralized organization?
An internal auditor wishes to test why there was a significant drop in accounts payable volume last month and creates several scenarios to help explain the anomaly.
Which of the following best describes this data analysis technique?
Which of the following IT-related activities is most commonly performed by the second line of defense?
Which of the following attributes of data is the most significantly impacted by the internet of things?
Which of the following statements is true regarding activity-based costing (ABC)?
Which of the following is classified as a product cost using the variable costing method?
Direct labor costs.
Insurance on a factory.
Manufacturing supplies.
Packaging and shipping costs.
Which of the following characteristics applies to an organization that adopts a flat structure?
Preferred stock is less risky for investors than is common stock because:
Which of the following risks is the result of an organization failing to create and establish strategies for the use of social media?
Which of the following techniques is the most relevant when an internal auditor conducts a valuation of an organization ' s physical assets?
An attacker, posing as a bank representative, convinced an employee to release certain, financial information that ultimately resulted in fraud. Which of the following best describes this cybersecurity risk?
An organization had three large centralized divisions: one that received customer orders for service work; one that scheduled the service work at customer locations; and one that answered customer calls about service problems. These three divisions were restructured into seven regional groups, each of which performed all three functions. One advantage of this restructuring would be:
A chief audit executive wants to implement an enterprisewide resource planning software. Which of the following internal audit assessments could provide overall assurance on the likelihood of the software implementation ' s success?
Which of the following techniques would best detect an inventory fraud scheme?
Which of the following is true of bond financing, compared to common stock, when alJ other variables are equal?
According to IIA guidance on IT, which of the following plans would pair the identification of critical business processes with recovery time objectives?
Which of the following is true regarding reporting on the quality assurance and improvement program (QAIP)?
An internal audit team is trialing a data analytics tool. An extract from accounts payable was loaded into the tool and as a result, the tool flagged most of the transactions, thus yielding no meaningful results. After investigating, the audit team determined that the extract contained duplicate entries and spelling issues.
Which of the following should have been performed prior to loading the data into the analytics tool?
Which of the following descriptions of the internal control system are indicators that risks are managed effectively?
Existing controls promote compliance with applicable laws and regulations.
The control environment is designed to address all identified risks to the organization.
Key controls for significant risks to the organization remain consistent over time.
Monitoring systems are in place to alert management to unexpected events.
Which of the following standards would be most useful in evaluating the performance of a customer-service group?
Which of the following are typical audit considerations for a review of authentication?
Authentication policies and evaluation of controls transactions.
Management of passwords, independent reconciliation, and audit trail.
Control self-assessment tools used by management.
Independent verification of data integrity and accuracy.
To assess the effectiveness of an organization ' s privacy program, which of the following approaches should an internal auditor take?
To achieve conformance with the Global Internal Audit Standards, the chief audit executive must include which of the following activities in the quality assurance and improvement program (QAIP)?
What would an internal auditor do to ensure that a process to mitigate risk is in place for the organization ' s change management process?
Which of the following would be most likely found in an internal audit procedures manual?
The project charter is an output from which of the following?