Summer Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

IIA IIA-CIA-Part3 Internal Audit Function Exam Practice Test

Internal Audit Function Questions and Answers

Question 1

Internal auditors are reviewing change management processes involving the organization’s IT department.

Which of the following is a characteristic of an ineffective change management process that would impact the organization’s clients?

Options:

A.

Projects delays result in lost opportunities in emerging markets against the competition.

B.

Flaws in the network create the risk of premature press releases that describe details about upcoming products.

C.

Changing priorities result in resources being moved from planned IT projects to unplanned projects.

D.

Staffing shortages result in prolonged delays related to addressing concerns about services.

Question 2

Which of the following measures would best protect an organization from automated attacks whereby the attacker attempts to identify weak or leaked passwords in order to log into employees ' accounts?

Options:

A.

Requiring users to change their passwords every two years.

B.

Requiring two-step verification for all users

C.

Requiring the use of a virtual private network (VPN) when employees are out of the office.

D.

Requiring the use of up-to-date antivirus, security, and event management tools.

Question 3

Which of the following responsibilities would ordinary fall under the help desk function of an organization?

Options:

A.

Maintenance service items such as production support.

B.

Management of infrastructure services, including network management.

C.

Physical hosting of mainframes and distributed servers

D.

End-to -end security architecture design.

Question 4

Which of the following measures the operating success of a company for a given period of time?

Options:

A.

Liquidity ratios.

B.

Profitability ratios.

C.

Solvency ratios.

D.

Current ratios.

Question 5

A new clerk in the managerial accounting department applied the high-low method and computed the difference between the high and low levels of maintenance costs. Which type of maintenance costs did the clerk determine?

Options:

A.

Fixed maintenance costs.

B.

Variable maintenance costs.

C.

Mixed maintenance costs.

D.

Indirect maintenance costs.

Question 6

Which of the following devices best controls both physical and logical access to information systems?

Options:

A.

Plenum.

B.

Biometric lock.

C.

Identification card.

D.

Electromechanical lock.

Question 7

Which of the following statements is true regarding user-developed applications (UDAs)?

Options:

A.

UDAs are less flexible and more difficult to configure than traditional IT applications.

B.

Updating UDAs may lead to various errors resulting from changes or corrections.

C.

UDAs typically are subjected to application development and change management controls.

D.

Using UDAs typically enhances the organization ' s ability to comply with regulatory factors.

Question 8

Which of the following information security controls has the primary function of preventing unauthorized outside users from accessing an organization ' s data through the organization ' s network?

Options:

A.

Firewall.

B.

Encryption.

C.

Antivirus.

D.

Biometrics.

Question 9

Which of the following are likely indicators of ineffective change management?

    IT management is unable to predict how a change will impact interdependent systems or business processes.

    There have been significant increases in trouble calls or in support hours logged by programmers.

    There is a lack of turnover in the systems support and business analyst development groups.

    Emergency changes that bypass the normal control process frequently are deemed necessary.

Options:

A.

1 and 3 only

B.

2 and 4 only

C.

1, 2, and 4 only

D.

1, 2, 3, and 4

Question 10

Which of the following is a characteristic of using a hierarchical control structure?

Options:

A.

Less use of policies and procedures.

B.

Less organizational commitment by employees.

C.

Less emphasis on extrinsic rewards.

D.

Less employee’s turnover.

Question 11

Which of the following situations best applies to an organisation that uses a project, rather than a process, to accomplish its business activities?

Options:

A.

Clothing company designs, makes, and sells a new item.

B.

A commercial construction company is hired to build a warehouse.

C.

A city department sets up a new firefighter training program.

D.

A manufacturing organization acquires component parts from a contracted vendor

Question 12

When determining the level of physical controls required for a workstation, which of the following factors should be considered?

Options:

A.

Ease of use.

B.

Value to the business.

C.

Intrusion prevention.

D.

Ergonomic model.

Question 13

During a routine bank branch audit, the internal audit function observed that the sole security guard at the branch only worked part time. The chief audit executive (CAE) believed that this increased the risk of loss of property and life in the event of a robbery. The branch security manager informed the CAE that a full-time guard was not needed because the branch was in close proximity to a police station. Still, the CAE found this to be an unacceptable risk due to the recent increase in robberies in that area. Which of the following is the most appropriate next step for the CAE to take?

Options:

A.

Immediately report the issue to the board to ensure timely corrective actions are taken to resolve the risk

B.

Continue discussions with the security manager until he is persuaded and agrees to increase branch security

C.

Document the security manager’s decision to accept the risk in the audit workpapers

D.

Escalate the issue to the bank’s chief security officer to determine acceptability of the risk

Question 14

Which of the following documents would provide an internal auditor with information on the length of time to maintain documents after the completion of an engagement?

Options:

A.

Internal audit charter

B.

Annual internal audit plan

C.

Internal audit policies

D.

Quality assurance and improvement program

Question 15

A chief audit executive (CAE) joined an organization in the middle of the financial year. A risk-based annual audit plan has been approved by the board and is already underway. However, after discussions with key stakeholders, the CAE realizes that some significant key risk areas have not been covered in the original audit plan. How should the CAE respond?

Options:

A.

Commit to delivering the original annual audit plan as it has already been approved by the board

B.

Revise the plan to incorporate the newly identified risks, and communicate significant interim changes to senior management and the board for review and approval

C.

Ensure that the newly identified risks are included in the next year ' s annual audit plan

D.

Assign internal auditors to immediately perform assurance engagements in the areas where the new risks have been identified, due to their significance

Question 16

According to IIA guidance, which of the following would be a primary reason for an internal auditor to test the organization ' s IT contingency plan?

Options:

A.

To ensure that adequate controls exist to prevent any significant business interruptions.

B.

To identify and address potential security weaknesses within the system.

C.

To ensure that tests contribute to improvement of the program.

D.

To ensure that deficiencies identified by the audit are promptly addressed.

Question 17

According to IIA guidance, which of the following is a typical risk associated with the tender process and contracting stage of an organization ' s IT outsourcing life cycle?

Options:

A.

The process is not sustained and is not optimized as planned.

B.

There is a lack of alignment to organizational strategies.

C.

The operational quality is less than projected.

D.

There is increased potential for loss of assets.

Question 18

How do data analysis technologies affect internal audit testing?

Options:

A.

They improve the effectiveness of spot check testing techniques.

B.

They allow greater insight into high risk areas.

C.

They reduce the overall scope of the audit engagement,

D.

They increase the internal auditor ' s objectivity.

Question 19

International marketing activities often begin with:

Options:

A.

Standardization.

B.

Global marketing.

C.

Limited exporting.

D.

Domestic marketing.

Question 20

Which of the following management statements illustrates how natural bias can lead to poor decision making?

Options:

A.

" Although we previously agreed that we would launch a new product this year, we changed our minds and decided to terminate the launch. "

B.

" Due to the crisis that arose last week, we are not prepared to provide the board with an estimate of next year ' s revenue. "

C.

" We will continue manufacturing the same products in the same way that we always have, because this tradition has made our organization successful. "

D.

" We decided to postpone expanding into the new market because of high uncertainty at this time. "

Question 21

Which of the following controls is the most effective for ensuring confidentially of transmitted information?

Options:

A.

Firewall.

B.

Antivirus software.

C.

Passwords.

D.

Encryption.

Question 22

As part of internal audit ' s risk assessment, a chief audit executive is determining certain factors as part of planning the areas to audit within an organization that makes silicon chips. Which of the following would be considered a subjective factor as part of the risk assessment?

Options:

A.

The number of vendors able to meet the supply demand request from the organization

B.

The quality of the staff supervision of silicon chips produced by the organization

C.

The length of time since the last audit of the organization ' s manufacturing facilities

D.

The asset value of the silicon chips that the organization did not produce because of a shortage in raw materials

Question 23

Which of the following can be classified as debt investments?

Options:

A.

Investments in the capital stock of a corporation

B.

Acquisition of government bonds.

C.

Contents of an investment portfolio,

D.

Acquisition of common stock of a corporation

Question 24

Which of the following would most likely serve as a foundation for individual operational goats?

Options:

A.

Individual skills and capabilities.

B.

Alignment with organizational strategy.

C.

Financial and human resources of the unit.

D.

Targets of key performance indicators

Question 25

During the second half of the audit year, the chief audit executive (CAE) identified significant negative variances to the approved audit budget required to complete the internal audit plan. Which of the following actions should the CAE take?

Options:

A.

Revise the internal audit plan to reduce coverage of new strategic critical areas so that the approved budget can be met

B.

Reduce the scope of the remainder of the engagements in the internal audit plan to reduce overall costs

C.

Communicate to senior management and the board the risk of not being able to complete the audit plan

D.

Continue to complete the plan regardless of the budget variances, as the audit function is invaluable to sound corporate governance

Question 26

Which of the following is a characteristic of big data?

Options:

A.

Big data is being generated slowly due to volume.

B.

Big data must be relevant for the purposes of organizations.

C.

Big data comes from a single type of formal.

D.

Big data is always changing

Question 27

What relationship exists between decentralization and the degree, importance, and range of lower-level decision making?

Options:

A.

Mutually exclusive relationship.

B.

Direct relationship.

C.

Intrinsic relationship.

D.

Inverse relationship.

Question 28

An organization has an agreement with a third-party vendor to have a fully operational facility, duplicate of the original site and configured to the organization ' s needs, in order to quickly recover operational capability in the event of a disaster, Which of the following best describes this approach to disaster recovery planning?

Options:

A.

Cold recovery plan,

B.

Outsourced recovery plan.

C.

Storage area network recovery plan.

D.

Hot recovery plan

Question 29

What is the primary risk associated with an organization adopting a decentralized structure?

Options:

A.

Inability to adapt.

B.

Greater costs of control function.

C.

Inconsistency in decision making.

D.

Lack of resilience.

Question 30

In an organization with a poor control environment, which of the following indicators would help an internal audit function measure its ability to provide risk-based assurance?

Options:

A.

The value of potential cost savings, or prevented losses, identified per year

B.

The percentage of observations that can be linked to significant organizational risks

C.

The extent of data mining or data analytics used during assurance engagements

D.

The amount of time dedicated to organization-wide risk assessments

Question 31

Which of the following is an example of a nonfinancial internal failure quality cost?

Options:

A.

Decreasing gross profit margins over time.

B.

Foregone contribution margin on lost sales.

C.

Defective units shipped to customers.

D.

Excessive time to convert raw materials into finished goods.

Question 32

Which of the following is not included in the process of user authentication?

Options:

A.

Authorization.

B.

Identification.

C.

Verification.

D.

Validation.

Question 33

Which of the following actions illustrates the use of electronic data interchange?

Options:

A.

Sending an invoice automatically from the supplier to the customer in a standard format.

B.

Using an accounting software hosted on the cloud.

C.

Transferring money using mobile phones.

D.

Updating vendor master files using online real-time.

Question 34

Which of the following statements is true regarding user developed applications (UDAs) and traditional IT applications?

Options:

A.

UDAs arid traditional JT applications typically follow a similar development life cycle

B.

A UDA usually includes system documentation to illustrate its functions, and IT-developed applications typically do not require such documentation.

C.

Unlike traditional IT applications. UDAs typically are developed with little consideration of controls.

D.

IT testing personnel usually review both types of applications thoroughly to ensure they were developed properly.

Question 35

According to IIA guidance, which of the following steps are most important for an internal auditor to perform when evaluating an organization ' s social and environmental impact on the local community?

    Determine whether previous incidents have been reported, managed, and resolved.

    Determine whether a business contingency plan exists.

    Determine the extent of transparency in reporting.

    Determine whether a cost/benefit analysis was performed for all related projects.

Options:

A.

1 and 3.

B.

1 and 4.

C.

2 and 3.

D.

2 and 4.

Question 36

An organization uses the management-by-objectives method whereby employee performance is based on defined goals. Which of the following statements is true regarding this approach?

Options:

A.

It is particularly helpful to management when the organization is facing rapid change.

B.

It is a more successful approach when adopted by mechanistic organizations.

C.

It is mere successful when goal setting is performed not only by management, but by all team members, including lower-level staff.

D.

It is particularly successful in environments that are prone to having poor employer-employee relations.

Question 37

Which of the following assessments will assist in evaluating whether the internal audit function is consistently delivering quality engagements?

Options:

A.

Periodic assessments

B.

Ongoing monitoring

C.

Full external assessments

D.

Self-Assessment with Independent Validation (SAIV)

Question 38

Which of the following would be classified as IT general controls?

Options:

A.

Error listings.

B.

Distribution controls.

C.

Transaction logging.

D.

Systems development controls.

Question 39

Which of the following is most appropriate for the chief audit executive to keep in mind when establishing policies and procedures to guide the internal audit function?

Options:

A.

The nature of the internal audit function

B.

The size of the organization

C.

The size and maturity of the internal audit function

D.

The structure of the organization

Question 40

An internal audit uncovered high-risk issues that needed to be addressed by the organization. During the exit conference, the audit team discussed the high-risk issues with the manager responsible for addressing them. How should the chief audit executive respond if the manager agrees to correct the issues identified during the audit?

Options:

A.

Include in the report that management has agreed to address the issue and set a date for follow-up

B.

Include an assignment in the annual internal audit plan to perform a follow-up audit

C.

Discuss the audit observation with senior management

D.

Solicit input from management and create the action plan

Question 41

Which of the following bring-your-own-device (BYOD) practices is likely to increase the risk of infringement on local regulations, such as copyright or privacy laws?

Options:

A.

Not installing anti-malware software.

B.

Updating operating software in a haphazard manner.

C.

Applying a weak password for access to a mobile device.

D.

Jailbreaking a locked smart device.

Question 42

Which of the following IT strategies is most effective for responding to competitive pressures created by the marketplace?

Options:

A.

Promote closer linkage between organizational strategy and information.

B.

Provide users with greater online access to information systems.

C.

Enhance the functionality of application systems.

D.

Expand the use of automated controls.

Question 43

Management has decided to change the organizational structure from one that was previously decentralized to one that is now highly centralized. As such: which of the

following would be a characteristic of the now highly centralized organization?

Options:

A.

Top management does little monitoring of the decisions made at lower levels.

B.

The decisions made at the lower levels of management are considered very important.

C.

Decisions made at lower levels in the organizational structure are few.

D.

Reliance is placed on top management decision making by few of the organization ' s departments.

Question 44

An organization is projecting sales of 100,000 units, at a unit price of $12. Unit variable costs are $7. If fixed costs are $350,000, what is the projected total contribution margin?

Options:

A.

$350,000

B.

$500,000

C.

$850,000

D.

$1,200,000

Question 45

An internal auditor identified a database administrator with an incompatible dual role. Which of the following duties should not be performed by the identified administrator?

Options:

A.

Designing and maintaining the database.

B.

Preparing input data and maintaining the database.

C.

Maintaining the database and providing its security,

D.

Designing the database and providing its security

Question 46

Which of the following lists best describes the classification of manufacturing costs?

Options:

A.

Direct materials, indirect materials, raw materials.

B.

Overhead costs, direct labor, direct materials.

C.

Direct materials, direct labor, depreciation on factory buildings.

D.

Raw materials, factory employees ' wages, production selling expenses.

Question 47

Which of the following IT layers would require the organization to maintain communication with a vendor in a tightly controlled and monitored manner?

Options:

A.

Applications

B.

Technical infrastructure.

C.

External connections.

D.

IT management

Question 48

Which of the following would be the best method to collect information about employees ' job satisfaction?

Options:

A.

Online surveys sent randomly to employees.

B.

Direct onsite observations of employees.

C.

Town hall meetings with employees.

D.

Face-to-face interviews with employees.

Question 49

Which of the following best describes the concept of relevant cost?

Options:

A.

A future cost that is the same among alternatives.

B.

A future cost that differs among alternatives.

C.

A past cost that is the same among alternatives.

D.

A past cost that differs among alternatives.

Question 50

Which of the following performance measures includes both profits and investment base?

Options:

A.

Residual income

B.

A flexible budget

C.

Variance analysis.

D.

A contribution margin income statement by segment.

Question 51

When auditing databases, which of the following risks would an Internal auditor keep In mind In relation to database administrators?

Options:

A.

The risk that database administrators will disagree with temporarily preventing user access to the database for auditing purposes.

B.

The risk that database administrators do not receive new patches from vendors that support database software in a timely fashion.

C.

The risk that database administrators set up personalized accounts for themselves, making the audit time consuming.

D.

The risk that database administrators could make hidden changes using privileged access.

Question 52

Employees at an events organization use a particular technique to solve problems and improve processes. The technique consists of five steps: define, measure, analyze,

improve, and control. Which of the following best describes this approach?

Options:

A.

Six Sigma,

B.

Quality circle.

C.

Value chain analysis.

D.

Theory of constraints.

Question 53

Which of the following is an effective preventive control for data center security?

Options:

A.

Motion detectors.

B.

Key card access to the facility.

C.

Security cameras.

D.

Monitoring access to data center workstations

Question 54

Import quotas that limit the quantities of goods that a domestic subsidiary can buy from its foreign parent company represent which type of barrier to the parent company?

Options:

A.

Political.

B.

Financial.

C.

Social.

D.

Tariff.

Question 55

Organizational activities that complement each other and create a competitive advantage are called a:

Options:

A.

Merger.

B.

Strategic fit.

C.

Joint venture.

D.

Strategic goal.

Question 56

Which of the following assumptions regarding cost-volume-profit analysis is true?

Options:

A.

Costs are affected by changes in activity only.

B.

The behavior of costs and revenues is inverse.

C.

When more than one type of product is sold, the sales mix changes.

D.

Only variable costs have to be classified accurately.

Question 57

An organization selected a differentiation strategy to compete at the business level. Which of the following structures best fits this strategic choice?

Options:

A.

Functional structure.

B.

Divisional structure.

C.

Mechanistic structure.

D.

Functional structure with cross-functional teams.

Question 58

Which of the following is the most appropriate action an internal auditor would perform during an audit of his organization ' s IT change management process?

Options:

A.

Validate that only authorized personnel can migrate changes into the production environment.

B.

Perform a risk assessment to determine the likelihood that risk could occur due to insufficient patch application.

C.

Publish a schedule that lists all approved changes and planned implementation dates.

D.

Update change management processes on a consistent basis to keep up with changing technologies.

Question 59

Which of the following types of accounts must be closed at the end of the period?

Options:

A.

Income statement accounts.

B.

Balance sheet accounts.

C.

Permanent accounts.

D.

Real accounts.

Question 60

Which of the following best describes the job design strategy used by the chief audit executive that encourages internal auditors to manage engagements from the beginning to the end?

Options:

A.

Job sharing.

B.

Job shadowing.

C.

Job enrichment.

D.

Job rotation.

Question 61

Which of the following local area network physical layouts is subject to the greatest risk of failure if one device fails?

Options:

A.

Star network.

B.

Bus network.

C.

Token ring network.

D.

Mesh network.

Question 62

Which of the following sites would an Internet service provider most likely use to restore operations after its servers were damaged by a natural disaster?

Options:

A.

On site.

B.

Cold site.

C.

Hot site.

D.

Warm site

Question 63

An organization has instituted a bring-your-own-device (BYOD) work environment. Which of the following policies best addresses the increased risk to the organization ' s network incurred by this environment?

Options:

A.

Limit the use of the employee devices for personal use to mitigate the risk of exposure to organizational data.

B.

Ensure that relevant access to key applications is strictly controlled through an approval and review process.

C.

Institute detection and authentication controls for all devices used for network connectivity and data storage.

D.

Use management software scan and then prompt parch reminders when devices connect to the network

Question 64

An organization that soils products to a foreign subsidiary wants to charge a price that wilt decrease import tariffs. Which of the following is the best course of action for the organization?

Options:

A.

Decrease the transfer price

B.

Increase the transfer price

C.

Charge at the arm ' s length price

D.

Charge at the optimal transfer price

Question 65

Which audit approach should be employed to test the accuracy of information housed in a database on an un-networked computer?

Options:

A.

Submit batches of test transactions through the current system and verify with expected results.

B.

Use a test program to simulate the normal data entering process.

C.

Select a sample of records from the database and ensure it matches supporting documentation.

D.

Evaluate compliance with the organization ' s change management process.

Question 66

What is the primary purpose of data and systems backup?

Options:

A.

To restore all data and systems immediately after the occurrence of an incident.

B.

To set the maximum allowable downtime to restore systems and data after the occurrence of an incident.

C.

To set the point in time to which systems and data must be recovered after the occurrence of an incident.

D.

To restore data and systems to a previous point in time after the occurrence of an incident

Question 67

Which of the following employee survey questions would be most effective to measure organizational commitment?

Options:

A.

How would you rate the development and training opportunities you receive at the organization?

B.

How satisfied are you with your manager ' s attitude and behavior?

C.

How content are you with the amount of pay you receive for your work?

D.

How likely are you to recommend the organization as an employer to your friends?

Question 68

Which type of bond sells at a discount from face value, then increases in value annually until it reaches maturity and provides the owner with the total payoff?

Options:

A.

High-yield bonds

B.

Commodity-backed bonds

C.

Zero-coupon bonds

D.

Junk bonds

Question 69

Which stage of group development is characterized by a decrease in conflict and hostility among group members and an increase in cohesiveness?

Options:

A.

Forming stage.

B.

Norming stage.

C.

Performing stage.

D.

Storming stage.

Question 70

Which of the following data analytics techniques is used to identify patterns among groups of data elements?

Options:

A.

Stratification of numeric values.

B.

Joining different data sources.

C.

Duplicate testing.

D.

Classification.

Question 71

Which of the following statements is accurate regarding the use of Secure Sockets Layer (SSL) as a control?

Options:

A.

It supports the authentication of information sent to a server.

B.

It prevents phishing attacks that redirect users to malicious sites.

C.

It prevents malware infections.

D.

It identifies each client-server session using temporary tokens.

Question 72

The internal audit activity has identified accounting errors that resulted in the organization overstating its net income for the fiscal year. Which of the following is the most likely cause of this overstatement?

Options:

A.

Beginning inventory was overstated for the year.

B.

Cost of goods sold was understated for the year.

C.

Ending inventory was understated for the year.

D.

Cost of goods sold was overstated for the year.

Question 73

A multinational organization allows its employees to access work email via personal smart devices. However, users are required to consent to the installation of mobile device management (MDM) software that will remotely wipe data in case of theft or other incidents. Which of the following should the organization ensure in exchange for the employees ' consent?

Options:

A.

That those employees who do not consent to MDM software cannot have an email account.

B.

That personal data on the device cannot be accessed and deleted by system administrators.

C.

That monitoring of employees ' online activities is conducted in a covert way to avoid upsetting them.

D.

That employee consent includes appropriate waivers regarding potential breaches to their privacy.

Question 74

Which type of bond sells at & discount from face value, then increases in value annually until it reaches maturity and provides the owner with the total payoff?

Options:

A.

High-yield bonds

B.

Commodity-backed bonds

C.

Zero coupon bonds

D.

Junk bonds

Question 75

Which of the following is an example of a contingent liability that a company should record?

Options:

A.

A potential assessment of additional income tax.

B.

Possible product warranty costs.

C.

The threat of a lawsuit by a competitor.

D.

The remote possibility of a contract breach.

Question 76

Which of the following purchasing scenarios would gain the greatest benefit from implementing electronic data interchange?

Options:

A.

A time-sensitive just-in-time purchase environment.

B.

A large volume of custom purchases.

C.

A variable volume sensitive to material cost.

D.

A currently inefficient purchasing process.

Question 77

Which of the following statements about assurance maps is true?

Options:

A.

They help identify gaps and duplications in an organization’s assurance coverage

B.

They allow the board to coordinate activities of internal and external assurance providers

C.

They help identify which assurance provider is responsible for performing each audit listed in the annual internal audit plan

D.

They allow internal auditors to map competencies and specialty areas of the assurance providers in an organization

Question 78

Which of the following attributes of data analytics relates to the growing number of sources from which data is being generated?

Options:

A.

Volume.

B.

Velocity.

C.

Variety.

D.

Veracity.

Question 79

A financial institution receives frequent and varied email requests from customers for funds to be wired out of their accounts. Which verification activity would best help the institution avoid falling victim to phishing?

Options:

A.

Reviewing the customer ' s wire activity to determine whether the request is typical.

B.

Calling the customer at the phone number on record to validate the request.

C.

Replying to the customer via email to validate the sender and request.

D.

Reviewing the customer record to verify whether the customer has authorized wire requests from that email address.

Question 80

Which of the following statements Is true regarding the use of centralized authority to govern an organization?

Options:

A.

Fraud committed through collusion is more likely when authority is centralized.

B.

Centralized managerial authority typically enhances certainty and consistency within an organization.

C.

When authority is centralized, the alignment of activities to achieve business goals typically is decreased.

D.

Using separation of duties to mitigate collusion is reduced only when authority is centralized.

Question 81

The internal auditor concluded there was a high likelihood that a significant wind farm development, worth $200 million, would be delayed from its approved schedule. As a result, electricity production would not start on time, leading to considerable financial penalties. Which of the following should be added to the observation to support its clarity and completeness?

Options:

A.

The effect of the observation

B.

The criteria of the observation

C.

The condition of the observation

D.

The cause of the observation

Question 82

Which of the following borrowing options is an unsecured loan?

Options:

A.

Second-mortgage financing from a bank.

B.

An issue of commercial paper.

C.

Pledged accounts receivable.

D.

Asset-based financing.

Question 83

Which of the following is most appropriately placed in the financing section of an organization ' s cash budget?

Options:

A.

Collections from customers

B.

Sale of securities.

C.

Purchase of trucks.

D.

Payment of debt, including interest

Question 84

According to Maslow’s hierarchy of needs theory, which of the following best describes a strategy where a manager offers an assignment to a subordinate specifically to support his professional growth and future advancement?

Options:

A.

Esteem by colleagues

B.

Self-fulfillment

C.

Sense of belonging in the organization

D.

Job security

Question 85

An organization filters data packets from public networks to send to an internal private network.

Which of the following devices would accomplish this?

Options:

A.

A router.

B.

A switch.

C.

A hub.

D.

A proxy gateway.

Question 86

Which of the following roles would be least appropriate for the internal audit activity to undertake with regard to an organization ' s corporate social responsibility program?

Options:

A.

Consult on project design and implementation of the CSR program.

B.

Serve as an advisor on internal controls related to CSR.

C.

Identify and prioritize the CSR issues that are important to the organization.

D.

Evaluate the effectiveness of the organization ' s CSR efforts.

Question 87

When executive compensation is based on the organization ' s financial results, which of the following situations is most likely to arise?

Options:

A.

The organization reports inappropriate estimates and accruals due to poof accounting controls.

B.

The organization uses an unreliable process forgathering and reporting executive compensation data.

C.

The organization experiences increasing discontent of employees, if executives are eligible for compensation amounts that are deemed unreasonable.

D.

The organization encourages employee behavior that is inconsistent with the interests of relevant stakeholders.

Question 88

Which of the following IT professionals is responsible for providing maintenance to switches and routers to keep IT systems running as intended?

Options:

A.

Data center operations manager

B.

Response and support team.

C.

Database administrator,

D.

Network administrator

Question 89

A organization finalized a contract in which a vendor is expected to design, procure, and construct a power substation for $3,000,000. In this scenario, the organization agreed to which of the following types of contracts?

Options:

A.

A cost-reimbursable contract.

B.

A lump-sum contract.

C.

A time and material contract.

D.

A bilateral contract.

Question 90

The internal audit function of a manufacturing organization is conducting an advisory engagement. The engagement team identifies a gap in procedures: there is no documentation for the activities that take place when new site construction projects are completed. In practice, these activities include the transfer of assets from the development department to the production department. What is the most appropriate action for the engagement team?

Options:

A.

Circulate a risk and control questionnaire to identify construction process risks

B.

Facilitate design of a checklist that can be used during asset transfer

C.

Carry out a root cause analysis to identify the underlying reasons of the process gap

D.

Allocate additional resources to the production department to better handle the new assets

Question 91

Which of the following is the best example of IT governance controls?

Options:

A.

Controls that focus on segregation of duties, financial, and change management,

B.

Personnel policies that define and enforce conditions for staff in sensitive IT areas.

C.

Standards that support IT policies by more specifically defining required actions

D.

Controls that focus on data structures and the minimum level of documentation required

Question 92

According to Herzberg ' s Two-Factor Theory of Motivation, which of the following is a factor mentioned most often by satisfied employees?

Options:

A.

Relationship with supervisor

B.

Salary

C.

Security.

D.

Achievement

Question 93

A company that uses the accrual basis of accounting can recognize revenue under which of the following conditions?

Options:

A.

When cash is received as payment for a service.

B.

When the receivable is recognized.

C.

When a check is received as payment for a good that has been ordered.

D.

When a good is provided or a service is performed.

Question 94

Which of the following attributes of data are cybersecurity controls primarily designed to protect?

Options:

A.

Veracity, velocity, and variety.

B.

Integrity, availability, and confidentiality.

C.

Accessibility, accuracy, and effectiveness.

D.

Authorization, logical access, and physical access.

Question 95

Which of the following is a key performance indicator of the efficiency of the internal audit function?

Options:

A.

The number of audits completed

B.

The number of significant audit observations

C.

The percentage of recommendations implemented

D.

The number of training hours per auditor

Question 96

Which of the following situations best applies to an organization that uses a project, rather than a process, to accomplish its business activities?

Options:

A.

A clothing company designs, makes, and sells a new item

B.

A commercial construction company is hired to build a warehouse

C.

A city department sets up a new firefighter training program

D.

A manufacturing organization acquires component parts from a contracted vendor

Question 97

When management uses the absorption costing approach, fixed manufacturing overhead costs are classified as which of the following types of costs?

Options:

A.

Direct product costs

B.

Indirect costs

C.

Direct period costs

D.

Indirect period costs

Question 98

An organization sells 1,000 shares of its treasury stock at $15 per share previously acquired at $10 per share.

Which of the following statements is true?

Options:

A.

The organization should record a $5,000 gain on sale of treasury stock.

B.

The organization should record $15,000 as a debit to treasury stock.

C.

The organization should record $5,000 as a credit to paid-in capital.

D.

The organization should record a $10,000 debit to paid-capital account.

Question 99

Which of the following is generally considered a best practice related to data backup?

    Performing full system backups on weekdays.

    Storing system backups onsite in a secured location.

    Testing system backup media periodically.

    Verifying backup media can be retrieved within seven years.

Options:

A.

2 only.

B.

3 only.

C.

1, 2, and 3 only.

D.

2, 3, and 4 only.

Question 100

Which of the following best describes owner ' s equity?

Options:

A.

Assets minus liabilities.

B.

Total assets.

C.

Total liabilities.

D.

Owners contribution plus drawings.

Question 101

According to IIA guidance, which of the following statements is true with regard to workstation computers that access company information stored on the network?

Options:

A.

Individual workstation computer controls are not as important as companywide server controls

B.

Particular attention should be paid to housing workstations away from environmental hazards

C.

Cybersecurity issues can be controlled at an enterprise level, making workstation-level controls redundant

D.

With security risks near an all-time high, workstations should not be connected to the company network

Question 102

Refer to the exhibit. If the profit margin of an organization decreases, and all else remains equal, which of the following describes how the “Funds Needed” line in the graph below will shift?

Options:

A.

The “Funds Needed” line will remain pointed upward, but will become less steep.

B.

The “Funds Needed” line will remain pointed upward, but will become more steep.

C.

The “Funds Needed” line will point downward with a minimal slope.

D.

The “Funds Needed” line will point downward with an extreme slope.

Question 103

During her annual performance review, a sales manager admits that she experiences significant stress due to her job but stays with the organization because of the high bonuses she earns. Which of the following best describes her primary motivation to remain in the job?

Options:

A.

Intrinsic reward.

B.

Job enrichment

C.

Extrinsic reward.

D.

The hierarchy of needs.

Question 104

Which of the following physical access controls is most likely to be based on the " something you have " concept?

Options:

A.

A retina characteristics reader.

B.

A PIN code reader.

C.

A card-key scanner.

D.

A fingerprint scanner.

Question 105

When granting third parties temporary access to an entity ' s computer systems, which of the following is the most effective control?

Options:

A.

Access is approved by the supervising manager.

B.

User accounts specify expiration dates and are based on services provided.

C.

Administrator access is provided for a limited period.

D.

User accounts are deleted when the work is completed.

Question 106

Which of the following is the most appropriate beginning step of a work program for an assurance engagement involving smart devices?

Options:

A.

Train all employees on bring-your-own-device (BYOD) policies.

B.

Understand what procedures are in place for locking lost devices

C.

Obtain a list of all smart devices in use

D.

Test encryption of all smart devices

Question 107

Which of the following best describes the benefit of an organization adopting a business continuity and disaster recovery plan for responding to natural disasters?

Options:

A.

It prevents economic impact to the organization.

B.

It enables the organization to predict when a natural disaster will occur.

C.

It reduces the likelihood that events will disrupt operating activities.

D.

It eliminates the threat to the organization.

Question 108

The chief audit executive (CAE) has embraced a total quality management approach to improving the internal audit activity ' s (lAArs) processes. He would like to reduce the time to complete audits and improve client ratings of the IAA. Which of the following staffing approaches is the CAE most likely lo select?

Options:

A.

Assign a team with a trained audit manager to plan each audit and distribute field work tasks to various staff auditors.

B.

Assign a team of personnel who have different specialties to each audit and empower Team members to participate fully in key decisions

C.

Assign a team to each audit, designate a single person to be responsible for each phase of the audit, and limit decision making outside of their area of responsibility.

D.

Assign a team of personnel who have similar specialties to specific engagements that would benefit from those specialties and limit Key decisions to the senior person.

Question 109

According to IIA guidance, which of the following would be the best first stop to manage risk when a third party is overseeing the organization ' s network and data?

Options:

A.

Creating a comprehensive reporting system for vendors to demonstrate their ongoing due diligence in network operations.

B.

Drafting a strong contract that requires regular vendor control reports end a right-to-audit clause.

C.

Applying administrative privileges to ensure right to access controls are appropriate.

D.

Creating a standing cyber-security committee to identify and manage risks related to data security

Question 110

Which of the following accurately describes a difference between phishing and spear phishing?

Options:

A.

Phishing targets individuals indiscriminately, while spear phishing targets specific individuals.

B.

Phishing uses emails in attacks, while spear phishing uses other methods.

C.

Phishing requires unauthorized access to a system, while spear phishing requires successful social engineering attempts.

D.

Phishing aims to acquire personal information, while spear phishing aims to send unsolicited notifications or advertisements.

Question 111

In accounting, which of the following statements is true regarding the terms debit and credit?

Options:

A.

Debit indicates the right side of an account and credit the left side

B.

Debit means an increase in an account and credit means a decrease.

C.

Credit indicates the right side of an account and debit the left side.

D.

Credit means an increase in an account and debit means a decrease

Question 112

An internal auditor has requested the organizational chart in order to evaluate the control environment of an organization. Which of the following is a disadvantage of using the organizational chart?

Options:

A.

The organizational chart shows only formal relationships.

B.

The organizational chart shows only the line of authority.

C.

The organizational chart shows only the senior management positions.

D.

The organizational chart is irrelevant when testing the control environment.

Question 113

Which of the following is an example of a physical control?

Options:

A.

Providing fire detection and suppression equipment

B.

Establishing a physical security policy and promoting it throughout the organization

C.

Performing business continuity and disaster recovery planning

D.

Keeping an offsite backup of the organization ' s critical data

Question 114

The board and senior management agree to outsource the internal audit function. Which of the following is true regarding the company’s quality assurance and improvement program (QAIP)?

Options:

A.

The organization is responsible for maintaining an effective QAIP

B.

The organization is responsible for the internal assessment of the QAIP

C.

The service provider is responsible for the external assessment of the QAIP every three years

D.

The QAIP should be postponed until the organization insources or cosources the internal audit function

Question 115

According to the International Professional Practices Framework, internal auditors who are assessing the adequacy of organizational risk management processes should not:

Options:

A.

Recognize that organizations use different techniques for managing risk.

B.

Seek assurance that the key objectives of the risk management processes are being met.

C.

Determine and accept the level of risk for the organization.

D.

Treat the evaluation of risk management processes differently from the risk analysis used to plan audit engagements.

Question 116

Which of the following is an example of a phishing attack?

Options:

A.

An organization’s website becomes flooded with malicious traffic on the first day of the online shopping season, causing the website to crash and preventing customers from purchasing deals online

B.

The employees of a retail organization responded to emails with a link to malware that enabled a hacker to access the point-of-sale system and obtain customers’ credit card information

C.

An organization’s employees clicked on a link that allowed a worm to infiltrate and encrypt the organization’s operating system, rendering it unusable. A group of hackers is demanding payment to unlock the encryption

D.

A group of online activists hacked into the private email and confidential records of the local police department and released the information online to expose the corrupt practices of the department

Question 117

Which of the following describes the most appropriate set of tests for auditing a workstation ' s logical access controls?

Options:

A.

Review the list of people with access badges to the room containing the workstation and a log of those who accessed the room.

B.

Review the password length, frequency of change, and list of users for the workstation ' s login process.

C.

Review the list of people who attempted to access the workstation and failed, as well as error messages.

D.

Review the passwords of those who attempted unsuccessfully to access the workstation and the log of their activity

Question 118

Which of the following is a characteristic of an emerging industry?

Options:

A.

Established strategy of players.

B.

Low number of new firms.

C.

High unit costs.

D.

Technical expertise.

Question 119

When examining; an organization ' s strategic plan, an internal auditor should expect to find which of the following components?

Options:

A.

Identification of achievable goals and timelines

B.

Analysis of the competitive environment.

C.

Plan for the procurement of resources

D.

Plan for progress reporting and oversight.

Question 120

Management is pondering the following question:

" How does our organization compete? "

This question pertains to which of the following levels of strategy?

Options:

A.

Functional-level strategy

B.

Corporate-level strategy.

C.

Business-level strategy,

D.

DepartmentsHevet strategy

Question 121

Listening effectiveness is best increased by:

Options:

A.

Resisting both internal and external distractions.

B.

Waiting to review key concepts until the speaker has finished talking.

C.

Tuning out messages that do not seem to fit the meeting purpose.

D.

Factoring in biases in order to evaluate the information being given.

Question 122

Which of the following is a project planning methodology that involves a complex series of required simulations to provide information about schedule risk?

Options:

Question 123

The first step in determining product price is:

Options:

A.

Determining the cost of the product.

B.

Developing pricing objectives.

C.

Evaluating prices set by the competitors.

D.

Selecting a pricing method.

Question 124

An internal auditor reviews consolidated financial statements for a group of organizations.

Which of the following risks should the auditor consider?

Options:

A.

The statements may conceal poor performance of a subsidiary within the group.

B.

The statements will not reflect business areas under common control.

C.

The statements will not indicate total wealth controlled by the parent company.

D.

The statements may be misleading due to inclusion of transactions between members of the group.

Question 125

An internal auditor is auditing their organization’s termination process. A primary objective of this engagement is to verify that exit interviews were conducted for all terminated employees over the last two years. The auditor discovered that not all employees received exit interviews.

Which of the following risks could this lead to?

Options:

A.

The risk of employee turnover.

B.

The risk of noncompliance with a local labor law.

C.

The risk of incorrect severance payments.

D.

The risk of a confidentiality breach.

Question 126

According to IIA guidance on IT, which of the following best describes a logical access control?

Options:

A.

Require complex passwords to be established and changed quarterly

B.

Require swipe cards to control entry into secure data centers.

C.

Monitor access to the data center with closed circuit camera surveillance.

D.

Maintain current role definitions to ensure appropriate segregation of duties

Question 127

According to the Standards, the internal audit activity must evaluate risk exposures relating to which of the following when examining an organization ' s risk management process?

    Organizational governance.

    Organizational operations.

    Organizational information systems.

    Organizational structure.

Options:

A.

1 and 3 only

B.

2 and 4 only

C.

1, 2, and 3 only

D.

1, 2, and 4 only

Question 128

Which of the following is a role of the board of directors in the governance process?

Options:

A.

Conduct periodic assessments of the organization ' s governance systems.

B.

Obtain assurance concerning the effectiveness of the organization ' s governance systems.

C.

Implement an effective system of internal controls to support the organization ' s governance systems.

D.

Review and approve operational goals and objectives.

Question 129

Which of the following is the best example of a compliance risk that is likely to arise when adopting a bring-your-own-device (BYOD) policy?

Options:

A.

The risk that users try to bypass controls and do not install required software updates

B.

The risk that smart devices can be lost or stolen due to their mobile nature

C.

The risk that an organization intrusively monitors personal information stored on smart devices

D.

The risk that proprietary information is not deleted from the device when an employee leaves

Question 130

Which of the following statements is true regarding data backup?

Options:

A.

System backups should always be performed in real-time.

B.

Backups should be stored in a secured location onsite for easy access.

C.

The tape rotation schedule affects how long data is retained.

D.

Backup media should be restored only in case of a hardware or software failure.

Question 131

Which of the following best describes a potential benefit of using data analyses?

Options:

A.

It easily aligns with existing internal audit competencies to reduce expenses

B.

It provides a more holistic view of the audited area.

C.

Its outcomes can be easily interpreted into audit: conclusions.

D.

Its application increases internal auditors ' adherence to the Standards

Question 132

Which of the following data analytics methods involves analyzing event trends to determine what happened?

Options:

A.

Diagnostic analytics.

B.

Descriptive analytics.

C.

Predictive analytics.

D.

Prescriptive analytics.

Question 133

Which of the following conflict resolution methods should be applied when the intention of the parties is to solve the problem by clarifying differences and attaining everyone ' s objectives?

Options:

A.

Accommodating.

B.

Compromising.

C.

Collaborating.

D.

Competing.

Question 134

Which of the following statements regarding the necessary resources to achieve the internal audit plan is true?

Options:

A.

Ultimate oversight and responsibility for the internal audit function can be outsourced

B.

Relying upon the work of other assurance providers decreases the efficiency with which to retain auditors with high knowledge and experience

C.

Internal audit resources can be obtained entirely from outside the organization

D.

Co-sourcing, where experts from outside the organization perform specialized work, must be used by chief audit executives instead of outsourcing

Question 135

What kind of strategy would be most effective for an organization to adopt in order to Implement a unique advertising campaign for selling identical product lines across all of its markets?

Options:

A.

Export strategy.

B.

Transnational strategy

C.

Multi-domestic strategy

D.

Globalization strategy

Question 136

An organization decided to install a motion detection system in its warehouse to protect against after-hours theft. According to the COSO enterprise risk management framework, which of the following best describes this risk management strategy?

Options:

A.

Avoidance.

B.

Reduction.

C.

Elimination.

D.

Sharing.

Question 137

Which of the following is a distinguishing feature of managerial accounting, which is not applicable to financial accounting?

Options:

A.

Managerial accounting uses double-entry accounting and cost data.

B.

Managerial accounting uses general accepted accounting principles.

C.

Managerial accounting involves decision making based on quantifiable economic events.

D.

Managerial accounting involves decision making based on predetermined standards.

Question 138

Which of the following engagement observations would provide the least motivation for management to amend or replace an existing cost accounting system?

Options:

A.

The distorted unit cost of a service is 50 percent lower than the true cost, while the true cost is 50 percent higher than the competition ' s cost.

B.

The organization is losing $1,000,000 annually because it incorrectly outsourced an operation based on information from its current system.

C.

The cost of rework, hidden by the current system, is 50 percent of the total cost of all services.

D.

Fifty percent of total organizational cost has been allocated on a volume basis.

Question 139

An internal auditor discovered that the organization was not in full compliance with a regulatory labeling requirement for one of its products. The responsible manager indicated that the current product labeling has been in use for several years without any problems. If discovered, this regulatory breach could result in significant fines for the organization. What should be the chief audit executive ' s next course of action?

Options:

A.

Discuss the matter with the CEO and other senior management

B.

Recommend that disciplinary action be taken against the manager for exposing the company to such risk

C.

Communicate to the board the current situation, including the risk exposure to the company

D.

Take on the initiative of implementing corrective actions to mitigate the identified risks

Question 140

Which mindset promotes the most comprehensive risk management strategy?

Options:

A.

Increase shareholder value.

B.

Maximize market share.

C.

Improve operational efficiency.

D.

Mitigate losses.

Question 141

At what point during the systems development process should an internal auditor verify that the new application ' s connectivity to the organization ' s other systems has been established correctly?

Options:

A.

Prior to testing the new application.

B.

During testing of the new application.

C.

During implementation of the new application.

D.

During maintenance of the new application.

Question 142

The cost to enter a foreign market would be highest in which of the following methods of global expansion?

Options:

A.

Joint ventures.

B.

Licensing.

C.

Exporting.

D.

Overseas production.

Question 143

Which of the following controls would an internal auditor consider the most relevant to reduce risks of project cost overruns?

Options:

A.

Scope change requests are reviewed and approved by a manager with a proper level of authority.

B.

Cost overruns are reviewed and approved by a control committee led by the project manager.

C.

There is a formal quality assurance process to review scope change requests before they are implemented

D.

There is a formal process to monitor the status of the project and compare it to the cost baseline

Question 144

An organization uses the management-by-objectives method, whereby employee performance is based on defined goals. Which of the following statements is true regarding this approach?

Options:

A.

It is particularly helpful to management when the organization is facing rapid change

B.

It is a more successful approach when adopted by mechanistic organizations

C.

It is more successful when goal-setting is performed not only by management, but by all team members, including lower-level staff

D.

It is particularly successful in environments that are prone to having poor employer-employee relations

Question 145

An organization decided to reorganize into a flatter structure. Which of the following changes would be expected with this new structure?

Options:

A.

Lower costs.

B.

Slower decision making at the senior executive level.

C.

Limited creative freedom in lower-level managers.

D.

Senior-level executives more focused on short-term, routine decision making

Question 146

Which of the following statements is accurate when planning for an external quality assurance assessment of the internal audit function?

Options:

A.

The external assessment would include the audit function’s compliance with laws and regulations

B.

The selected qualified assessor can be from the organization’s shared services team

C.

The external assessment team members must work for an accounting firm

D.

The frequency of the performance of assessments should be considered by the assessor

Question 147

What is the primary purpose of an integrity control?

Options:

A.

To ensure data processing is complete, accurate, and authorized

B.

To ensure data being processed remains consistent and intact

C.

To monitor the effectiveness of other controls

D.

To ensure the output aligns with the intended result

Question 148

Which of the following statements about matrix organizations is false?

Options:

A.

In a matrix organization, conflict between functional and product managers may arise.

B.

In a matrix organization, staff under dual command is more likely to suffer stress at work.

C.

Matrix organizations offer the advantage of greater flexibility.

D.

Matrix organizations minimize costs and simplify communication.

Question 149

A capital investment project will have a higher net present value, everything else being equal, if it has:

Options:

A.

A higher initial investment level.

B.

A higher discount rate.

C.

Cash inflows that are larger in the later years of the life of the project.

D.

Cash inflows that are larger in the earlier years of the life of the project.

Question 150

An internal auditor is using data analytics to focus on high-risk areas during an engagement. The auditor has obtained data and is working to eliminate redundancies in the data. Which of the following statements is true regarding this scenario?

Options:

A.

The auditor is normalizing data in preparation for analyzing it.

B.

The auditor is analyzing the data in preparation for communicating the results.

C.

The auditor is cleaning the data in preparation for determining which processes may be involved.

D.

The auditor is reviewing the data prior to defining the question.

Question 151

Which of the following principles s shared by both hierarchies and open organizational structures?

1. A superior can delegate the authority to make decisions but cannot delegate the ultimate responsibility for the results of those decisions.

2. A supervisor ' s span of control should not exceed seven subordinates.

3. Responsibility should be accompanied by adequate authority.

4. Employees at all levels should be empowered to make decisions.

Options:

A.

1 and 3 only

B.

1 and 4 only

C.

2 and 3 only

D.

3 and 4 only

Question 152

A holding company set up a centralized group technology department, using a local area network with a mainframe computer to process accounting information for all companies within the group. An internal auditor would expect to find all of the following controls within the technology department except:

Options:

A.

Adequate segregation of duties between data processing controls and file security controls.

B.

Documented procedures for remote job entry and for local data file retention.

C.

Emergency and disaster recovery procedures and maintenance agreements in place to ensure continuity of operations.

D.

Established procedures to prevent and detect unauthorized changes to data files.

Question 153

An internal auditor discusses user-defined default passwords with the database administrator. Such passwords will be reset as soon as the user logs in for the first time, but the initial value of the password is set as " 123456. " Which of the following are the auditor and the database administrator most likely discussing in this situation?

Options:

A.

Whether it would be more secure to replace numeric values with characters.

B.

What happens in the situations where users continue using the initial password.

C.

What happens in the period between the creation of the account and the password change.

D.

Whether users should be trained on password management features and requirements.

Question 154

The project manager responsible for overseeing a controversial project decides to accept the risks associated with the project launch. These risks might have a significant impact on the organization meeting its environmental sustainability goals. Which of the following is the most appropriate next step for the chief audit executive to take in response to the decision?

Options:

A.

Educate employees working on the project launch about the risks

B.

Notify the board about the significant risks the organization might face

C.

Communicate the risks to senior management

D.

Instruct the project manager to stop the controversial project development

Question 155

Which of the following scenarios best illustrates a spear phishing attack?

Options:

A.

Numerous and consistent attacks on the company ' s website caused the server to crash and service was disrupted.

B.

A person posing as a representative of the company ' s IT help desk called several employees and played a generic prerecorded message requesting password data.

C.

A person received a personalized email regarding a golf membership renewal, and he clicked a hyperlink to enter his credit card data into a fake website.

D.

Many users of a social network service received fake notifications of a unique opportunity to invest in a new product

Question 156

Which of the following is a necessary action for an internal audit function if senior management chooses not to take action to remediate the finding and accepts the risk?

Options:

A.

The chief audit executive (CAE) must discuss this disagreement with senior management and communicate this information to external stakeholders

B.

The CAE must include this disagreement in the final audit report and conclude the engagement

C.

The CAE must make a judgment regarding the prudence of that decision and report to the board if needed

D.

The CAE must establish a follow-up process to monitor the acceptable risk level as part of the engagement

Question 157

Which of the following is an indicator of liquidity that is more dependable than working capital?

Options:

A.

Acid-test (quick) ratio

B.

Average collection period

C.

Current ratio.

D.

Inventory turnover.

Question 158

An organization has 10,000 units of a defect item in stock, per unit, market price is $10$; production cost is $4; and defect selling price is $5. What is the carrying amount (inventory value) of defects at your end?

Options:

A.

$0

B.

$4,000

C.

$5,000

D.

$10,000

Question 159

Which of the following can be viewed as a potential benefit of an enterprisewide resource planning system?

Options:

A.

Real-time processing of transactions and elimination of data redundancies.

B.

Fewer data processing errors and more efficient data exchange with trading partners.

C.

Exploitation of opportunities and mitigation of risks associated with e-business.

D.

Integration of business processes into multiple operating environments and databases.

Question 160

Which of the following describes the most effective control that restricts access to secure areas?

Options:

A.

Employee security policy.

B.

Access log reviews.

C.

Biometric authorization.

D.

Security cameras.

Question 161

Which of the following network types should an organization choose if it wants to allow access only to its own personnel?

Options:

A.

An extranet

B.

A local area network

C.

An Intranet

D.

The internet

Question 162

An organization has an immediate need for servers, but no time to complete capital acquisitions. Which of the following cloud services would assist with this situation?

Options:

A.

Infrastructure as a Service (laaS).

B.

Platform as a Service (PaaS).

C.

Enterprise as a Service (EaaS).

D.

Software as a Service (SaaS).

Question 163

During which of the following phases of contracting does the organization analyze whether the market is aligned with organizational objectives?

Options:

A.

Initiation phase

B.

Bidding phase

C.

Development phase

D.

Negotiation phase

Question 164

Which of the following is the most important contract term to audit, because it typically impacts business efficiency?

Options:

A.

Warranty service.

B.

Extraordinary circumstance clause.

C.

Indemnities.

D.

Limitation of liability.

Question 165

An internal auditor conducts a preliminary privacy and data protection risk assessment. Which of the following is the most essential question to start the assessment?

Options:

A.

How does the cybersecurity unit investigate instances of data leakage or allegations?

B.

What are potential fines applicable to the organization for data protection breaches?

C.

What type of private data is collected and maintained by the organization?

D.

In what instances is data pseudonymization is applied in the organization?

Question 166

Which of the following should be included in a data privacy poky?

1. Stipulations for deleting certain data after a specified period of time.

2. Guidance on acceptable methods for collecting personal data.

3. A requirement to retain personal data indefinitely to ensure a complete audit trail,

4. A description of what constitutes appropriate use of personal data.

Options:

A.

1 and 2 only

B.

2 and 3 only

C.

1, 2 and 4 only

D.

2, 3, and 4 only

Question 167

An organization suffered significant damage to its local: file and application servers as a result of a hurricane. Fortunately, the organization was able to recover all information backed up by its overseas third-party contractor. Which of the following approaches has been used by the organization?

Options:

A.

Application management

B.

Data center management

C.

Managed security services

D.

Systems integration

Question 168

During an internal audit engagement, numerous deficiencies in the organization ' s management of customer data were discovered, entailing the risk of breaching personal data protection legislation. An improvement plan was approved by senior management. Which of the following conditions observed during the periodic follow-up process best justifies the chief audit executive ' s decision to escalate the issue to the board?

Options:

A.

The organization ' s customer satisfaction index does not show any signs of improvement

B.

No budget or resources have been allocated to implement corrective measures

C.

The board has not been informed about the planned improvements approved by senior management

D.

Employees responsible for improvements are resisting any additional workload

Question 169

An internal auditor found that several employees of a vendor were authorized to remotely access the internal assets management system.

Which of the following should the auditor determine next?

Options:

A.

Whether there is a documented business need for the access.

B.

Whether access rights granted to vendor employees are read-only.

C.

Who to inform regarding the need to remove vendor employees’ access rights.

D.

Who manages vendor employees’ devices used to access the system.

Question 170

Employees of an organization noticed that an exterior surface of the office building was deteriorating. Upon investigation, it was found that the deterioration was caused by harsh cleaning chemicals used to remove excessive bird droppings, and that the birds were drawn to the building to feed from a spider infestation. Which of the following best represents a root cause-based recommendation for this situation?

Options:

A.

Repair the surface of the building

B.

Discontinue the use of the cleaning chemicals

C.

Scare the birds away by installing scarecrows

D.

Enhance cleaning of the building to displace spiders

Question 171

Which of the following is a security feature that Involves the use of hardware and software to filter or prevent specific Information from moving between the inside network and the outs de network?

Options:

A.

Authorization

B.

Architecture model

C.

Firewall

D.

Virtual private network

Question 172

Internal audit discovered that several loads of pellets were deleted from the scaling database and consequently had no sales invoices, significantly affecting financial statements. An investigation revealed that technicians had deleted the pellet loads accidentally, with no evidence of fraud. Which of the following actions should management implement first?

Options:

A.

Address root causes by launching a project to understand and revise the methods for granting database access rights

B.

Address the condition by limiting technicians ' access to live database data

C.

Address potential risks by reconciling all sales invoices against scaling data

D.

Address investigation results by dismissing technicians who caused the disruption

Question 173

An internal auditor uses a risk and control questionnaire as part of the preliminary survey for an audit of the organization ' s anti-bribery and corruption program. What is the primary purpose of using this approach?

Options:

A.

To compare records from one source to subsequently prepared records about the anti-bribery program

B.

To ascertain the existence of certain controls in the organization ' s anti-bribery program

C.

To obtain testimonial information about certain controls in the organization ' s anti-bribery program

D.

To validate control information through outside parties independent of the anti-bribery program

Question 174

Senior management of a dairy organization asks the internal audit function to undertake an advisory service within the finance function and the internal audit function subsequently issues a report. Which of the following is aligned with IIA guidance on monitoring the results of such an engagement?

Options:

A.

Senior management should dedicate a team to carry out a follow-up audit

B.

A member of the finance function should undertake follow-up in line with the scope

C.

Follow-up on the outcome of advisory services is not required

D.

The internal audit function should agree with senior management on the scope of a follow-up

Question 175

An organization decided to outsource its human resources function. As part of its process migration, the organization is implementing controls over sensitive employee data.

What would be the most appropriate directive control in this area?

Options:

A.

Require a Service Organization Controls (SOC) report from the service provider

B.

Include a data protection clause in the contract with the service provider.

C.

Obtain a nondisclosure agreement from each employee at the service provider who will handle sensitive data.

D.

Encrypt the employees ' data before transmitting it to the service provider

Question 176

Which of the following accounting methods is an investor organization likely to use when buying 40 percent of the stock of another organization?

Options:

A.

Cost method.

B.

Equity method .

C.

Consolidation method.

D.

Fair value method.

Question 177

Which of the following data privacy concerns can be attributed specifically to blockchain technologies?

Options:

A.

Cybercriminals mainly resort to blockchain technologies to phish for private data

B.

Since blockchain transactions can be easily tampered with, the risk of private data leakage is high

C.

Data privacy regulations overregulate the usage of private data in blockchain transactions

D.

Immutability of blockchain technologies makes private data erasure a challenge

Question 178

A major IT project is scheduled to be implemented over a three-month period during the year. The chief audit executive (CAE) scheduled significant audit resources to provide consultation. Due to technical challenges from a supplier, the project is postponed until the following year. What should the CAE do in this case?

Options:

A.

Communicate to the IT project manager that the audit resources are still available to his department for other projects

B.

Reassign the available audit resources to other areas of risk and advise the respective managers in those areas

C.

Amend the plan accordingly and advise the board and senior management for their review and approval

D.

Keep the available resources unassigned so that they are able to take on any ad hoc assignment that may arise

Question 179

According to lIA guidance on IT, which of the following plans would pair the identification of critical business processes with recovery time objectives?

Options:

A.

The business continuity management charter.

B.

The business continuity risk assessment plan.

C.

The business Impact analysis plan

D.

The business case for business continuity planning

Question 180

According to Porter ' s model of competitive strategy, which of the following is a generic strategy?

    Differentiation.

    Competitive advantage.

    Focused differentiation.

    Cost focus.

Options:

A.

2 only

B.

3 and 4 only

C.

1, 3, and 4 only

D.

1, 2, 3, and 4

Question 181

Which of the following statements regarding flat and hierarchical internal audit functions is true?

Options:

A.

A flat structure creates an internal audit function that is highly knowledgeable and collaborative

B.

A hierarchical structure requires little supervision, and the work performed is consistent and reliable

C.

A flat structure allows for growth within the function and leads to the cultivation of diverse skills and fresh perspectives

D.

A hierarchical structure tends to result in a higher cost base due to higher salaries to retain auditors with high knowledge and experience

Question 182

According to IIA guidance, which of the following statements is true regarding the chief audit executive ' s (CAE’s) responsibility for following up on management action plans?

Options:

A.

Follow-up activities must be performed on an ongoing basis, such as quarterly, rather than being scheduled as specific assignments in the internal audit plan

B.

The primary purpose of the CAE’s follow-up activities is to verify whether the audit issues raised in the audit report are valid

C.

The CAE may plan follow-up activities on a selective basis, depending on risk significance, to verify whether management action plans were completed

D.

Where management believes certain action plans are no longer necessary, the CAE must resolve the matter with the board and if the matter remains unresolved, communicate to senior management

Question 183

Which of the following controls would enable management to receive timely feedback and help mitigate unforeseen risks?

Options:

A.

Measure product performance against an established standard.

B.

Develop standard methods for performing established activities.

C.

Require the grouping of activities under a single manager.

D.

Assign each employee a reasonable workload.

Question 184

Which of the following capital budgeting techniques considers the expected total net cash flows from investment?

Options:

A.

Cash payback

B.

Annual rate of return

C.

Incremental analysis

D.

Net present value

Question 185

Which of the following dimensions relates to the quality of big data?

Options:

A.

Veracity.

B.

Validity.

C.

Value.

D.

Variety.

Question 186

During an internal audit engagement, it was found that several vendors were on a government sanctions list and must no longer be traded with. Which of the following would most effectively mitigate the risk of noncompliance with sanctions lists that are updated regularly?

Options:

A.

Agreements with sanctioned vendors discovered by internal audit will be placed on hold until further notice from the government

B.

A new procedure of vendor onboarding will be implemented to ensure that all new vendors undergo screenings against the sanctions list

C.

Controls will be embedded in the vendor management processes to ensure that new and existing vendors are compliant with changes to the sanctions list

D.

The legal team will be asked to prepare counter arguments to dispute audit findings and potential inquiries from the governmental authority

Question 187

At one organization, the specific terms of a contract require both the promisor end promise to sign the contract in the presence of an independent witness.

What is the primary role to the witness to these signatures?

Options:

A.

A witness verifies the quantities of the copies signed.

B.

A witness verifies that the contract was signed with the free consent of the promisor and promise.

C.

A witness ensures the completeness of the contract between the promisor and promise.

D.

A witness validates that the signatures on the contract were signed by tire promisor and promise.

Question 188

Which of the following networks is best for an organization to use when employees are granted access rights to authenticate themselves to the IT resources from outside the organization?

Options:

A.

Local area network.

B.

Wide area network.

C.

Metropolitan area network.

D.

Virtual private network.

Question 189

Which of the following is an example of two-factor authentication?

Options:

A.

The user ' s facial geometry and voice recognition.

B.

The user ' s password and a separate passphrase.

C.

The user ' s key fob and a smart card.

D.

The user ' s fingerprint and a personal Identification number.

Question 190

An organization engages in questionable financial reporting practices due to pressure to meet unrealistic performance targets. Which internal control component is most negatively affected?

Options:

A.

Monitoring.

B.

Control activities.

C.

Risk assessment.

D.

Control environment.

Question 191

As it relates to the data analytics process, which of the following best describes the purpose of an internal auditor who cleaned and normalized cate?

Options:

A.

The auditor eliminated duplicate information.

B.

The auditor organized data to minimize useless information.

C.

The auditor made data usable for a specific purpose by ensuring that anomalies were Identified and corrected.

D.

The auditor ensured data fields were consistent and that data could be used for a specific purpose.

Question 192

Which of the following responsibilities would ordinarily fall under the help desk function of an organization?

Options:

A.

Maintenance service items such as production support

B.

Management of infrastructure services, including network management

C.

Physical hosting of mainframes and distributed servers

D.

End-to-end security architecture design

Question 193

Which of the following is an advantage of a decentralized organizational structure, as opposed to a centralized structure?

Options:

A.

Greater cost-effectiveness

B.

Increased economies of scale

C.

Larger talent pool

D.

Strong internal controls

Question 194

Which of the following statements regarding organizational governance is not correct?

Options:

A.

An effective internal audit function is one of the four cornerstones of good governance.

B.

Those performing governance activities are accountable to the customer.

C.

Accountability is one of the key elements of organizational governance.

D.

Governance principles and the need for an internal audit function are applicable to governmental and not-for-profit activities.

Question 195

An internal auditor reviewed Finance Department records to obtain a list of current vendor addresses. The auditor then compared the vendor addresses to a record of employee addresses maintained by the Payroll Department Which of the following types of data analysis did the auditor perform?

Options:

A.

Duplicate testing.

B.

Joining data sources.

C.

Gap analysis.

D.

Classification

Question 196

According to IIA guidance on IT, which of the following best describes a situation where data backup plans exist to ensure that critical data can be restored at some point in the future, but recovery and restore processes have not been defined?

Options:

A.

Hot recovery plan

B.

Warm recovery plan

C.

Cold recovery plan

D.

Absence of recovery plan

Question 197

Which of the following performance measures disincentives engaging in earnings management?

Options:

A.

Linking performance to profitability measures such as return on investment.

B.

Linking performance to the stock price.

C.

Linking performance to quotas such as units produced.

D.

Linking performance to nonfinancial measures such as customer satisfaction and employees training

Question 198

Under a value-added taxing system:

Options:

A.

Businesses must pay a tax only if they make a profit.

B.

The consumer ultimately bears the cost of the tax through higher prices.

C.

Consumer savings are discouraged.

D.

The amount of value added is the difference between an organization ' s sales and its cost of goods sold.

Question 199

Which of the following data security policies is most likely to be the result of a data privacy law?

Options:

A.

Access to personally identifiable information is limited to those who need it to perform their job.

B.

Confidential data must be backed up and recoverable within a 24-hour period.

C.

Updates to systems containing sensitive data must be approved before being moved to production.

D.

A record of employees with access to insider information must be maintained, and those employees may not trade company stock during blackout periods.

Question 200

An organization ' s IT systems can only be accessed using the organization ' s virtual private network. However, organizational emails, videoconferencing, and file-sharing tools are cloud-based and can be accessed using multi-factor authentication via any device. Which of the following risks should the organization acknowledge?

Options:

A.

The risk that internal data can be leaked via unapproved applications

B.

The risk that virtual private networks are not secure

C.

The risk that remote access controls are usually ineffective in cloud solutions

D.

The risk that employees may read organizational emails outside of business hours

Question 201

Which of the following statements is true regarding a project life cycle?

Options:

A.

Risk and uncertainty increase over the life of the project.

B.

Costs and staffing levels are typically high as the project draws to a close.

C.

Costs related to making changes increase as the project approaches completion.

D.

The project life cycle corresponds with the life cycle of the product produced by or modified by the project.

Question 202

An investor has acquired an organization that has a dominant position in a mature, slow-growth industry and consistently creates positive financial income. Which of the following terms would the investor most likely label this investment in her portfolio?

Options:

A.

A star

B.

A cash cow

C.

A question mark

D.

A dog

Question 203

When an organization is choosing a new external auditor, which of the following is the most appropriate role for the chief audit executive to undertake?

Options:

A.

Review and acquire the external audit service.

B.

Assess the appraisal and actuarial services.

C.

Determine the selection criteria.

D.

Identify regulatory requirements to be considered.

Question 204

A motivational technique generally used to overcome monotony and job-related boredom is:

Options:

A.

Job specification.

B.

Job objectives.

C.

Job rotation.

D.

Job description.

Question 205

While performing an audit of a car tire manufacturing plant, an internal auditor noticed a significant decrease in the number of tires produced from the previous operating

period. To determine whether worker inefficiency caused the decrease, what additional information should the auditor request?

Options:

A.

Total tire production labor hours for the operating period.

B.

Total tire production costs for the operating period.

C.

Plant production employee headcount average for the operating period.

D.

The production machinery utilization rates.

Question 206

Which of the following would provide the most relevant assurance that the application under development will provide maximum value to the organization?

Options:

A.

Use of a formal systems development lifecycle.

B.

End-user involvement.

C.

Adequate software documentation.

D.

Formalized non-regression testing phase.

Question 207

Senior management has decided to implement the Three Lines of Defense model for risk management. Which of the following best describes senior management ' s duties with regard to this model?

Options:

A.

Ensure compliance with the model.

B.

Identify management functions.

C.

Identify emerging issues.

D.

Set goals for implementation.

Question 208

According to 11A guidance on it; which of the following statements is true regarding websites used in e-commerce transactions?

Options:

A.

HTTP sites provide sufficient security to protect customers ' credit card information.

B.

Web servers store credit cardholders ' information submitted for payment.

C.

Database servers send cardholders’ information for authorization in clear text.

D.

Payment gatewaysauthorizecredit cardonlinepayments.

Question 209

When preparing the annual internal audit plan, which of the following should the chief audit executive (CAE) consider to optimize efficiency and effectiveness?

Options:

A.

The CAE should review the objectives and scope of the external audit plan and consider including audits with the same objectives and scope to ensure thorough coverage of the area

B.

The CAE should review the audit plan prepared by the compliance department and coordinate any audits in the same areas to reduce duplication of objectives and minimize disruption to the area under review

C.

The CAE should avoid reviewing plans by internal or external assurance providers to increase effectiveness and reduce bias in internal audit selection

D.

The CAE should review operational quality assurance audit plans, place reliance on the areas covered, and exclude those areas from final consideration in the annual internal audit plan

Question 210

The process of scenario planning begins with which of the following steps?

Options:

A.

Determining the trends that will influence key factors in the organization ' s environment.

B.

Selecting the issue or decision that will impact how the organization conducts future business.

C.

Selecting leading indicators to alert the organization of future developments.

D.

Identifying how customers, suppliers, competitors, employees, and other stakeholders will react.

Question 211

An internal auditor was asked to review an equal equity partnership. In one sampled transaction, Partner A transferred equipment into the partnership with a self-declared value of $10,000, and Partner B contributed equipment with a self-declared value of $15,000. The capital accounts of each partner were subsequently credited with $12,500. Which of the following statements is true regarding this transaction?

Options:

A.

The capital accounts of the partners should be increased by the original cost of the contributed equipment.

B.

The capital accounts should be increased using a weighted average based on the current percentage of ownership.

C.

No action is necessary as the capital account of each partner was increased by the correct amount.

D.

The capital accounts of the partners should be increased by the fair market value of their contribution.

Question 212

A rapidly expanding retail organization continues to be tightly controlled by its original small management team. Which of the following is a potential risk in this vertically centralized organization?

Options:

A.

Lack of coordination among different business units

B.

Operational decisions are inconsistent with organizational goals

C.

Suboptimal decision-making

D.

Duplication of business activities

Question 213

An internal auditor wishes to test why there was a significant drop in accounts payable volume last month and creates several scenarios to help explain the anomaly.

Which of the following best describes this data analysis technique?

Options:

A.

Descriptive.

B.

Diagnostic.

C.

Predictive.

D.

Prescriptive.

Question 214

Which of the following IT-related activities is most commonly performed by the second line of defense?

Options:

A.

Block unauthorized traffic.

B.

Encrypt data.

C.

Review disaster recovery test results.

D.

Provide an independent assessment of IT security.

Question 215

Which of the following attributes of data is the most significantly impacted by the internet of things?

Options:

A.

Normalization

B.

Velocity

C.

Structuration

D.

Veracity

Question 216

Which of the following statements is true regarding activity-based costing (ABC)?

Options:

A.

An ABC costing system is similar to conventional costing systems in how it treats the allocation of manufacturing overhead.

B.

An ABC costing system uses a single unit-level basis to allocate overhead costs to products.

C.

An ABC costing system may be used with either a job order or a process cost accounting system.

D.

The primary disadvantage of an ABC costing system is less accurate product costing.

Question 217

Which of the following is classified as a product cost using the variable costing method?

Direct labor costs.

Insurance on a factory.

Manufacturing supplies.

Packaging and shipping costs.

Options:

A.

1 and 2

B.

1 and 3

C.

2 and 4

D.

3 and 4

Question 218

Which of the following characteristics applies to an organization that adopts a flat structure?

Options:

A.

The structure is dispersed geographically

B.

The hierarchy levels are more numerous.

C.

The span of control is wide

D.

The tower-level managers are encouraged to exercise creativity when solving problems

Question 219

Preferred stock is less risky for investors than is common stock because:

Options:

A.

Common stock pays dividends as a stated percentage of face value.

B.

Common stock has priority over preferred stock with regard to earnings and assets.

C.

Preferred dividends are usually cumulative.

D.

Preferred stock with no conversion feature has a higher dividend yield than does convertible preferred stock.

Question 220

Which of the following risks is the result of an organization failing to create and establish strategies for the use of social media?

Options:

A.

The organization does not ensure that all employee posts have been vetted by the relevant department.

B.

The organization may be subject to penalties for employee posts.

C.

The organization does not ensure the board ' s tone at the top reaches all employees.

D.

The organization is reactive rather than proactive in the use of social media.

Question 221

Which of the following techniques is the most relevant when an internal auditor conducts a valuation of an organization ' s physical assets?

Options:

A.

Observation.

B.

Inspection.

C.

Original cost.

D.

Vouching.

Question 222

An attacker, posing as a bank representative, convinced an employee to release certain, financial information that ultimately resulted in fraud. Which of the following best describes this cybersecurity risk?

Options:

A.

Shoulder suiting

B.

Pharming,

C.

Phishing.

D.

Social engineering.

Question 223

An organization had three large centralized divisions: one that received customer orders for service work; one that scheduled the service work at customer locations; and one that answered customer calls about service problems. These three divisions were restructured into seven regional groups, each of which performed all three functions. One advantage of this restructuring would be:

Options:

A.

Better internal controls.

B.

Greater economies of scale.

C.

Improved workflow.

D.

Increased specialization.

Question 224

A chief audit executive wants to implement an enterprisewide resource planning software. Which of the following internal audit assessments could provide overall assurance on the likelihood of the software implementation ' s success?

Options:

A.

Readiness assessment.

B.

Project risk assessment.

C.

Post-implementation review.

D.

Key phase review.

Question 225

Which of the following techniques would best detect an inventory fraud scheme?

Options:

A.

Analyze Invoice payments just under individual authorization limits.

B.

Analyze stratification of inventory adjustments by warehouse location.

C.

Analyze inventory invoice amounts and compare with approved contract amounts.

D.

Analyze differences discovered during duplicate payment testing

Question 226

Which of the following is true of bond financing, compared to common stock, when alJ other variables are equal?

Options:

A.

Lower shareholder control

B.

lower indebtedness

C.

Higher company earnings per share.

D.

Higher overall company earnings

Question 227

According to IIA guidance on IT, which of the following plans would pair the identification of critical business processes with recovery time objectives?

Options:

A.

The business continuity management charter

B.

The business continuity risk assessment plan

C.

The business impact analysis plan

D.

The business case for business continuity planning

Question 228

Which of the following is true regarding reporting on the quality assurance and improvement program (QAIP)?

Options:

A.

The results of ongoing monitoring must be communicated annually to the board and other appropriate stakeholders

B.

The results of any periodic self-assessment and level of conformance with the Global Internal Audit Standards must be reported to the board before completion

C.

The results of any external assessments and level of conformance with the Standards must be reported to the board before completion

D.

The QAIP and the resulting action plan must be made available to external assessors

Question 229

An internal audit team is trialing a data analytics tool. An extract from accounts payable was loaded into the tool and as a result, the tool flagged most of the transactions, thus yielding no meaningful results. After investigating, the audit team determined that the extract contained duplicate entries and spelling issues.

Which of the following should have been performed prior to loading the data into the analytics tool?

Options:

A.

Data segregation.

B.

Data stratification.

C.

Data normalization.

D.

Data quantification.

Question 230

Which of the following descriptions of the internal control system are indicators that risks are managed effectively?

    Existing controls promote compliance with applicable laws and regulations.

    The control environment is designed to address all identified risks to the organization.

    Key controls for significant risks to the organization remain consistent over time.

    Monitoring systems are in place to alert management to unexpected events.

Options:

A.

1 and 3.

B.

1 and 4.

C.

2 and 3.

D.

2 and 4.

Question 231

Which of the following standards would be most useful in evaluating the performance of a customer-service group?

Options:

A.

The average time per customer inquiry should be kept to a minimum.

B.

Customer complaints should be processed promptly.

C.

Employees should maintain a positive attitude when dealing with customers.

D.

All customer inquiries should be answered within seven days of receipt.

Question 232

Which of the following are typical audit considerations for a review of authentication?

    Authentication policies and evaluation of controls transactions.

    Management of passwords, independent reconciliation, and audit trail.

    Control self-assessment tools used by management.

    Independent verification of data integrity and accuracy.

Options:

A.

1, 2, and 3

B.

1, 2, and 4

C.

1, 3, and 4

D.

2, 3, and 4

Question 233

To assess the effectiveness of an organization ' s privacy program, which of the following approaches should an internal auditor take?

Options:

A.

Conduct a series of employee interviews.

B.

Conduct penetration tests.

C.

Review privacy policies and procedures.

D.

Analyze the life cycle of sensitive data.

Question 234

To achieve conformance with the Global Internal Audit Standards, the chief audit executive must include which of the following activities in the quality assurance and improvement program (QAIP)?

Options:

A.

Require board oversight of the QAIP

B.

Assess Standards conformance for each individual assurance engagement

C.

Conduct a self-assessment at least once every five years

D.

Report the results of the QAIP to the board

Question 235

What would an internal auditor do to ensure that a process to mitigate risk is in place for the organization ' s change management process?

Options:

A.

Develop and enforce change policies to ensure employees are continually trained.

B.

Apply a risk-based approach and impose segregation of duties related to the change management process.

C.

Conduct a high-level threat analysis and implement a compensating control.

D.

Validate authorization, segregation of duties, testing of changes, and approval to move changes into production.

Question 236

Which of the following would be most likely found in an internal audit procedures manual?

Options:

A.

A summary of the strategic plan of the area under review

B.

Appropriate response options for when findings are disputed by management

C.

An explanation of the resources needed for each engagement

D.

The extent of the auditor ' s authority to collect data from management

Question 237

The project charter is an output from which of the following?

Options:

A.

Scope planning.

B.

Scope definition.

C.

Scope verification.

D.

Project initiation.