Summer Sale - Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dpt65

IIA-CIA-Part1 Questions and Answers

Question # 6

According to IIA guidance, which of the following is accurate regarding the chief audit executive's (CAE's) requirement to report the results of quality assessments?

1. The CAE must report the results of external assessments at least annually.

2. The CAE must report the results of ongoing monitoring at least annually.

3. The CAE must report the results of quality assessments to senior management.

4. The CAE must report the results of quality assessments to the board.

A.

1 and 3 only.

B.

2 and 4 only.

C.

1,2. and 3.

D.

2,3, and 4.

Full Access
Question # 7

With regard to governance, which of the following is a board-level responsibility rather than a management responsibility?

A.

Obtaining assurance on external financial, regulatory, and internal audits.

B.

Complying with laws, regulations, and codes.

C.

Assigning authority and responsibilities organization wide.

D.

Monitoring and measuring performance.

Full Access
Question # 8

Which of the following best demonstrates internal auditors performing their work with proficiency?

A.

Internal auditors meet with operational management at each phase of the audit process.

B.

Internal auditors adhere to The IIA’s Code of Ethics.

C.

Internal auditors work collaboratively with their engagement team.

D.

Internal auditors complete a program of continuing professional development.

Full Access
Question # 9

Which of the following statements is true regarding the role of the internal audit activity in the organization's risk management process?

A.

The internal audit activity should not be responsible for developing the organization's risk management framework, even with appropriate safeguards.

B.

The internal audit activity is typically responsible for alerting operational management to emerging risks and changes in regulatory scenarios

C.

The internal audit activity may coach management on risk response scenarios if safeguards have been implemented.

D.

The internal audit activity should avoid giving assurance regarding the accuracy of risk evaluations if safeguards have not been implemented.

Full Access
Question # 10

Which of the following statements is the most appropriate for a chief audit executive to include in the internal audit policy manual in order to promote objectivity?

A.

Internal auditors may conduct a financial effectiveness engagement in a business unit at any point after being transferred from that area.

B.

Internal auditors may conclude that a business unit's current control environment is adequate and effective if the review of the prior year's workpapers and audit report supports that conclusion.

C.

Internal auditors may conduct an engagement in a business unit at any point after providing a training workshop in that area.

D.

Internal auditors should limit the scope of an engagement if they become aware of a potential impairment of their objectivity in order to reduce the potential impact of the impairment on the engagement results.

Full Access
Question # 11

The chief audit executive (CAE) has hired a new internal auditor who was immediately assigned to a procurement function audit. Because the new auditor's name is similar to that of the procurement manager, some staff members think the two are related, although they are not. Which of the following actions is most appropriate for the CAE to take?

A.

Take no action, as there is no impairment to independence.

B.

Remove the new internal auditor from the engagement team.

C.

Discuss the matter with the appropriate personnel to alleviate concerns.

D.

Closely supervise the new auditor and carefully review his work.

Full Access
Question # 12

Which of the following describes the primary objective when implementing a risk management framework?

A.

To achieve planned profitability for business expansion.

B.

To enhance an organization's confidence in achieving strategy.

C.

To strengthen corporate governance standards.

D.

To eliminate business risks and uncertainties.

Full Access
Question # 13

An organization is considering purchasing a new banking software system and has asked the internal audit activity to evaluate the system. An internal auditor assigned to perform the engagement worked at the software company two years ago and is familiar with the system's design strengths and weaknesses. Which of the following is true regarding impairment to the auditor's objectivity?

A.

This situation does not necessitate any action related to the auditor's objectivity.

B.

The auditor should decline to perform the audit because personal conflicts of interest are likely.

C.

The auditor must disclose to the chief audit executive that this situation may impair her objectivity.

D.

The auditor can provide only consulting services, not assurance.

Full Access
Question # 14

Which of the following is most likely to impair the internal audit activity's independence?

A.

Undertaking audit work in an area where internal auditors lack the necessary skills.

B.

Establishing an internal audit activity without documented policies and procedures.

C.

Assigning compliance responsibilities to the chief audit executive.

D.

Concluding that an internal control is effective without first obtaining evidence

Full Access
Question # 15

According to HA guidance, if an internal auditor suspects fraud during an assurance engagement, what should the auditor do first?

A.

Recommend parties involved to be sanctioned in accordance with the organization's policy.

B.

Determine whether any additional audit work needs to be performed.

C.

Launch an investigation to obtain details of the fraud and parties involved.

D.

Request that the responsible process owner remediate the issue immediately.

Full Access
Question # 16

Which of the following is an indicator of ineffective third-party risk management?

A.

Sourcing of third parties does not follow public procurement law.

B.

Violations of service conditions trigger either fines or termination.

C.

Due diligence of third parties is conducted only after contract signing.

D.

The right-to-audit clause is limited by personal data protection regulations.

Full Access
Question # 17

A new internal audit activity is considering the adoption of a risk and control framework. Which of the following is the most appropriate consideration during this process?

A.

The framework should not be developed by the internal audit activity

B.

The framework should apply to individual projects rather than the organization as a whole

C.

The framework should always be tailored to the organization

D.

The framework should require fewer resources to implement

Full Access
Question # 18

Which of the following is true regarding the auditing of soft controls?

A.

Soft controls should not be audited due to subjectivity issues.

B.

There are no effective tools to use for audits of soft controls.

C.

Traditional testing is less suitable for soft controls assessment.

D.

Management input is the best source for assessment of soft controls.

Full Access
Question # 19

Which of the following would most likely be classified as a consulting engagement?

A.

Examining the internal control effectiveness of the marketing department

B.

Assessing the adequacy of the IT system's business process design

C.

Facilitating a self assessment of the organizations business risk and control identification

D.

Reviewing the application controls in the human resources system

Full Access
Question # 20

Which of the following is an example of an application control?

A.

Employees in the data center must always wear identification badges

B.

Operating system updates must be installed within 48 hours.

C.

A two stage authentication process must be used to access customer information

D.

System backup and recovery testing must be done monthly

Full Access
Question # 21

A chief audit executive (CAE) identifies that the internal audit activity lacks a necessary skill to perform a management request for a consulting engagement. According to IIA guidance, which of the following is the most appropriate action the CAE should take regarding the request?

A.

Assign the engagement to a more senior internal auditor.

B.

Decline the engagement request.

C.

Allow the internal auditors to acquire the needed skills while performing the engagement.

D.

Supervise the assigned internal auditors throughout the engagement.

Full Access
Question # 22

The chief audit executive (CAE) annually develops a budget and resource plan and submits it to the board for approval. This action best fulfills which of the following responsibilities of the CAE?

A.

The responsibility to maintain organizational independence.

B.

The responsibility to perform engagements with due professional care.

C.

The responsibility to communicate corrective action plans to the board.

D.

The responsibility to define the purpose of the internal audit activity.

Full Access
Question # 23

During the planning stage of an assurance engagement, a payroll clerk informed the internal auditor that he is often asked to add new employees to the payroll without any formal new-hire documentation from human resources. The auditor is concerned that this increases the risk for fraud. To complete engagement planning, which of the following is the most appropriate next step for the auditor to take?

A.

Increase the sample size to be tested, ensuring a thorough review of the payroll records.

B.

Advise the chief audit executive of the clerk's assertion, despite the lack of supporting evidence.

C.

Ask the clerk to provide a list of any suspicious new employee names on the payroll.

D.

Investigate the matter further to understand precisely how many payroll records were affected.

Full Access
Question # 24

Which of the following is an area that an organization would most likely include as part of its corporate social responsibility reporting?

A.

The profitability impact of its products in developing markets.

B.

The amount of political donations to local government races.

C.

The number of complaints related to traffic from its new factory.

D.

The compensation packages awarded to senior management.

Full Access
Question # 25

The collaborating style for conflict resolution, where the parties promote assertiveness and work together to develop a mutually beneficial solution, is best used in which of the following situations?

A.

Parties are confident of the solution and are ready to defend it.

B.

There is a high level of trust among the parties.

C.

Resolution is time sensitive and a quick decision is necessary.

D.

The issue is more important to one patty than the others.

Full Access
Question # 26

What is an appropriate first step in an internal auditor’s fraud risk assessment to evaluate how the organization manages such risk?

A.

Develop preventive and detective controls

B.

Identify potential fraud scenarios

C.

Assess the impact and likelihood of fraud risks

D.

Determine fraud risk responses

Full Access
Question # 27

According to the Standards, in today's technology and business environments, how much computer and information systems-related knowledge and skills must an internal auditor have to be effective in fulfilling his job responsibilities?

A.

Auditors must have an IT specialty in at least one of their organization's key information technology systems.

B.

Auditors must be proficient in data analysis and computer assisted audit techniques for their organization.

C.

Auditors must understand their organization's integrated test facilities and generalized audit software.

D.

Auditors must understand their organization's IT governance, risk, and control processes.

Full Access
Question # 28

Which of the following scenarios provides the most concerning red flag or indicator of possible fraud?

A.

An employee receives a bonus for perfect attendance

B.

During the past 18 months three chief financial officers have left the organization after having been promoted to the position

C.

The organization does not perform any due diligence research on third party service providers

D.

Three competitors are highly profitable but a fourth equal in size is approaching bankruptcy limits

Full Access
Question # 29

According to The IIA’s Code of Ethics, which of the following best describes the principle of integrity?

A.

Auditors shall observe the law and make disclosures expected by the law and the profession

B.

Auditors shall disclose all material facts known to them that if not disclosed may distort the reporting of activities under review

C.

Auditors shall engage only in those services for which they have the necessary knowledge skills and experience

D.

Auditors shall be prudent in the use and protection of information acquired in the course of their duties

Full Access
Question # 30

Which of the following is true regarding internal audit role's in The IIA's Three Lines Model?

A.

As internal control is part of risk management, the internal audit role in risk management implies reduced emphasis on internal control.

B.

Internal audit can blur the distinction between the second and the third lines as long as value is added.

C.

Internal audit cannot rely on other assurance providers when opining on the effectiveness of risk management.

D.

Internal audit should be aligned with first- and second-line functions through effective communication, cooperation, and collaboration.

Full Access
Question # 31

According to MA guidance, which of the following is an appropriate role for the internal audit activity?

A.

Coaching management in responding to risks.

B.

Implementing risk responses on management's behalf.

C.

Imposing risk management processes.

D.

Setting the risk appetite.

Full Access
Question # 32

Which of the following engagements would be considered an appropriate consulting service?

A.

The internal audit activity of a commercial bank routinely performs branch audits for compliance with regulations.

B.

The internal audit activity participates in a cosourcing arrangement with an IT audit firm to test information systems security.

C.

The internal audit activity facilitates biannual training of the risk management team in risk identification methodologies.

D.

The internal audit activity partners with external auditors annually to complete fieldwork required as a part of the external audit exercise.

Full Access
Question # 33

Who has the ultimate responsibility of implementing the organization’s governance system?

A.

Stakeholders

B.

The board

C.

The chief executive officer

D.

Internal auditors

Full Access
Question # 34

Which of the following can be used to minimize employees’ resentment of controls?

A.

Making sure employees are exempt from participating in control creation

B.

Implementing controls without lengthy explanations of their purpose

C.

Developing general constricting controls rather than detailed ones

D.

Not using controls to achieve goals

Full Access