Summer Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

IIA-CIA-Part3 Questions and Answers

Question # 6

In reviewing an organization ' s IT infrastructure risks, which of the following controls is to be tested as pan of reviewing workstations?

A.

Input controls

B.

Segregation of duties

C.

Physical controls

D.

Integrity controls

Full Access
Question # 7

An organization uses a database management system (DBMS) as a repository for data. The DBMS, in turn, supports a number of end-user developed applications which were created using fourth-generation programming languages. Some of the applications update the database. Which of the following is the most important control related to the integrity of the data in the database?

A.

End users have their read-only applications approved by the information systems department before accessing the database.

B.

Concurrency update controls are in place.

C.

End-user applications are developed on personal computers before being implemented on the mainframe.

D.

A hierarchical database model is adopted so that multiple users can be served at the same time.

Full Access
Question # 8

According to IIA guidance on IT, which of the following best describes a situation where data backup plans exist to ensure that critical data can be restored at some point in the future, but recovery and restore processes have not been defined?

A.

Hot recovery plan

B.

Warm recovery plan

C.

Cold plan

D.

Absence of recovery plan

Full Access
Question # 9

A rapidly expanding retail organisation continues to be tightly controlled by its original small management team. Which of the following is a potential risk in this vertically centralized organization?

A.

Lack of coordination among different business units

B.

Operational decisions are inconsistent with organizational goals

C.

Suboptimal decision making

D.

Duplication of business activities

Full Access
Question # 10

Which of the following would best contribute to the success of a guest auditor program that allows people from other areas of the organization to serve as subject matter experts?

A.

Selecting guest auditors whose work has recently been audited by the internal audit function

B.

Recommending the guest auditor to design the internal audit program and perform testing procedures

C.

Soliciting feedback from the guest auditor once the engagement is complete

D.

Enabling the guest auditor to interact with internal audit staff to identify mutually beneficial opportunities

Full Access
Question # 11

Which of the following IT disaster recovery plans includes a remote site designated for recovery with available space for basic services, such as internet and telecommunications, but does not have servers or infrastructure equipment?

A.

Frozen site

B.

Cold site

C.

Warm site

D.

Hot site

Full Access
Question # 12

Which of the following control techniques would minimize the risk of interception during transmission in an electronic data interchange system?

    Encryption.

    Traffic padding.

    Edit checks.

    Structured data format.

A.

1 and 2 only

B.

2 and 3 only

C.

3 and 4 only

D.

1, 2, and 3 only

Full Access
Question # 13

A manager who is authorized to make purchases up to a certain dollar amount approves the set-up of a fictitious vendor and subsequently initiates purchase orders. Which of the following controls would best address this risk?

A.

Establish separate vendor creation and approval teams.

B.

Develop and distribute a code of conduct that prohibits conflicts of interest.

C.

Perform a regular review of the vendor master file.

D.

Require submission of a conflict-of-interest declaration.

Full Access
Question # 14

Which of the following responsibilities would ordinary fall under the help desk function of an organization?

A.

Maintenance service items such as production support.

B.

Management of infrastructure services, including network management.

C.

Physical hosting of mainframes and distributed servers

D.

End-to -end security architecture design.

Full Access
Question # 15

Which of the following statements regarding flat and hierarchical internal audit functions is true?

A.

A flat structure creates an internal audit function that is highly knowledgeable and collaborative

B.

A hierarchical structure requires little supervision, and the work performed is consistent and reliable

C.

A flat structure allows for growth within the function and leads to the cultivation of diverse skills and fresh perspectives

D.

A hierarchical structure tends to result in a higher cost base due to higher salaries to retain auditors with high knowledge and experience

Full Access
Question # 16

Which of the following controls is designed to mitigate a physical IT risk?

A.

An automated fire prevention system.

B.

Access control restrictions in a system.

C.

Anti-malware protection software.

D.

A network isolating firewall system.

Full Access
Question # 17

Which of the following security controls focuses most on prevention of unauthorized access to the power plant?

A.

An offboarding procedure is initiated monthly to determine redundant physical access rights.

B.

Logs generated by smart locks are automatically scanned to identify anomalies in access patterns.

C.

Requests for additional access rights are sent for approval and validation by direct supervisors.

D.

Automatic notifications are sent to a central security unit when employees enter the premises during nonwork hours

Full Access
Question # 18

Which of the following situations best applies to an organisation that uses a project, rather than a process, to accomplish its business activities?

A.

Clothing company designs, makes, and sells a new item.

B.

A commercial construction company is hired to build a warehouse.

C.

A city department sets up a new firefighter training program.

D.

A manufacturing organization acquires component parts from a contracted vendor

Full Access
Question # 19

According to The IIA ' s Three Lines Model, which of the following IT security activities is commonly shared by all three lines?

A.

Assessments of third parties and suppliers.

B.

Recruitment and retention of certified IT talent.

C.

Classification of data and design of access privileges.

D.

Creation and maintenance of secure network and device configuration.

Full Access
Question # 20

Which of the following would most likely serve as a foundation for individual operational goats?

A.

Individual skills and capabilities.

B.

Alignment with organizational strategy.

C.

Financial and human resources of the unit.

D.

Targets of key performance indicators

Full Access
Question # 21

Which of the following is a key characteristic of a zero-based budget?

A.

A zero-based budget provides estimates of costs that would be incurred under different levels of activity.

B.

A zero-based budget maintains focus on the budgeting process.

C.

A zero-based budget is prepared each year and requires each item of expenditure to be justified.

D.

A zero-based budget uses input from lower-level and middle-level managers to formulate budget plans.

Full Access
Question # 22

Which of the following purchasing scenarios would gain the greatest benefit from implementing electronic data interchange (EDI)?

A.

A just-in-time purchasing environment

B.

A large volume of custom purchases

C.

A variable volume sensitive to material cost

D.

A currently inefficient purchasing process

Full Access
Question # 23

Which of the following statements is true regarding the capital budgeting procedure known as the discounted payback period?

A.

It calculates the overall value of a project.

B.

It ignores the time value of money.

C.

It calculates the time a project takes to break even.

D.

It begins at time zero for the project.

Full Access
Question # 24

An internal auditor is reviewing key phases of a software development project. Which of the following would; the auditor most likely use to measure the project team ' s performance related to how project tasks are completed?

A.

A balanced scorecard.

B.

A quality audit

C.

Earned value analysis.

D.

Trend analysis

Full Access
Question # 25

An organization ' s IT systems can only be accessed using the organization ' s virtual private network. However, organizational emails, videoconferencing, and file-sharing tools are cloud-based and can be accessed using multi-factor authentication via any device. Which of the following risks should the organization acknowledge?

A.

The risk that internal data can be leaked via unapproved applications

B.

The risk that virtual private networks are not secure

C.

The risk that remote access controls are usually ineffective in cloud solutions

D.

The risk that employees may read organizational emails outside of business hours

Full Access
Question # 26

Which of the following factors is considered a disadvantage of vertical integration?

A.

It may reduce the flexibility to change partners.

B.

It may not reduce the bargaining power of suppliers.

C.

It may limit the organization ' s ability to differentiate the product.

D.

It may lead to limited control of proprietary knowledge.

Full Access
Question # 27

As part of internal audit ' s risk assessment, a chief audit executive is determining certain factors as part of planning the areas to audit within an organization that makes silicon chips. Which of the following would be considered a subjective factor as part of the risk assessment?

A.

The number of vendors able to meet the supply demand request from the organization

B.

The quality of the staff supervision of silicon chips produced by the organization

C.

The length of time since the last audit of the organization ' s manufacturing facilities

D.

The asset value of the silicon chips that the organization did not produce because of a shortage in raw materials

Full Access
Question # 28

Which of the following conflict resolution methods should be applied when the intention of the parties is to solve the problem by clarifying differences and attaining everyone ' s objectives?

A.

Accommodating.

B.

Compromising.

C.

Collaborating.

D.

Competing.

Full Access
Question # 29

What kind of strategy would be most effective for an organization to adopt in order to Implement a unique advertising campaign for selling identical product lines across all of its markets?

A.

Export strategy.

B.

Transnational strategy

C.

Multi-domestic strategy

D.

Globalization strategy

Full Access
Question # 30

Which of the following is on advantage of a decentralized organizational structure, as opposed to a centralized structure?

A.

Greater cost-effectiveness

B.

Increased economies of scale

C.

Larger talent pool

D.

Strong internal controls

Full Access
Question # 31

Which of the following is an example of a phishing attack?

A.

An organization’s website becomes flooded with malicious traffic on the first day of the online shopping season, causing the website to crash and preventing customers from purchasing deals online

B.

The employees of a retail organization responded to emails with a link to malware that enabled a hacker to access the point-of-sale system and obtain customers’ credit card information

C.

An organization’s employees clicked on a link that allowed a worm to infiltrate and encrypt the organization’s operating system, rendering it unusable. A group of hackers is demanding payment to unlock the encryption

D.

A group of online activists hacked into the private email and confidential records of the local police department and released the information online to expose the corrupt practices of the department

Full Access
Question # 32

A retail organization mistakenly did have include $10,000 of Inventory in the physical count at the end of the year. What was the impact to the organization ' s financial statements?

A.

Cost of sales and net income are understated.

B.

Cost of sales and net income are overstated.

C.

Cost of sales is understated and not income is overstated.

D.

Cost of sales is overstated and net Income is understated.

Full Access
Question # 33

Under which of the following circumstances can the internal audit function rely most confidently on the work performed by external auditors?

A.

The chief audit executive (CAE) has access to the external auditors ' audit programs and workpapers

B.

The CAE requires that external auditors use the same techniques, methods, and terminology as the internal auditors

C.

The board of directors reviews the materiality and risk assessment performed by external auditors to direct the CAE

D.

The board of directors requires that all final communications by external auditors be reviewed by the CAE

Full Access
Question # 34

An attacker, posing as a bank representative, convinced an employee to release certain, financial information that ultimately resulted in fraud. Which of the following best describes this cybersecurity risk?

A.

Shoulder suiting

B.

Pharming,

C.

Phishing.

D.

Social engineering.

Full Access
Question # 35

Which of the following descriptions of the internal control system are indicators that risks are managed effectively?

    Existing controls promote compliance with applicable laws and regulations.

    The control environment is designed to address all identified risks to the organization.

    Key controls for significant risks to the organization remain consistent over time.

    Monitoring systems are in place to alert management to unexpected events.

A.

1 and 3.

B.

1 and 4.

C.

2 and 3.

D.

2 and 4.

Full Access
Question # 36

Which of the following communication characteristics is achieved when the internal audit function avoids redundancies and excludes information that is unnecessary, insignificant, or unrelated to the engagement?

A.

Constructive communications

B.

Complete communications

C.

Concise communications

D.

Clear communications

Full Access
Question # 37

As it relates to the data analytics process, which of the following best describes the purpose of an internal auditor who cleaned and normalized data?

A.

The auditor eliminated duplicate information

B.

The auditor organized data to minimize useless information

C.

The auditor made data usable for a specific purpose by ensuring that anomalies were identified and addressed

D.

The auditor ensured data fields were consistent and that data could be used for a specific purpose

Full Access
Question # 38

Which mindset promotes the most comprehensive risk management strategy?

A.

Increase shareholder value.

B.

Maximize market share.

C.

Improve operational efficiency.

D.

Mitigate losses.

Full Access
Question # 39

Which of the following is a limitation of the remote wipe for a smart device?

A.

Encrypted data cannot be locked to prevent further access

B.

Default settings cannot be restored on the device.

C.

All data, cannot be completely removed from the device

D.

Mobile device management software is required for successful remote wipe

Full Access
Question # 40

Which of the following is classified as a product cost using the variable costing method?

Direct labor costs.

Insurance on a factory.

Manufacturing supplies.

Packaging and shipping costs.

A.

1 and 2

B.

1 and 3

C.

2 and 4

D.

3 and 4

Full Access
Question # 41

Which would provide the board with the highest level of assurance regarding whether an internal audit function can achieve its objectives?

A.

Percentage of completed audit engagements

B.

Key stakeholder satisfaction surveys

C.

External quality assurance feedback

D.

Audit personnel commitment and turnover rates

Full Access
Question # 42

Which of the following statements is true regarding the resolution of interpersonal conflict?

A.

Unrealized expectations can be avoided with open and honest discussion.

B.

Reorganization would probably not help ambiguous or overlapping jurisdictions.

C.

Deferring action should be used until there is sufficient time to fully deal with the issue.

D.

Timely and unambiguous clarification of roles and responsibilities will eliminate most interpersonal conflict.

Full Access
Question # 43

Upon completing a follow-up audit engagement, the chief audit executive (CAE) noted that management has not implemented any mitigation measures to address the high risks that were reported in the initial audit report. What initial step must the CAE take to address this situation?

A.

Communicate the issue to senior management

B.

Discuss the issue with members of management responsible for the risk area

C.

Report the situation to the external auditors

D.

Escalate the issue to the board

Full Access
Question # 44

For which of the following scenarios would the most recent backup of the human resources database be the best source of information to use?

A.

An incorrect program fix was implemented just prior to the database backup.

B.

The organization is preparing to train all employees on the new self-service benefits system.

C.

There was a data center failure that requires restoring the system at the backup site.

D.

There is a need to access prior year-end training reports for all employees in the human resources database

Full Access
Question # 45

A third party who provides payroll services to the organization was asked to create audit or “read-only 1 functionalities in their systems. Which of the following statements is true regarding this request?

A.

This will support execution of the right-to-audit clause.

B.

This will enforce robust risk assessment practices

C.

This will address cybersecurity considerations and concerns.

D.

This will enhance the third party ' s ability to apply data analytics

Full Access
Question # 46

Which of the following statements is most accurate concerning the management and audit of a web server?

A.

The file transfer protocol (FTP) should always be enabled

B.

The simple mail transfer protocol (SMTP) should be operating under the most privileged accounts

C.

The number of ports and protocols allowed to access the web server should be maximized

D.

Secure protocols for confidential pages should be used instead of clear-text protocols such as HTTP or FTP

Full Access
Question # 47

Which of the following analytical techniques would an internal auditor use to verify that none of an organization ' s employees are receiving fraudulent invoice payments?

A.

Perform gap testing.

B.

Join different data sources.

C.

Perform duplicate testing.

D.

Calculate statistical parameters.

Full Access
Question # 48

An organization uses radio frequency identification (RFID) technology to identify vehicles authorized to enter a gated facility. The RFID reader scans the vehicle ' s license plate number, and if the number is on a pre-authorized list, a green light flashes, indicating to the security guard that he can push a button to open the gate.

Which of the following controls should be added to ensure that a particular vehicle is authorized to enter the facility?

A.

The security guard should question the vehicle ' s driver, if the guard has any doubts.

B.

Physical characteristics of the vehicle should be described in the system.

C.

The security guard should send each access request to administrative personnel for validation prior to admitting the vehicle into the gated facility.

D.

Video surveillance cameras should be installed to provide a full view of the vehicle.

Full Access
Question # 49

In accounting, which of the following statements is true regarding the terms debit and credit?

A.

Debit indicates the right side of an account and credit the left side

B.

Debit means an increase in an account and credit means a decrease.

C.

Credit indicates the right side of an account and debit the left side.

D.

Credit means an increase in an account and debit means a decrease

Full Access
Question # 50

Which of the following local area network physical layouts is subject to the greatest risk of failure if one device fails?

A.

Star network.

B.

Bus network.

C.

Token ring network.

D.

Mesh network.

Full Access
Question # 51

Which of the following Issues would be a major concern for internal auditors when using a free software to analyze a third-party vendor ' s big data?

A.

The ability to use the software with ease to perform the data analysis to meet the engagement objectives.

B.

The ability to purchase upgraded features of the software that allow for more In-depth analysis of the big data.

C.

The ability to ensure that big data entered into the software is secure from potential compromises or loss.

D.

The ability to download the software onto the appropriate computers for use in analyzing the big data.

Full Access
Question # 52

Which of the following is a characteristic of an emerging industry?

A.

Established strategy of players.

B.

Low number of new firms.

C.

High unit costs.

D.

Technical expertise.

Full Access
Question # 53

An organization produces finished lumber for the construction industry.

Which of the following inventory valuation methods will lead to the highest profit, assuming all other variables remain the same in a period of rising material costs?

A.

Average-cost method.

B.

Weighted cost method.

C.

First-in, first-out (FIFO).

D.

Specific identification.

Full Access
Question # 54

Maintenance cost at a hospital was observed to increase as activity level increased. The following data was gathered:

January: 5,600 patient days; maintenance cost $7,900

February: 7,100 patient days; maintenance cost $8,500

March: 5,000 patient days; maintenance cost $7,400

April: 6,500 patient days; maintenance cost $8,200

May: 7,300 patient days; maintenance cost $9,100

June: 8,000 patient days; maintenance cost $9,800

If the cost of maintenance is expressed in an equation, what is the independent variable for this data?

A.

Fixed cost.

B.

Variable cost.

C.

Total maintenance cost.

D.

Patient days.

Full Access
Question # 55

An organization has 1,000 units of a defective item in stock. Per unit, market price is $10; production cost is $4; and the defect selling price is $5. What is the carrying amount (inventory value) of defects at year-end?

A.

$0

B.

$4,000

C.

$5,000

D.

$10,000

Full Access
Question # 56

Which of the following devices best controls both physical and logical access to information systems?

A.

Plenum.

B.

Biometric lock.

C.

Identification card.

D.

Electromechanical lock.

Full Access
Question # 57

During a review of the accounts payable process, an internal auditor gathered all of the vendor payment transactions for the past 24 months. The auditor then used an Analytics tool to identify the top five vendors that received the highest sum of payments. Which of the following analytics techniques did the auditor apply?

A.

Process analysis

B.

Process mining

C.

Data analysis.

D.

Data mining

Full Access
Question # 58

Which of the following capital budgeting techniques considers the tune value of money?

A.

Annual rate of return.

B.

Incremental analysis.

C.

Discounted cash flow.

D.

Cash payback

Full Access
Question # 59

According to Maslow ' s hierarchy of needs theory, which of the following best describes a strategy where a manager offers an assignment to a subordinate specifically to support his professional growth and future advancement?

A.

Esteem by colleagues.

B.

Self-fulfillment

C.

Series of belonging in the organization

D.

Job security

Full Access
Question # 60

Which of the following responsibilities would ordinarily fall under the help desk function of an organization?

A.

Maintenance service items such as production support

B.

Management of infrastructure services, including network management

C.

Physical hosting of mainframes and distributed servers

D.

End-to-end security architecture design

Full Access
Question # 61

Which of the following should internal auditors be attentive of when reviewing personal data consent and opt-in/opt-out management process?

A.

Whether customers are asked to renew their consent for their data processing at least quarterly.

B.

Whether private data is processed in accordance with the purpose for which the consent was obtained?

C.

Whether the organization has established explicit and entitywide policies on data transfer to third parties.

D.

Whether customers have an opportunity to opt-out the right to be forgotten from organizational records and systems.

Full Access
Question # 62

An organization has outsourced its payroll function to a third-party service provider. Which of the following contract clauses is most important to include in the outsourcing agreement to ensure access to records of the third-party provider?

A.

A termination clause.

B.

A right-to-audit clause.

C.

A confidentiality clause.

D.

A data security accountability clause.

Full Access
Question # 63

Which of the following assumptions regarding cost-volume-profit analysis is true?

A.

Costs are affected by changes in activity only.

B.

The behavior of costs and revenues is inverse.

C.

When more than one type of product is sold, the sales mix changes.

D.

Only variable costs have to be classified accurately.

Full Access
Question # 64

According to IIA guidance, which of the following corporate social responsibility evaluation activities may be performed by the internal audit activity?

    Consult on CSR program design and implementation.

    Serve as an advisor on CSR governance and risk management.

    Review third parties for contractual compliance with CSR terms.

    Identify and mitigate risks to help meet the CSR program objectives.

A.

1, 2, and 3

B.

1, 2, and 4

C.

1, 3, and 4

D.

2, 3, and 4

Full Access
Question # 65

What security feature would Identity a legitimate employee using her own smart device to gam access to an application run by the organization?

A.

Using a jailbroken or rooted smart device feature.

B.

Using only smart devices previously approved by the organization.

C.

Obtaining written assurance from the employee that security policies and procedures are followed.

D.

Introducing a security question known only by the employee.

Full Access
Question # 66

Which of the following is generally considered a best practice related to data backup?

    Performing full system backups on weekdays.

    Storing system backups onsite in a secured location.

    Testing system backup media periodically.

    Verifying backup media can be retrieved within seven years.

A.

2 only.

B.

3 only.

C.

1, 2, and 3 only.

D.

2, 3, and 4 only.

Full Access
Question # 67

Which of the following describes a benefit of using data analytics during an audit engagement?

A.

An increased number of data extracts obtained from IT personnel.

B.

A reduced audit risk by focusing risk assessment and stratifying the population.

C.

A broadened scope of assurance services through the increase of audit staff.

D.

An increased performance level of data analysis that enables reduced time for audit planning.

Full Access
Question # 68

Which of the following statements about matrix organizations is false?

A.

In a matrix organization, conflict between functional and product managers may arise.

B.

In a matrix organization, staff under dual command is more likely to suffer stress at work.

C.

Matrix organizations offer the advantage of greater flexibility.

D.

Matrix organizations minimize costs and simplify communication.

Full Access
Question # 69

Which of the following is true regarding the use of remote wipe for smart devices?

A.

It can restore default settings and lock encrypted data when necessary.

B.

It enables the erasure and reformatting of secure digital (SD) cards.

C.

It can delete data backed up to a desktop for complete protection if required.

D.

It can wipe data that is backed up via cloud computing

Full Access
Question # 70

An organization has decided to allow its managers to use their own smart phones at work. With this change, which of the following is most important to Include In the IT department ' s comprehensive policies and procedures?

A.

Required documentation of process for discontinuing use of the devices

B.

Required removal of personal pictures and contacts.

C.

Required documentation of expiration of contract with service provider.

D.

Required sign-off on conflict of interest statement.

Full Access
Question # 71

The management of working capital is most crucial for which of the following aspects of business?

A.

Liquidity

B.

Profitability

C.

Solvency

D.

Efficiency

Full Access
Question # 72

Which of the following statements is true regarding internal audit methodologies?

A.

One of the main objectives of internal audit methodologies is to enable audit clients to validate audit observations

B.

IIA guidance states that they should be made available to all stakeholders on the organization’s webpage

C.

One of the main objectives of internal audit methodologies is to ensure the execution of organizational strategy and risk management

D.

Although the content of internal audit methodologies is determined by the chief audit executive, alignment with principles of confidentiality and competency must be demonstrated

Full Access
Question # 73

Which of the following information security controls has the primary function of preventing unauthorized outside users from accessing an organization ' s data through the organization ' s network?

A.

Firewall.

B.

Encryption.

C.

Antivirus.

D.

Biometrics.

Full Access
Question # 74

Which of the following descriptions of the internal control system are indicators that risks are managed effectively?

    Existing controls promote compliance with applicable laws and regulations.

    The control environment is designed to address all identified risks to the organization.

    Key controls for significant risks to the organization remain consistent over time.

    Monitoring systems are in place to alert management to unexpected events.

A.

1 and 3.

B.

1 and 4.

C.

2 and 3.

D.

2 and 4.

Full Access
Question # 75

Which of the following distinguishes the added-value negotiation method from traditional negotiating methods?

A.

Each party ' s negotiator presents a menu of options to the other party.

B.

Each party adopts one initial position from which to start.

C.

Each negotiator minimizes the information provided to the other party.

D.

Each negotiator starts with an offer, which is optimal from the negotiator ' s perspective.

Full Access
Question # 76

An analytical model determined that on Friday and Saturday nights the luxury brands stores should be open for extended hours and with a doubled number of employees

present; while on Mondays and Tuesdays costs can be minimized by reducing the number of employees to a minimum and opening only for evening hours Which of the

following best categorizes the analytical model applied?

A.

Descriptive.

B.

Diagnostic.

C.

Prescriptive.

D.

Prolific.

Full Access
Question # 77

When auditing databases, which of the following risks would an Internal auditor keep In mind In relation to database administrators?

A.

The risk that database administrators will disagree with temporarily preventing user access to the database for auditing purposes.

B.

The risk that database administrators do not receive new patches from vendors that support database software in a timely fashion.

C.

The risk that database administrators set up personalized accounts for themselves, making the audit time consuming.

D.

The risk that database administrators could make hidden changes using privileged access.

Full Access
Question # 78

Which of the following situations best illustrates a " false positive " in the performance of a spam filter?

A.

The spam filter removed Incoming communication that included certain keywords and domains.

B.

The spam filter deleted commercial ads automatically, as they were recognized as unwanted.

C.

The spam filter routed to the " junk|r folder a newsletter that appeared to include links to fake websites.

D.

The spam filter blocked a fitness club gift card that coworkers sent to an employee for her birthday.

Full Access
Question # 79

For employees, the primary value of implementing job enrichment is which of the following?

A.

Validation of the achievement of their goals anti objectives

B.

Increased knowledge through the performance of additional tasks

C.

Support for personal growth and a meaningful work experience

D.

An increased opportunity to manage better the work done by their subordinates

Full Access
Question # 80

Under a value-added taxing system:

A.

Businesses must pay a tax only if they make a profit.

B.

The consumer ultimately bears the cost of the tax through higher prices.

C.

Consumer savings are discouraged.

D.

The amount of value added is the difference between an organization ' s sales and its cost of goods sold.

Full Access
Question # 81

An organization plans to upgrade its IT network to address a recent ransomware incident that hampered operations for weeks. The ransomware was the result of lapses in access to the network that exposed sensitive information.

Which of the following is a risk that could significantly be impacted by the organization’s planned change to its IT network?

A.

The organization lacks the necessary senior management to ensure that project objectives are met.

B.

The organization’s recent hiring of additional staff to the IT department would create more scrutiny of end user activity.

C.

The organization creates new processes and policies that employees feel are too burdensome.

D.

The organization experiences continuing issues that hamper employees’ ability to provide quality customer service.

Full Access
Question # 82

A chief audit executive (CAE) joined an organization in the middle of the financial year. A risk-based annual audit plan has been approved by the board and is already underway. However, after discussions with key stakeholders, the CAE realizes that some significant key risk areas have not been covered in the original audit plan. How should the CAE respond?

A.

Commit to delivering the original annual audit plan as it has already been approved by the board

B.

Revise the plan to incorporate the newly identified risks, and communicate significant interim changes to senior management and the board for review and approval

C.

Ensure that the newly identified risks are included in the next year ' s annual audit plan

D.

Assign internal auditors to immediately perform assurance engagements in the areas where the new risks have been identified, due to their significance

Full Access
Question # 83

An organization has recorded the following profit and expenses:

Profit before interest and tax: $200,000

Sales: $2,300,000

Purchases of materials: $700,000

Interest expenses: $30,000

If the value-added tax rate is 20 percent and the corporate tax rate is 30 percent, which of the following is the amount of VAT that the organization has to pay?

A.

$34,000

B.

$51,000

C.

$60,000

D.

$320,000

Full Access
Question # 84

Which of the following statements is true regarding activity-based costing (ABC)?

A.

An ABC costing system is similar to conventional costing systems in how it treats the allocation of manufacturing overhead.

B.

An ABC costing system uses a single unit-level basis to allocate overhead costs to products.

C.

An ABC costing system may be used with either a job order or a process cost accounting system.

D.

The primary disadvantage of an ABC costing system is less accurate product costing.

Full Access
Question # 85

Which of the following are typical audit considerations for a review of authentication?

    Authentication policies and evaluation of controls transactions.

    Management of passwords, independent reconciliation, and audit trail.

    Control self-assessment tools used by management.

    Independent verification of data integrity and accuracy.

A.

1, 2, and 3

B.

1, 2, and 4

C.

1, 3, and 4

D.

2, 3, and 4

Full Access
Question # 86

Which of the following lists best describes the classification of manufacturing costs?

A.

Direct materials, indirect materials, raw materials.

B.

Overhead costs, direct labor, direct materials.

C.

Direct materials, direct labor, depreciation on factory buildings.

D.

Raw materials, factory employees ' wages, production selling expenses.

Full Access
Question # 87

An organization uses the management-by-objectives method whereby employee performance is based on defined goals. Which of the following statements is true regarding this approach?

A.

It is particularly helpful to management when the organization is facing rapid change.

B.

It is a more successful approach when adopted by mechanistic organizations.

C.

It is mere successful when goal setting is performed not only by management, but by all team members, including lower-level staff.

D.

It is particularly successful in environments that are prone to having poor employer-employee relations.

Full Access
Question # 88

Which of the following corporate social responsibility strategies is likely to be most effective in minimizing confrontations with influential activists and lobbyists?

A.

Continually evaluate the needs and opinions of all stakeholder groups.

B.

Ensure strict compliance with applicable laws and regulations to avoid incidents.

C.

Maintain a comprehensive publicity campaign that highlights the organization ' s efforts.

D.

Increase goodwill through philanthropic activities among stakeholder communities.

Full Access
Question # 89

A newly hired chief audit executive (CAE) reviews and will revise the existing internal audit strategy. What should the CAE initially refer to when revising the internal audit strategy?

A.

Legal and regulatory requirements

B.

Organization-wide risk assessment results

C.

Key internal control activities

D.

Organizational business objectives

Full Access
Question # 90

Which of the following is an example of a nonfinancial internal failure quality cost?

A.

Decreasing gross profit margins over time.

B.

Foregone contribution margin on lost sales.

C.

Defective units shipped to customers.

D.

Excessive time to convert raw materials into finished goods.

Full Access
Question # 91

Which of the following best describes depreciation?

A.

It is a process of allocating cost of assets between periods.

B.

It is a process of assets valuation.

C.

It is a process of accumulating adequate funds to replace assets.

D.

It is a process of measuring decline in the value of assets because of obsolescence

Full Access
Question # 92

An organization sells 1,000 shares of its treasury stock at $15 per share previously acquired at $10 per share.

Which of the following statements is true?

A.

The organization should record a $5,000 gain on sale of treasury stock.

B.

The organization should record $15,000 as a debit to treasury stock.

C.

The organization should record $5,000 as a credit to paid-in capital.

D.

The organization should record a $10,000 debit to paid-capital account.

Full Access
Question # 93

Which of the following would be most likely found in an internal audit procedures manual?

A.

A summary of the strategic plan of the area under review

B.

Appropriate response options for when findings are disputed by management

C.

An explanation of the resources needed for each engagement

D.

The extent of the auditor ' s authority to collect data from management

Full Access
Question # 94

When using data analytics during a review of the procurement process, what is the first step in the analysis process?

A.

Identify data anomalies and outliers

B.

Define questions to be answered

C.

Identify data sources available

D.

Determine the scope of the data extract

Full Access
Question # 95

An internal auditor for a pharmaceutical company as planning a cybersecurity audit and conducting a risk assessment. Which of the following would be considered the most significant cyber threat to the organization?

A.

Cybercriminals hacking into the organization ' s time and expense system to collect employee personal data.

B.

Hackers breaching the organization ' s network to access research and development reports

C.

A denial-of-service attack that prevents access to the organization ' s website.

D.

A hacker accessing she financial information of the company

Full Access
Question # 96

Which of the following should be established by management during implementation of big data systems to enable ongoing production monitoring?

A.

Key performance indicators.

B.

Reports of software customization.

C.

Change and patch management.

D.

Master data management

Full Access
Question # 97

To execute its new strategy of differentiation, based mainly on innovation, flexibility, and responsiveness, while maintaining control on operations and reducing any duplication of resources, an organization has introduced many changes that are relevant to its organizational structure. Which of the following structures would best fit the new strategy?

A.

The functional structure.

B.

The divisional structure.

C.

The team approach.

D.

The virtual network approach.

Full Access
Question # 98

Which of the following statements accurately describes the responsibility of the internal audit activity regarding IT governance?

    The internal audit activity does not have any responsibility because IT governance is the responsibility of the board and senior management of the organization.

    The internal audit activity must assess whether the IT governance of the organization supports the organization ' s strategies and objectives.

    The internal audit activity may assess whether the IT governance of the organization supports the organization ' s strategies and objectives.

    The internal audit activity may accept requests from management to perform advisory services regarding how the IT governance of the organization supports the organization ' s strategies and objectives.

A.

1 only

B.

4 only

C.

2 and 4

D.

3 and 4

Full Access
Question # 99

An organization that soils products to a foreign subsidiary wants to charge a price that wilt decrease import tariffs. Which of the following is the best course of action for the organization?

A.

Decrease the transfer price

B.

Increase the transfer price

C.

Charge at the arm ' s length price

D.

Charge at the optimal transfer price

Full Access
Question # 100

At what point during the systems development process should an internal auditor verify that the new application ' s connectivity to the organization ' s other systems has been established correctly?

A.

Prior to testing the new application.

B.

During testing of the new application.

C.

During implementation of the new application.

D.

During maintenance of the new application.

Full Access
Question # 101

An internal auditor is using data analytics to focus on high-risk areas during an engagement. The auditor has obtained data and is working to eliminate redundancies in the data. Which of the following statements is true regarding this scenario?

A.

The auditor is normalizing data in preparation for analyzing it.

B.

The auditor is analyzing the data in preparation for communicating the results.

C.

The auditor is cleaning the data in preparation for determining which processes may be involved.

D.

The auditor is reviewing the data prior to defining the question.

Full Access
Question # 102

A key advantage of developing a computer application by using the prototyping approach is that it:

A.

Does not require testing for user acceptance.

B.

Allows applications to be portable across multiple system platforms.

C.

Is less expensive since it is self-documenting.

D.

Better involves users in the design process.

Full Access
Question # 103

Which of the following statements is true regarding an investee that received a dividend distribution from an entity and is presumed to have little influence over the entity?

A.

The cash dividends received increase the investee investment account accordingly.

B.

The investee must adjust the investment account by the ownership interest

C.

The investment account is adjusted downward by the percentage of ownership.

D.

The investee must record the cash dividends as dividend revenue

Full Access
Question # 104

Which of the following items represents the first thing that should be done with obtained dote in the data analytics process?

A.

Verify completeness and accuracy.

B.

Verify existence and accuracy.

C.

Verify completeness and integrity.

D.

Verify existence and completeness.

Full Access
Question # 105

Which of the following best describes a transformational leader, as opposed to a transactional leader?

A.

The leader searches for deviations from the rules and standards and intervenes when deviations exist.

B.

The leader intervenes only when performance standards are not met.

C.

The leader intervenes to communicate high expectations.

D.

The leader does not intervene to promote problem-solving

Full Access
Question # 106

Which of the following strategies is most appropriate for an industry that is in decline?

A.

Invest in marketing.

B.

Invest in research and development.

C.

Control costs.

D.

Shift toward mass production.

Full Access
Question # 107

Which of the following statements is true regarding the management-by-objectives (MBO) approach?

A.

Management by objectives is most helpful in organizations that have rapid changes

B.

Management by objectives is most helpful in mechanistic organizations with rigidly defined tasks

C.

Management by objectives helps organizations to keep employees motivated

D.

Management by objectives helps organizations to distinguish clearly strategic goals from operational goals

Full Access
Question # 108

A holding company set up a centralized group technology department, using a local area network with a mainframe computer to process accounting information for all companies within the group. An internal auditor would expect to find all of the following controls within the technology department except:

A.

Adequate segregation of duties between data processing controls and file security controls.

B.

Documented procedures for remote job entry and for local data file retention.

C.

Emergency and disaster recovery procedures and maintenance agreements in place to ensure continuity of operations.

D.

Established procedures to prevent and detect unauthorized changes to data files.

Full Access
Question # 109

According to IIA guidance on IT auditing, which of the following would not be an area examined by the internal audit activity?

A.

Access system security.

B.

Policy development.

C.

Change management.

D.

Operations processes.

Full Access
Question # 110

Which of the following are the most common characteristics of big data?

A.

Visibility, validity, vulnerability

B.

Velocity, variety, volume

C.

Complexity, completeness, constancy

D.

Continuity, control, convenience

Full Access
Question # 111

An internal auditor was assigned to test for ghost employees using data analytics. The auditor extracted employee data from human resources and payroll. Using spreadsheet functions, the auditor matched data sets by name and assumed that employees who were not present in each data set should be investigated further. However, the results seemed erroneous, as very few employees matched across all data sets. Which of the following data analytics steps has the auditor most likely omitted?

A.

Data analysis.

B.

Data diagnostics.

C.

Data velocity.

D.

Data normalization.

Full Access
Question # 112

A chief audit executive wants to implement an enterprisewide resource planning software. Which of the following internal audit assessments could provide overall assurance on the likelihood of the software implementation ' s success?

A.

Readiness assessment.

B.

Project risk assessment.

C.

Post-implementation review.

D.

Key phase review.

Full Access
Question # 113

A manager at a publishing company received an email that appeared to be from one of her vendors with an attachment that contained malware embedded in an Excel spreadsheet . When the spreadsheet was opened, the cybercriminal was able to attack the company ' s network and gain access to an unpublished and highly anticipated book. Which of the following controls would be most effective to prevent such an attack?

A.

Monitoring network traffic.

B.

Using whitelists and blacklists to manage network traffic.

C.

Restricting access and blocking unauthorized access to the network

D.

Educating employees throughout the company to recognize phishing attacks.

Full Access
Question # 114

The process of scenario planning begins with which of the following steps?

A.

Determining the trends that will influence key factors in the organization ' s environment.

B.

Selecting the issue or decision that will impact how the organization conducts future business.

C.

Selecting leading indicators to alert the organization of future developments.

D.

Identifying how customers, suppliers, competitors, employees, and other stakeholders will react.

Full Access
Question # 115

A senior payroll accountant was responsible for three business units. When the number of employees increased considerably, another accountant was hired and became responsible for one of the units. However, an access rights attestation from the senior payroll accountant remained the same, despite an internal policy requiring payroll access to be restricted. Which of the following controls most likely failed?

A.

Reauthorization controls.

B.

Authorization controls.

C.

Authentication controls.

D.

Segregation of duties.

Full Access
Question # 116

Which of the following techniques is the most relevant when an internal auditor conducts a valuation of an organization ' s physical assets?

A.

Observation.

B.

Inspection.

C.

Original cost.

D.

Vouching.

Full Access
Question # 117

Which of the following is useful for forecasting the required level of inventory?

    Statistical modeling.

    Information about seasonal variations in demand.

    Knowledge of the behavior of different business cycles.

    Pricing models linked to seasonal demand.

A.

1 and 2 only

B.

2 and 3 only

C.

1, 2, and 3 only

D.

1, 2, 3, and 4

Full Access
Question # 118

Which of the following organization structures would most likely be able to cope with rapid changes and uncertainties?

A.

Decentralized

B.

Centralized

C.

Departmentalized

D.

Tall structure

Full Access
Question # 119

Which of the following methods has the lowest risk of inaccurate authentication?

A.

Fingerprint identification.

B.

Complex passwords.

C.

Signature verification.

D.

Personal security questions.

Full Access
Question # 120

Which of the following scenarios would cause a chief audit executive (CAE) to immediately discontinue using any statements that would indicate conformance with the Global Internal Audit Standards in an audit report?

A.

The internal audit function used a risk-based approach to create the internal audit plan

B.

The engagement supervisor considered requests from senior management regarding engagements to include in the internal audit plan

C.

The CAE only accepted engagements that the internal audit function collectively had the knowledge to perform

D.

The activity under review restricted the internal audit function ' s ability to access records, impacting the audit results

Full Access
Question # 121

The board and senior management agree to outsource the internal audit function. Which of the following is true regarding the company’s quality assurance and improvement program (QAIP)?

A.

The organization is responsible for maintaining an effective QAIP

B.

The organization is responsible for the internal assessment of the QAIP

C.

The service provider is responsible for the external assessment of the QAIP every three years

D.

The QAIP should be postponed until the organization insources or cosources the internal audit function

Full Access
Question # 122

During which phase of the contracting process ere contracts drafted for a proposed business activity?

A.

Initiation phase.

B.

Bidding phase

C.

Development phase

D.

Management phase

Full Access
Question # 123

An internal auditor found the following information while reviewing the monthly financial statements for a wholesaler of safety glasses: Opening inventory: 1,000 units at $2 per unit; Purchased: 5,000 units at $3 per unit; Sold: 3,000 units at $7 per unit. The cost of goods sold was reported at $8,500. Which of the following inventory methods was used to derive this value?

A.

Average cost method

B.

First-in, first-out (FIFO) method

C.

Specific identification method

D.

Activity-based costing method

Full Access
Question # 124

Which of the following roles would be least appropriate for the internal audit activity to undertake with regard to an organization ' s corporate social responsibility program?

A.

Consult on project design and implementation of the CSR program.

B.

Serve as an advisor on internal controls related to CSR.

C.

Identify and prioritize the CSR issues that are important to the organization.

D.

Evaluate the effectiveness of the organization ' s CSR efforts.

Full Access
Question # 125

Which of the following controls is the most effective for ensuring confidentially of transmitted information?

A.

Firewall.

B.

Antivirus software.

C.

Passwords.

D.

Encryption.

Full Access
Question # 126

Which stage of group development is characterized by a decrease in conflict and hostility among group members and an increase in cohesiveness?

A.

Forming stage.

B.

Norming stage.

C.

Performing stage.

D.

Storming stage.

Full Access
Question # 127

How can the chief audit executive best provide the internal audit function with the resources needed to fulfill the annual audit plan?

A.

Improve skills by strengthening staff competencies

B.

Map the audit risk assessment to the organization ' s strategic plan

C.

Collaborate with other risk management functions in the organization

D.

Refine its audit processes according to the Global Internal Audit Standards

Full Access
Question # 128

Which of the following statements regarding organizational governance is not correct?

A.

An effective internal audit function is one of the four cornerstones of good governance.

B.

Those performing governance activities are accountable to the customer.

C.

Accountability is one of the key elements of organizational governance.

D.

Governance principles and the need for an internal audit function are applicable to governmental and not-for-profit activities.

Full Access
Question # 129

A organization finalized a contract in which a vendor is expected to design, procure, and construct a power substation for $3,000,000. In this scenario, the organization agreed to which of the following types of contracts?

A.

A cost-reimbursable contract.

B.

A lump-sum contract.

C.

A time and material contract.

D.

A bilateral contract.

Full Access
Question # 130

Which of the following is a primary driver behind the creation and prloritteation of new strategic Initiatives established by an organization?

A.

Risk tolerance

B.

Performance

C.

Threats and opportunities

D.

Governance

Full Access
Question # 131

An internal audit function has commenced its annual follow-up activity. An internal auditor has been assigned to verify whether the recommendations from an audit engagement completed three months ago were implemented by the business unit. The auditor had not participated in that audit engagement. What should the auditor do first?

A.

Conduct interviews with senior management of the business unit

B.

Request information from the business unit regarding the corrective actions taken

C.

Review the previous audit findings and management ' s response

D.

Conduct a walkthrough of the business unit

Full Access
Question # 132

The internal audit function conducted an engagement on maintenance operations of a construction organization and identified several issues of medium importance. The head of maintenance proposed an improvement plan with deadlines and personnel responsible. The internal audit function issued the final report to senior management. Senior management was dissatisfied with the report as they believed that improvement plan deadlines should be considerably shorter. Which of the following should the internal audit function change in the reporting process?

A.

Discontinue discussing draft reports with responsible employees, as their input is needed during fieldwork only

B.

Involve senior management at the draft report stage and in the development of action plans

C.

Request senior management to issue a separate memo regarding their changes to deadlines

D.

Invite senior management to the board meeting regarding engagement results so that they can express their concerns

Full Access
Question # 133

Which of the following should the chief audit executive agree upon with the board before starting an external assessment of the internal audit function?

A.

The audit areas that should be reviewed

B.

The level of testing that will be required

C.

The qualifications needed on the external assessment team

D.

The specialized skills that each external assessment team member needs

Full Access
Question # 134

Which of the following statements is accurate when planning for an external quality assurance assessment of the internal audit function?

A.

The external assessment would include the audit function’s compliance with laws and regulations

B.

The selected qualified assessor can be from the organization’s shared services team

C.

The external assessment team members must work for an accounting firm

D.

The frequency of the performance of assessments should be considered by the assessor

Full Access
Question # 135

When examining; an organization ' s strategic plan, an internal auditor should expect to find which of the following components?

A.

Identification of achievable goals and timelines

B.

Analysis of the competitive environment.

C.

Plan for the procurement of resources

D.

Plan for progress reporting and oversight.

Full Access
Question # 136

Which of the following purchasing scenarios would gain the greatest benefit from implementing electronic data interchange?

A.

A time-sensitive just-in-time purchase environment.

B.

A large volume of custom purchases.

C.

A variable volume sensitive to material cost.

D.

A currently inefficient purchasing process.

Full Access
Question # 137

Which of the following statements is accurate regarding the use of Secure Sockets Layer (SSL) as a control?

A.

It supports the authentication of information sent to a server.

B.

It prevents phishing attacks that redirect users to malicious sites.

C.

It prevents malware infections.

D.

It identifies each client-server session using temporary tokens.

Full Access
Question # 138

Which of the following is likely to have an expiration date and may contain stored clear text passwords?

A.

Cookie.

B.

Universal resource locator (URL).

C.

Hypertext transport protocol (HTTP).

D.

Browser.

Full Access
Question # 139

Which of the following techniques would best detect an inventory fraud scheme?

A.

Analyze Invoice payments just under individual authorization limits.

B.

Analyze stratification of inventory adjustments by warehouse location.

C.

Analyze inventory invoice amounts and compare with approved contract amounts.

D.

Analyze differences discovered during duplicate payment testing

Full Access
Question # 140

Which of the following can be viewed as a potential benefit of an enterprisewide resource planning system?

A.

Real-time processing of transactions and elimination of data redundancies.

B.

Fewer data processing errors and more efficient data exchange with trading partners.

C.

Exploitation of opportunities and mitigation of risks associated with e-business.

D.

Integration of business processes into multiple operating environments and databases.

Full Access
Question # 141

Which of the following statements is correct regarding corporate compensation systems and related bonuses?

    A bonus system should be considered part of the control environment of an organization and should be considered in formulating a report on internal control.

    Compensation systems are not part of an organization ' s control system and should not be reported as such.

    An audit of an organization ' s compensation system should be performed independently of an audit of the control system over other functions that impact corporate bonuses.

A.

1 only

B.

2 only

C.

3 only

D.

2 and 3 only

Full Access
Question # 142

As it relates to the data analytics process, which of the following best describes the purpose of an internal auditor who cleaned and normalized cate?

A.

The auditor eliminated duplicate information.

B.

The auditor organized data to minimize useless information.

C.

The auditor made data usable for a specific purpose by ensuring that anomalies were Identified and corrected.

D.

The auditor ensured data fields were consistent and that data could be used for a specific purpose.

Full Access
Question # 143

An organization decided to outsource its human resources function. As part of its process migration, the organization is implementing controls over sensitive employee data.

What would be the most appropriate directive control in this area?

A.

Require a Service Organization Controls (SOC) report from the service provider

B.

Include a data protection clause in the contract with the service provider.

C.

Obtain a nondisclosure agreement from each employee at the service provider who will handle sensitive data.

D.

Encrypt the employees ' data before transmitting it to the service provider

Full Access
Question # 144

The percentage of sales method, rather than the percentage of receivables method, would be used to estimate uncollectible accounts if an organization seeks to:

A.

Use an aging schedule to more closely estimate uncollectible accounts.

B.

Eliminate the need for an allowance for doubtful accounts.

C.

Emphasize the accuracy of the net realizable value of the receivables on the balance sheet.

D.

Use a method that approximates the matching principle.

Full Access
Question # 145

An organization with global headquarters in the United States has subsidiaries in eight other nations. If the organization operates with an ethnocentric attitude, which of the following statements is true?

A.

Standards used for evaluation and control are determined at local subsidiaries, not set by headquarters

B.

Orders, commands, and advice are sent to the subsidiaries from headquarters

C.

People of local nationality are developed for the best positions within their own country

D.

There is a significant amount of collaboration between headquarters and subsidiaries

Full Access
Question # 146

An internal audit activity is piloting a data analytics model, which aims to identify anomalies in payments to vendors and potential fraud indicators. Which of the following would be the most appropriate criteria for assessing the success of the piloted model?

A.

The percentage of cases flagged by the model and confirmed as positives.

B.

The development and maintenance costs associated with the model

C.

The feedback of auditors involved with developing the model.

D.

The number of criminal investigations initiated based on the outcomes of the model

Full Access
Question # 147

A manager decided to build his team ' s enthusiasm by giving encouraging talks about employee empowerment, hoping to change the perception that management should make all decisions in the department.

The manager is most likely trying to impact which of the following components of his team ' s attitude?

A.

Affective component.

B.

Cognition component.

C.

Thinking component.

D.

Behavioral component.

Full Access
Question # 148

Which of the following statements distinguishes a router from a typical switch?

A.

A router operates at layer two. while a switch operates at layer three of the open systems interconnection model.

B.

A router transmits data through frames, while a switch sends data through packets.

C.

A router connects networks, while a switch connects devices within a network.

D.

A router uses a media access control address during the transmission of data, whie a switch uses an internet protocol address.

Full Access
Question # 149

Which of the following management statements illustrates how natural bias can lead to poor decision making?

A.

" Although we previously agreed that we would launch a new product this year, we changed our minds and decided to terminate the launch. "

B.

" Due to the crisis that arose last week, we are not prepared to provide the board with an estimate of next year ' s revenue. "

C.

" We will continue manufacturing the same products in the same way that we always have, because this tradition has made our organization successful. "

D.

" We decided to postpone expanding into the new market because of high uncertainty at this time. "

Full Access
Question # 150

Which of the following performance measures would be appropriate for evaluating an investment center, which has responsibility for its revenues, costs, and investment base, but would not be appropriate for evaluating cost, revenue, or profit centers?

A.

A flexible budget.

B.

Variance analysis.

C.

A contribution margin income statement by segment.

D.

Residual income.

Full Access
Question # 151

Which of the following controls is the most effective in mitigating activities of bots that continuously attempt to access a user’s account?

A.

Password length.

B.

User session timeout.

C.

User account lockout.

D.

Password aging.

Full Access
Question # 152

An intruder posing as the organization ' s CEO sent an email and tricked payroll staff into providing employees ' private tax information. What type of attack was perpetrated?

A.

Boundary attack.

B.

Spear phishing attack.

C.

Brute force attack.

D.

Spoofing attack.

Full Access
Question # 153

Which of the following serves as a safeguard to protect the confidentiality of information being transmitted from an internal network to an external network?

A.

A cloud network.

B.

A mobile network.

C.

An intranet.

D.

A virtual private network.

Full Access
Question # 154

A capital investment project will have a higher net present value, everything else being equal, if it has:

A.

A higher initial investment level.

B.

A higher discount rate.

C.

Cash inflows that are larger in the later years of the life of the project.

D.

Cash inflows that are larger in the earlier years of the life of the project.

Full Access
Question # 155

Which of the following performance measures disincentives engaging in earnings management?

A.

Linking performance to profitability measures such as return on investment.

B.

Linking performance to the stock price.

C.

Linking performance to quotas such as units produced.

D.

Linking performance to nonfinancial measures such as customer satisfaction and employees training

Full Access
Question # 156

An internal auditor is auditing their organization’s termination process. A primary objective of this engagement is to verify that exit interviews were conducted for all terminated employees over the last two years. The auditor discovered that not all employees received exit interviews.

Which of the following risks could this lead to?

A.

The risk of employee turnover.

B.

The risk of noncompliance with a local labor law.

C.

The risk of incorrect severance payments.

D.

The risk of a confidentiality breach.

Full Access
Question # 157

A significant project is nearing its development stage end, and line management intends to apply for a final investment decision from senior management at an upcoming meeting. The internal audit function is at the fieldwork stage of an assurance engagement related to this project and discovers that tenders conducted for the project were not carried out transparently by line management. The audit report will not be ready by the upcoming senior management meeting. Which of the following actions is the most appropriate next step for the chief audit executive?

A.

Escalate the issue to the chief risk officer

B.

Raise the issue with senior management

C.

Continue with the assurance engagement as planned

D.

Place the assurance engagement on hold due to inappropriate timing

Full Access
Question # 158

An organization ' s chief audit executive scheduled an assurance engagement on the key processes and controls related to organizational culture. Which approach to auditing the organization ' s culture did the CAE use?

A.

Integrated approach.

B.

Top-down approach.

C.

Targeted approach.

D.

Blended approach.

Full Access
Question # 159

Which of the following principles is shared by both hierarchical and open organizational structures?

A superior can delegate the authority to make decisions but cannot delegate the ultimate responsibility for the results of those decisions.

A supervisor ' s span of control should not exceed seven subordinates.

Responsibility should be accompanied by adequate authority.

Employees at all levels should be empowered to make decisions.

A.

1 and 3 only

B.

1 and 4 only

C.

2 and 3 only

D.

3 and 4 only

Full Access
Question # 160

During her annual performance review, a sales manager admits that she experiences significant stress due to her job but stays with the organization because of the high bonuses she earns. Which of the following best describes her primary motivation to remain in the job?

A.

Intrinsic reward.

B.

Job enrichment

C.

Extrinsic reward.

D.

The hierarchy of needs.

Full Access
Question # 161

Which of the following is most appropriately placed in the financing section of an organization ' s cash budget?

A.

Collections from customers

B.

Sale of securities.

C.

Purchase of trucks.

D.

Payment of debt, including interest

Full Access
Question # 162

According to the Standards, the internal audit activity must evaluate risk exposures relating to which of the following when examining an organization ' s risk management process?

    Organizational governance.

    Organizational operations.

    Organizational information systems.

    Organizational structure.

A.

1 and 3 only

B.

2 and 4 only

C.

1, 2, and 3 only

D.

1, 2, and 4 only

Full Access
Question # 163

Which of the following is not a method for implementing a new application system?

A.

Direct cutover.

B.

Parallel.

C.

Pilot.

D.

Test.

Full Access
Question # 164

A newly appointed board member received an email that appeared to be from the company ' s CEO. The email stated:

“Good morning. As you remember, the closure of projects is our top priority. Kindly organize prompt payment of the attached invoice for our new solar energy partners.” The board member quickly replied to the email and asked under which project the expense should be accounted. Only then did he realize that the sender ' s mail domain was different from the company ' s. Which of the following cybersecurity risks nearly occurred in the situation described?

A.

A risk of spyware and malware.

B.

A risk of corporate espionage.

C.

A ransomware attack risk.

D.

A social engineering risk.

Full Access
Question # 165

Which of the following best describes owner ' s equity?

A.

Assets minus liabilities.

B.

Total assets.

C.

Total liabilities.

D.

Owners contribution plus drawings.

Full Access
Question # 166

Which of the following principles s shared by both hierarchies and open organizational structures?

1. A superior can delegate the authority to make decisions but cannot delegate the ultimate responsibility for the results of those decisions.

2. A supervisor ' s span of control should not exceed seven subordinates.

3. Responsibility should be accompanied by adequate authority.

4. Employees at all levels should be empowered to make decisions.

A.

1 and 3 only

B.

1 and 4 only

C.

2 and 3 only

D.

3 and 4 only

Full Access
Question # 167

Capacity overbuilding is most likely to occur when management is focused on which of the following?

A.

Marketing.

B.

Finance.

C.

Production.

D.

Diversification.

Full Access
Question # 168

According to Herzberg ' s Two-Factor Theory of Motivation, which of the following factors arc mentioned most often by satisfied employees?

A.

Salary and status

B.

Responsibility and advancement

C.

Work conditions and security

D.

Peer relationships and personal life

Full Access
Question # 169

To achieve conformance with the Global Internal Audit Standards, the chief audit executive must include which of the following activities in the quality assurance and improvement program (QAIP)?

A.

Require board oversight of the QAIP

B.

Assess Standards conformance for each individual assurance engagement

C.

Conduct a self-assessment at least once every five years

D.

Report the results of the QAIP to the board

Full Access
Question # 170

Which of the following is a product-oriented definition of a business rather than a market-oriented definition of a business?

A.

We are a people-and-goods mover.

B.

We supply energy.

C.

We make movies.

D.

We provide climate control in the home.

Full Access
Question # 171

Which of the following statements is true regarding data backup?

A.

System backups should always be performed in real-time.

B.

Backups should be stored in a secured location onsite for easy access.

C.

The tape rotation schedule affects how long data is retained.

D.

Backup media should be restored only in case of a hardware or software failure.

Full Access
Question # 172

Which of the following standards would be most useful in evaluating the performance of a customer-service group?

A.

The average time per customer inquiry should be kept to a minimum.

B.

Customer complaints should be processed promptly.

C.

Employees should maintain a positive attitude when dealing with customers.

D.

All customer inquiries should be answered within seven days of receipt.

Full Access
Question # 173

A line on a spreadsheet includes an employee ' s name, date of hire, job title, and monthly salary. Which of the following correctly describes this line information?

A.

Field.

B.

File.

C.

Record.

D.

Database.

Full Access
Question # 174

Which of the following describes the most appropriate set of tests for auditing a workstation ' s logical access controls?

A.

Review the list of people with access badges to the room containing the workstation and a log of those who accessed the room.

B.

Review the password length, frequency of change, and list of users for the workstation ' s login process.

C.

Review the list of people who attempted to access the workstation and failed, as well as error messages.

D.

Review the passwords of those who attempted unsuccessfully to access the workstation and the log of their activity

Full Access
Question # 175

What would an internal auditor do to ensure that a process to mitigate risk is in place for the organization ' s change management process?

A.

Develop and enforce change policies to ensure employees are continually trained.

B.

Apply a risk-based approach and impose segregation of duties related to the change management process.

C.

Conduct a high-level threat analysis and implement a compensating control.

D.

Validate authorization, segregation of duties, testing of changes, and approval to move changes into production.

Full Access
Question # 176

Which of the following controls helps protect externally stored sensitive or confidential data from cyberthreats?

A.

Secure configurations and access controls.

B.

Strong vendor contracts with control reports provided by service organizations.

C.

Active and frequent monitoring of network traffic activities.

D.

Firewalls to block unauthorized processing of transactions.

Full Access
Question # 177

An organization upgraded to a new accounting software. Which of the following activities should be performed by the IT software vendor immediately following the upgrade?

A.

Market analysis lo identify trends

B.

Services to manage and maintain the IT Infrastructure.

C.

Backup and restoration.

D.

Software testing and validation

Full Access
Question # 178

Refer to the exhibit. The figure below shows the network diagram for the activities of a large project. What is the shortest number of days in which the project can be completed?

A.

21 days.

B.

22 days.

C.

27 days.

D.

51 days.

Full Access
Question # 179

Which of the following best describes the chief audit executive ' s responsibility for assessing the organization ' s residual risk?

A.

Create an action plan to mitigate the risk

B.

Incorporate management acceptance of risk in the workpapers as internal audit evidence

C.

Report deviations immediately to the board

D.

Communicate the matter with senior management

Full Access
Question # 180

A retail organization mistakenly did not include $10,000 of inventory in the physical count at the end of the year. What was the impact to the organization’s financial statements?

A.

Cost of sales and net income are understated

B.

Cost of sales and net income are overstated

C.

Cost of sales is understated and net income is overstated

D.

Cost of sales is overstated and net income is understated

Full Access
Question # 181

Which of the following should be the primary consideration of a right-to-audit clause in a contract?

A.

It should be a simple statement to give the contracting organization the right to conduct an audit.

B.

It should clearly state the conditions and criteria necessary to conduct an audit under reasonable and acceptable conditions.

C.

It should be a detailed statement to give the contracted organization the right to conduct an audit.

D.

It should clearly and concisely describe the conditions and criteria to prohibit an organization ' s ability to conduct an audit.

Full Access
Question # 182

Which audit approach should be employed to test the accuracy of information housed in a database on an un-networked computer?

A.

Submit batches of test transactions through the current system and verify with expected results.

B.

Use a test program to simulate the normal data entering process.

C.

Select a sample of records from the database and ensure it matches supporting documentation.

D.

Evaluate compliance with the organization ' s change management process.

Full Access
Question # 183

What impact is there to liabilities on the balance sheet when ending inventory is overstated?

A.

There is no effect on liabilities.

B.

Liabilities are overstated.

C.

Liabilities are understated.

D.

Inventory errors affect income statement only.

Full Access
Question # 184

Senior management has decided to implement the Three Lines of Defense model for risk management. Which of the following best describes senior management ' s duties with regard to this model?

A.

Ensure compliance with the model.

B.

Identify management functions.

C.

Identify emerging issues.

D.

Set goals for implementation.

Full Access
Question # 185

When using the absorption costing approach, which of the following should be categorized as a period cost?

A.

Selling expenses.

B.

Fixed manufacturing overhead.

C.

Direct labor.

D.

Variable manufacturing overhead.

Full Access
Question # 186

According to 11A guidance on IT, which of the following spreadsheets is most likely to be considered a high-risk user-developed application?

A.

A revenue calculation spreadsheet supported with price and volume reports from the production department.

B.

An asset retirement calculation spreadsheet comprised of multiple formulas and assumptions.

C.

An ad-hoc inventory listing spreadsheet comprising details of written-off inventory quantities.

D.

An accounts receivable reconciliation spreadsheet used by the accounting manager to verify balances

Full Access
Question # 187

Which of the following controls would be most efficient to protect business data from corruption and errors?

A.

Controls to ensure data is unable to be accessed without authorization.

B.

Controls to calculate batch totals to identify an error before approval.

C.

Controls to encrypt the data so that corruption is likely ineffective.

D.

Controls to quickly identify malicious intrusion attempts.

Full Access
Question # 188

Which of the following is the most appropriate way lo record each partner ' s initial Investment in a partnership?

A.

At the value agreed upon by the partners.

B.

At book value.

C.

At fair value

D.

At the original cost.

Full Access
Question # 189

In response to a question posed by an internal auditor, management indicated that there is an agreement in place to quickly rent servers and desktop workstations to restore operations from tapes stored at an off-site location. Which of the following plans would the auditor most likely conclude is currently in place for the organization?

A.

A hot recovery plan.

B.

No recovery plan.

C.

A cold recovery plan.

D.

A warm recovery plan.

Full Access
Question # 190

Which of the following borrowing options is an unsecured loan?

A.

Second-mortgage financing from a bank.

B.

An issue of commercial paper.

C.

Pledged accounts receivable.

D.

Asset-based financing.

Full Access
Question # 191

An organization with global headquarters in the United States has subsidiaries in eight other nations. If the organization operates with an ethnocentric attitude, which of the following statements is true?

A.

Standards used for evaluation and control are determined at local subsidiaries, not set by headquarters.

B.

Orders, commands, and advice are sent to the subsidiaries from headquarters.

C.

Poop o of local nationality are developed for the best positions within their own country.

D.

There is a significant amount of collaboration between headquarters and subs diaries.

Full Access
Question # 192

When applied to international economics, the theory of comparative advantage proposes that total worldwide output will be greatest when:

A.

Each nation ' s total imports approximately equal its total exports.

B.

Each good is produced by the nation that has the lowest opportunity cost for that good.

C.

Goods that contribute to a nation ' s balance-of-payments deficit are no longer imported.

D.

International trade is unrestricted and tariffs are not imposed.

Full Access
Question # 193

An internal auditor reviews a data population and calculates the mean, median, and range. What is the most likely purpose of performing this analytic technique?

A.

To inform the classification of the data population.

B.

To determine the completeness and accuracy of the data.

C.

To identify whether the population contains outliers.

D.

To determine whether duplicates in the data inflate the range.

Full Access
Question # 194

An organization ' s financial statements indicate a note that the financial statements have been prepared on the basis of the organization continuing operations for the foreseeable future. Which of the following accounting principles has been applied based on this note?

A.

Monetary unit assumption.

B.

Going concern assumption.

C.

Time period assumption.

D.

Economic entity assumption.

Full Access
Question # 195

Which stage in the industry life cycle is characterized by many different product variations?

A.

Introduction.

B.

Growth.

C.

Maturity.

D.

Decline.

Full Access
Question # 196

Which of the following engagement observations would provide the least motivation for management to amend or replace an existing cost accounting system?

A.

The distorted unit cost of a service is 50 percent lower than the true cost, while the true cost is 50 percent higher than the competition ' s cost.

B.

The organization is losing $1,000,000 annually because it incorrectly outsourced an operation based on information from its current system.

C.

The cost of rework, hidden by the current system, is 50 percent of the total cost of all services.

D.

Fifty percent of total organizational cost has been allocated on a volume basis.

Full Access
Question # 197

A large pharmaceutical company would most likely use which of the following to determine liquidity?

A.

Earnings per share.

B.

Asset turnover ratio.

C.

Net income.

D.

Current ratio.

Full Access
Question # 198

Which of the following is true regarding bonds?

A.

Bondholders do not have voting rights but obtain corporate control via interest pay-outs.

B.

Debenture bonds are rarely used by organizations with good credit ratings.

C.

Using bonds involves paying interest on a periodic basis and repaying the principal at the due date.

D.

Debenture bonds have specific assets pledged by the organization as collateral for the bonds.

Full Access
Question # 199

According to IIA guidance, which of the following links computers and enables them to -communicate with each other?

A.

Application program code

B.

Database system

C.

Operating system

D.

Networks

Full Access
Question # 200

An organization accomplishes its goal to obtain a 40 percent share of the domestic market, but is unable to get the desired return on investment and output per hour of labor. Based on this information, the organization is most likely focused on which of the following?

A.

Capital investment and not marketing.

B.

Marketing and not capital investment.

C.

Efficiency and not input economy.

D.

Effectiveness and not efficiency.

Full Access
Question # 201

Which of the following statements best describes the current state of data privacy regulation?

A.

Regulations related to privacy are evolving and complex, and the number of laws is increasing

B.

Most privacy laws are prescriptive and focused on organizations’ privacy rights

C.

The concept of data privacy is well established, privacy regulations are mature, and minimal regulatory changes are expected

D.

Because the concept of privacy is different around the world, data privacy is relatively unregulated

Full Access
Question # 202

In an analysis of alternative credit-management policies, which of the following components will cause the net present value of receivables on credit sales to increase, if everything else remains constant?

A.

A tougher collections policy that reduces the bad debt loss ratio.

B.

A higher cost per unit sold.

C.

A longer average collection period.

D.

An increase in the cost of capital.

Full Access
Question # 203

Which type of bond sells at a discount from face value, then increases in value annually until it reaches maturity and provides the owner with the total payoff?

A.

High-yield bonds

B.

Commodity-backed bonds

C.

Zero-coupon bonds

D.

Junk bonds

Full Access
Question # 204

With regard to disaster recovery planning, which of the following would most likely involve stakeholders from several departments?

A.

Determining the frequency with which backups will be performed.

B.

Prioritizing the order in which business systems would be restored.

C.

Assigning who in the IT department would be involved in the recovery procedures.

D.

Assessing the resources needed to meet the data recovery objectives.

Full Access
Question # 205

An investor has acquired an organization that has a dominant position in a mature. slew-growth Industry and consistently creates positive financial income.

Which of the following terms would the investor most likely label this investment in her portfolio?

A.

A star

B.

A cash cow

C.

A question mark

D.

A dog

Full Access
Question # 206

According to IIA guidance, which of the following would be the best first step to manage risk when a third party is overseeing the organization’s network and data?

A.

Creating a comprehensive reporting system for vendors to demonstrate their ongoing due diligence in network operations

B.

Drafting a strong contract that requires regular vendor control reports and a right-to-audit clause

C.

Applying administrative privileges to ensure right-to-access controls are appropriate

D.

Creating a standing cybersecurity committee to identify and manage risks related to data security

Full Access
Question # 207

Which of the following statements about slack time and milestones are true?

    Slack time represents the amount of time a task may be delayed without delaying the entire project.

    A milestone is a moment in time that marks the completion of the project ' s major deliverables.

    Slack time allows the project manager to move resources from one task to another to ensure that the project is finished on time.

    A milestone requires resource allocation and needs time to be completed.

A.

1 and 4 only

B.

2 and 3 only

C.

1, 2, and 3 only

D.

1, 2, 3, and 4

Full Access
Question # 208

Which of the following is a typical activity performed by the help desk?

A.

Monitoring the network

B.

Troubleshooting

C.

Backing up data

D.

Assigning authorizations to a user, a role, or profile

Full Access
Question # 209

During disaster recovery planning, the organization established a recovery point objective. Which of the following best describes this concept?

A.

The maximum tolerable downtime after the occurrence of an incident.

B.

The maximum tolerable data loss after the occurrence of an incident.

C.

The maximum tolerable risk related to the occurrence of an incident

D.

The minimum recovery resources needed after the occurrence of an incident

Full Access
Question # 210

Which of the following is an established systems development methodology?

A.

Waterfall.

B.

Projects in Controlled Environments (PRINCE2).

C.

Information Technology Infrastructure Library (ITIL).

D.

COBIT

Full Access
Question # 211

The chief audit executive (CAE) and management of the area under review disagree over managing a significant risk item. According to IIA guidance, which of the following actions should the CAE take first?

A.

Refer the matter to the board for resolution

B.

Consult the approved audit charter on supremacy of internal auditors’ decisions

C.

Record management’s and the internal auditor ' s positions in the audit report

D.

Discuss the issue in question further with senior management

Full Access
Question # 212

According to IIA guidance, which of the following statements is true regarding penetration testing?

A.

Testing should not be announced to anyone within the organization to solicit a real-life response.

B.

Testing should take place during heavy operational time periods to test system resilience.

C.

Testing should be wide in scope and primarily address detective management controls for identifying potential attacks.

D.

Testing should address the preventive controls and management ' s response.

Full Access
Question # 213

According to IIA guidance, which of the following statements is true regarding the chief audit executive ' s (CAE’s) responsibility for following up on management action plans?

A.

Follow-up activities must be performed on an ongoing basis, such as quarterly, rather than being scheduled as specific assignments in the internal audit plan

B.

The primary purpose of the CAE’s follow-up activities is to verify whether the audit issues raised in the audit report are valid

C.

The CAE may plan follow-up activities on a selective basis, depending on risk significance, to verify whether management action plans were completed

D.

Where management believes certain action plans are no longer necessary, the CAE must resolve the matter with the board and if the matter remains unresolved, communicate to senior management

Full Access
Question # 214

Which of the following is a key factor in the development of a production budget for a manufacturing organization?

A.

Direct materials units required.

B.

Estimated ending unit inventory.

C.

Projected sales revenue.

D.

Variable overhead costs.

Full Access
Question # 215

Which of the following data analytics techniques is used to identify patterns among groups of data elements?

A.

Stratification of numeric values.

B.

Joining different data sources.

C.

Duplicate testing.

D.

Classification.

Full Access
Question # 216

The internal audit function is instructed by the audit committee to assess and give an opinion annually on risk management process effectiveness. However, lacking in-house expertise, the chief audit executive (CAE) initially appoints an independent consultant to assist with this engagement. Which of the following approaches is the most appropriate?

A.

The engagement is wholly performed by the independent consultant and the CAE forms the opinion

B.

The independent consultant accomplishes the entire engagement and forms the opinion

C.

Internal auditors work with the independent consultant and the CAE forms the opinion

D.

Internal auditors carry out the entire engagement and the independent consultant forms the opinion

Full Access
Question # 217

Which of the following bring-your-own-device (BYOD) practices is likely to increase the risk of infringement on local regulations, such as copyright or privacy laws?

A.

Not installing anti-malware software.

B.

Updating operating software in a haphazard manner.

C.

Applying a weak password for access to a mobile device.

D.

Jailbreaking a locked smart device.

Full Access
Question # 218

Which of the following is not a barrier to effective communication?

A.

Filtering.

B.

Communication overload.

C.

Similar frames of reference.

D.

Lack of source credibility.

Full Access
Question # 219

Which of the following describes how human resources can best assist in recruitment efforts for the internal audit function?

A.

Prepare competency-based interview questions and interview potential candidates

B.

Leverage the organization ' s intranet and recruiting agencies to search for potential candidates

C.

Forward all applications to the chief audit executive for review

D.

Select the most qualified candidate for the vacant position

Full Access
Question # 220

Which of the following are the most appropriate measures for evaluating the change in an organization ' s liquidity position?

A.

Times interest earned, return on assets, and inventory turnover.

B.

Accounts receivable turnover, inventory turnover in days, and the current ratio.

C.

Accounts receivable turnover, return on assets, and the current ratio.

D.

Inventory turnover in days, the current ratio, and return on equity.

Full Access
Question # 221

Which of the following is the most appropriate way to record each partner’s initial investment in a partnership?

A.

At the value agreed upon by the partners

B.

At book value

C.

At fair value

D.

At the original cost

Full Access
Question # 222

Which of the following must be adjusted to index a progressive tax system to inflation?

A.

Tax deductions, exemptions, and tax filings.

B.

Tax deductions, exemptions, and tax brackets.

C.

Tax brackets, tax deductions, and tax payments.

D.

Tax brackets, exemptions, and nominal tax receipts.

Full Access
Question # 223

Which of the following database components stores metadata regarding the database’s own configuration, setup, and objects?

A.

Database table.

B.

Program files.

C.

Backup system.

D.

Data dictionary.

Full Access
Question # 224

Unsecured loans are loans:

A.

That do not have to be repaid for over one year.

B.

That appear to be too risky for most lenders to consider.

C.

Granted on the basis of a company ' s credit standing.

D.

Backed by mortgaged assets.

Full Access
Question # 225

An internal auditor considers the financial statement of an organization as part of a financial assurance engagement. The auditor expresses the organization ' s electricity and depreciation expenses as a percentage of revenue to be 10% and 7% respectively. Which of the following techniques was used by the internal auditor In this calculation?

A.

Horizontal analysis

B.

Vertical analysis

C.

Ratio analysis

D.

Trend analysis

Full Access
Question # 226

Which of the following steps should an internal auditor take during an audit of an organization ' s business continuity plans?

    Evaluate the business continuity plans for adequacy and currency.

    Prepare a business impact analysis regarding the loss of critical business.

    Identify key personnel who will be required to implement the plans.

    Identify and prioritize the resources required to support critical business processes.

A.

1 only

B.

2 and 4 only

C.

1, 3, and 4 only

D.

1, 2, 3, and 4

Full Access
Question # 227

Management has established a performance measurement focused on the accuracy of disbursements. The disbursement statistics, provided daily to ail accounts payable and audit staff, include details of payments stratified by amount and frequency. Which of the following is likely to be the greatest concern regarding this performance measurement?

A.

Articulation of the data

B.

Availability of the data.

C.

Measurability of the data

D.

Relevance of the data.

Full Access
Question # 228

Which of the following can be classified as debt investments?

A.

Investments in the capital stock of a corporation

B.

Acquisition of government bonds.

C.

Contents of an investment portfolio,

D.

Acquisition of common stock of a corporation

Full Access
Question # 229

According to UA guidance on IT, at which of the following stages of the project life cycle would the project manager most likely address the need to coordinate project resources?

A.

Initiation.

B.

Planning.

C.

Execution.

D.

Monitoring.

Full Access
Question # 230

Which of the following would be most effective in preventing phishing attacks from impacting business systems?

A.

Training users on security awareness.

B.

Monitoring the usage of IT systems.

C.

Using software to detect malware.

D.

Blocking access to a user ' s accounts.

Full Access
Question # 231

The audit committee has asked the internal audit activity to integrate data analytics into all work programs going forward. To accomplish this, which of the following describes the first step an audit team should take when planning for an audit?

A.

Ensure that there are sufficient audit resources or train personnel in data analytics.

B.

Obtain and assess as much data as possible for the audit.

C.

Identify the business question or need, data required, and expected results.

D.

Gain management ' s approval and willingness to accept audit findings based on data analytics.

Full Access
Question # 232

Which of the following is an example of an application control?

A.

Automated password change requirements.

B.

System data backup process.

C.

User testing of system changes.

D.

Formatted data fields.

Full Access
Question # 233

Which of the following is a security feature that Involves the use of hardware and software to filter or prevent specific Information from moving between the inside network and the outs de network?

A.

Authorization

B.

Architecture model

C.

Firewall

D.

Virtual private network

Full Access
Question # 234

Which of the following business practices promotes a culture of high performance?

A.

Reiterating the importance of compliance with established policies and procedures.

B.

Celebrating employees ' individual excellence.

C.

Periodically rotating operational managers.

D.

Avoiding status differences among employees.

Full Access
Question # 235

Which of the following statements is true regarding the use of public key encryption to secure data while it is being transmitted across a network?

A.

Both the key used to encrypt the data and the key used to decrypt the data are made public.

B.

The key used to encrypt the data is kept private but the key used to decrypt the data is made public.

C.

The key used to encrypt the data is made public but the key used to decrypt the data is kept private.

D.

Both the key used to encrypt the data and the key used to decrypt the data are made private.

Full Access
Question # 236

Which of the following IT layers would require the organization to maintain communication with a vendor in a tightly controlled and monitored manner?

A.

Applications

B.

Technical infrastructure.

C.

External connections.

D.

IT management

Full Access
Question # 237

Which of the following statements is true regarding a project life cycle?

A.

Risk and uncertainty increase over the life of the project.

B.

Costs and staffing levels are typically high as the project draws to a close.

C.

Costs related to making changes increase as the project approaches completion.

D.

The project life cycle corresponds with the life cycle of the product produced by or modified by the project.

Full Access