Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

IIA IIA-CIA-Part3 Internal Audit Function Exam Practice Test

Demo: 237 questions
Total 791 questions

Internal Audit Function Questions and Answers

Question 1

Which of the following statements is correct regarding risk analysis?

Options:

A.

The extent to which management judgments are required in an area could serve as a risk factor in assisting the auditor in making a comparative risk analysis.

B.

The highest risk assessment should always be assigned to the area with the largest potential loss.

C.

The highest risk assessment should always be assigned to the area with the highest probability of occurrence.

D.

Risk analysis must be reduced to quantitative terms in order to provide meaningful comparisons across an organization.

Question 2

Which observations should the chief audit executive include in the executive summary of the final engagement communication?

Options:

A.

All observations

B.

Only observations with an action plan

C.

Only significant observations

D.

Only observations agreed with management

Question 3

Which of the following best explains how selling and administrative expenses are recognized under both absorption and variables costing approaches?

Options:

A.

They are recognized as product costs under absorption costing, and period costs under variable costing.

B.

They are recognized as period costs under absorption costing, and product costs under variable costing.

C.

They are recognized as period costs under both approaches.

D.

They are recognized as product costs under both approaches.

Question 4

Which of the following statements. Is most accurate concerning the management and audit of a web server?

Options:

A.

The file transfer protocol (FTP) should always be enabled.

B.

The simple mail transfer protocol (SMTP) should be operating under the most privileged accounts.

C.

The number of ports and protocols allowed to access the web server should be maximized.

D.

Secure protocols for confidential pages should be used instead of dear-text protocols such as HTTP or FTP.

Question 5

The finance department of an organization recently undertook an asset verification exercise. The internal audit function scheduled a review of the IT department’s operations, which includes verifying the existence of computers distributed and their assignment. Can the internal audit function consider relying on the asset verification work performed by the finance department?

Options:

A.

Yes, in order to be efficient and make better use of internal audit resources

B.

No, as the finance department is an internal department of the organization

C.

Yes, but the finance manager would be responsible for supporting the conclusions of the work

D.

No, the internal audit function should do its own verification and should not rely on the work of finance

Question 6

In a final audit report, internal auditors drafted the following management action plan with a due date of the last day of the calendar year:

" Plan: A bank reconciliation template has been updated to address issues with formulas incorrectly calculating variances. "

Which critical element of the action plan is missing?

Options:

A.

The responsible personnel

B.

The status of the action plan

C.

A referral to the policy or procedure

D.

The level of risk

Question 7

Which would provide the board with the highest level of assurance regarding whether an internal audit function can achieve its objectives?

Options:

A.

Percentage of completed audit engagements

B.

Key stakeholder satisfaction surveys

C.

External quality assurance feedback

D.

Audit personnel commitment and turnover rates

Question 8

Data analysis indicates that a hospital pharmacy disbursed higher levels of controlled drugs than similar pharmacies in the area. The hospital ' s internal auditor discusses the risk with the head of the hospital pharmacy, who believes that the risk is appropriately mitigated by controls and feels comfortable with the number of prescriptions written.

What should the auditor do next?

Options:

A.

Document that the head of the pharmacy has accepted the risk and believes it is sufficiently mitigated, and conclude the risk assessment.

B.

Request that an independent third party re-perform the data analysis to verify the accuracy of the initial findings.

C.

Investigate the risk by requesting pharmacy policies, procedures, and detailed reports.

D.

Add an audit of the hospital pharmacy to the annual audit plan to fully investigate the risk later in the year.

Question 9

The internal audit function conducted an engagement on maintenance operations of a construction organization and identified several issues of medium importance. The head of maintenance proposed an improvement plan with deadlines and personnel responsible. The internal audit function issued the final report to senior management. Senior management was dissatisfied with the report as they believed that improvement plan deadlines should be considerably shorter. Which of the following should the internal audit function change in the reporting process?

Options:

A.

Discontinue discussing draft reports with responsible employees, as their input is needed during fieldwork only

B.

Involve senior management at the draft report stage and in the development of action plans

C.

Request senior management to issue a separate memo regarding their changes to deadlines

D.

Invite senior management to the board meeting regarding engagement results so that they can express their concerns

Question 10

What is the primary purpose of an integrity control?

Options:

A.

To ensure data processing is complete, accurate, and authorized

B.

To ensure data being processed remains consistent and intact

C.

To monitor the effectiveness of other controls

D.

To ensure the output aligns with the intended result

Question 11

Which of the following is likely to occur when an organization decides to adopt a decentralized organizational structure?

Options:

A.

A slower response to external change.

B.

Less controlled decision making.

C.

More burden on higher-level managers.

D.

Less use of employees ' true skills and abilities.

Question 12

Which of the following common quantitative techniques used in capital budgeting is best associated with the use of a table that describes the present value of an annuity?

Options:

A.

Cash payback technique.

B.

Discounted cash flow technique: net present value.

C.

Annual rate of return

D.

Discounted cash flow technique: internal rate of return.

Question 13

When applied to international economics, the theory of comparative advantage proposes that total worldwide output will be greatest when:

Options:

A.

Each nation ' s total imports approximately equal its total exports.

B.

Each good is produced by the nation that has the lowest opportunity cost for that good.

C.

Goods that contribute to a nation ' s balance-of-payments deficit are no longer imported.

D.

International trade is unrestricted and tariffs are not imposed.

Question 14

The activity that involves a trial run of a product in a typical segment of the market before proceeding to a national launch is referred to as:

Options:

A.

Test marketing

B.

Experimentation

C.

Segmentation

D.

Positioning

Question 15

Which approach should a chief audit executive take when preparing the internal audit plan?

Options:

A.

Organize the auditable units within the organization into an audit universe to facilitate risk assessment

B.

Select auditable units within the organization based on monetary values

C.

Evaluate auditable units based on senior management ' s information about risks

D.

Eliminate auditable units not mandated to be audited by laws and regulations applicable to the organization

Question 16

A new manager received computations of the internal rate of return regarding his project proposal. What should the manager compare the computation results to in order to determine whether the project is potentially acceptable?

Options:

A.

Compare to the annual cost of capital.

B.

Compare to the annual interest rate.

C.

Compare to the required rate of return.

D.

Compare to the net present value.

Question 17

An organization accomplishes its goal to obtain a 40 percent share of the domestic market, but is unable to get the desired return on investment and output per hour of labor. Based on this information, the organization is most likely focused on which of the following?

Options:

A.

Capital investment and not marketing.

B.

Marketing and not capital investment.

C.

Efficiency and not input economy.

D.

Effectiveness and not efficiency.

Question 18

An organization uses the management-by-objectives method, whereby employee performance is based on defined goals. Which of the following statements is true regarding this approach?

Options:

A.

It is particularly helpful to management when the organization is facing rapid change

B.

It is a more successful approach when adopted by mechanistic organizations

C.

It is more successful when goal-setting is performed not only by management, but by all team members, including lower-level staff

D.

It is particularly successful in environments that are prone to having poor employer-employee relations

Question 19

Which of the following is an element of effective negotiating?

Options:

A.

Ensuring that the other party has a personal stake in the agreement.

B.

Focusing on interests rather than on obtaining a winning position.

C.

Considering a few select choices during the settlement phase.

D.

Basing the agreement on negotiating power and positioning leverage.

Question 20

According to IIA guidance, which of the following would be the best first step to manage risk when a third party is overseeing the organization’s network and data?

Options:

A.

Creating a comprehensive reporting system for vendors to demonstrate their ongoing due diligence in network operations

B.

Drafting a strong contract that requires regular vendor control reports and a right-to-audit clause

C.

Applying administrative privileges to ensure right-to-access controls are appropriate

D.

Creating a standing cybersecurity committee to identify and manage risks related to data security

Question 21

An organization wants to offer a standard product across all markets but also wants to differentiate the product to fit local demands in different geographic markets and to meet government regulations.

Which of the following strategies may help the organization achieve its goal?

Options:

A.

Globalization strategy.

B.

Transnational strategy.

C.

Multidomestic strategy.

D.

Export strategy.

Question 22

If a bank ' s activities are categorized under such departments as community banking, institutional banking, and agricultural banking, what kind of departmentalization is being utilized?

Options:

A.

Product departmentalization.

B.

Process departmentalization.

C.

Functional departmentalization.

D.

Customer departmentalization.

Question 23

An organization decided to install a motion detection system in its warehouse to protect against after-hours theft. According to the COSO enterprise risk management framework, which of the following best describes this risk management strategy?

Options:

A.

Avoidance.

B.

Reduction.

C.

Elimination.

D.

Sharing.

Question 24

The decision to implement enhanced failure detection and backup systems to improve data integrity is an example of which risk response?

Options:

A.

Risk acceptance.

B.

Risk sharing.

C.

Risk avoidance.

D.

Risk reduction.

Question 25

Which of the following is a necessary action for an internal audit function if senior management chooses not to take action to remediate the finding and accepts the risk?

Options:

A.

The chief audit executive (CAE) must discuss this disagreement with senior management and communicate this information to external stakeholders

B.

The CAE must include this disagreement in the final audit report and conclude the engagement

C.

The CAE must make a judgment regarding the prudence of that decision and report to the board if needed

D.

The CAE must establish a follow-up process to monitor the acceptable risk level as part of the engagement

Question 26

Which of the following functions of a quality assurance and improvement program (QAIP) must be performed by personnel independent of the internal audit function?

Options:

A.

External assessments

B.

Communication of QAIP results to the board

C.

Disclosure of nonconformance

D.

Internal assessments

Question 27

An organization ' s internal audit activity is performing an audit of human resources. As part of the audit a survey of employees was conducted. The survey indicated that employees were concerned about IT security when working outside of the office. The IT department suggested implementing a network that allows employees to send and receive data as if they were connected to a private network.

Which of the following networks is IT recommending?

Options:

A.

Global area network (GAN).

B.

Wide area network (WAN).

C.

Virtual private network (VPN).

D.

Local area network (LAN).

Question 28

According to IIA guidance on IT, which of the following would be considered a primary control for a spreadsheet to help ensure accurate financial reporting?

Options:

A.

Formulas and static data are locked or protected.

B.

The spreadsheet is stored on a network server that is backed up daily.

C.

The purpose and use of the spreadsheet are documented.

D.

Check-in and check-out software is used to control versions.

Question 29

Organizational activities that complement each other and create a competitive advantage are called a:

Options:

A.

Merger.

B.

Strategic fit.

C.

Joint venture.

D.

Strategic goal.

Question 30

Which of the following practices impacts copyright issues related to the manufacturer of a smart device?

Options:

A.

Session hijacking.

B.

Jailbreaking

C.

Eavesdropping,

D.

Authentication.

Question 31

Which of the following statements regarding organizational structures is true?

Options:

A.

Decentralized organizations tend to have written rules, established procedures, and a high level of uniformity.

B.

Centralized organizations tend to be more efficient and make faster decisions.

C.

Centralized organizations tend to have less control at the top management level.

D.

Decentralized organizations’ power is more dispersed and is based on the regional managers’ knowledge.

Question 32

Which of the following assessments will assist in evaluating whether the internal audit function is consistently delivering quality engagements?

Options:

A.

Periodic assessments

B.

Ongoing monitoring

C.

Full external assessments

D.

Self-Assessment with Independent Validation (SAIV)

Question 33

When auditing the account receivables for the first time, an internal auditor noted that the finance team had not—over many accounting periods—reviewed the accounts receivables for debts that could no longer be collected. How should the auditor proceed?

Options:

A.

Escalate the finding to the board, due to the significance of the risk

B.

Recommend that management review the receivables for debts that can no longer be collected and remove them from the cash flow statement

C.

Recommend that management review the receivables for debts that can no longer be collected and write them off

D.

Document the finding and conclude that no immediate action is warranted, as bad debt allowances are merely estimates

Question 34

Which of the following lists is comprised of computer hardware only?

Options:

A.

A central processing unit, a scanner, and a value-added network

B.

A computer chip, a data warehouse, and a router

C.

A server, a firewall, and a smartphone

D.

A workstation, a modem, and a disk drive

Question 35

Which of the following is an example of a contingent liability that a company should record?

Options:

A.

A potential assessment of additional income tax.

B.

Possible product warranty costs.

C.

The threat of a lawsuit by a competitor.

D.

The remote possibility of a contract breach.

Question 36

Which of the following best describes the concept of relevant cost?

Options:

A.

A future cost that is the same among alternatives.

B.

A future cost that differs among alternatives.

C.

A past cost that is the same among alternatives.

D.

A past cost that differs among alternatives.

Question 37

Which of the following statements best describes the current state of data privacy regulation?

Options:

A.

Regulations related to privacy are evolving and complex, and the number of laws is increasing

B.

Most privacy laws are prescriptive and focused on organizations’ privacy rights

C.

The concept of data privacy is well established, privacy regulations are mature, and minimal regulatory changes are expected

D.

Because the concept of privacy is different around the world, data privacy is relatively unregulated

Question 38

Which of the following statements is true regarding cost-volume-profit analysis?

Options:

A.

Contribution margin is the amount remaining from sales revenue after fixed expenses have been deducted.

B.

Breakeven point is the amount of units sold to cover variable costs.

C.

Breakeven occurs when the contribution margin covers fixed costs.

D.

Following breakover1, he operating income will increase by the excess of fixed costs less the variable costs per units sold.

Question 39

According to IIA guidance, which of the following statements is true with regard to workstation computers that access company information stored on the network?

Options:

A.

Individual workstation computer controls are not as important as companywide server controls

B.

Particular attention should be paid to housing workstations away from environmental hazards

C.

Cybersecurity issues can be controlled at an enterprise level, making workstation-level controls redundant

D.

With security risks near an all-time high, workstations should not be connected to the company network

Question 40

An internal audit function has commenced its annual follow-up activity. An internal auditor has been assigned to verify whether the recommendations from an audit engagement completed three months ago were implemented by the business unit. The auditor had not participated in that audit engagement. What should the auditor do first?

Options:

A.

Conduct interviews with senior management of the business unit

B.

Request information from the business unit regarding the corrective actions taken

C.

Review the previous audit findings and management ' s response

D.

Conduct a walkthrough of the business unit

Question 41

Which of the following statements is true regarding a bring-your-own-device (BYOD) environment?

Options:

A.

There is a greater need for organizations to rely on users to comply with policies and procedures.

B.

With fewer devices owned by the organization, there is reduced need to maintain documented policies and procedures.

C.

Incident response times are less critical in the BYOD environment compared to a traditional environment.

D.

There is greater sharing of operational risk in a BYOD environment.

Question 42

What kind of strategy would be most effective for an organization to adopt in order to Implement a unique advertising campaign for selling identical product lines across all of its markets?

Options:

A.

Export strategy.

B.

Transnational strategy

C.

Multi-domestic strategy

D.

Globalization strategy

Question 43

Which of the following best describes a competitive strategy in which the organization focuses on attempts to be more efficient than competitors?

Options:

A.

Differentiation strategy.

B.

Cost leadership strategy.

C.

Focus strategy.

D.

Portfolio strategy.

Question 44

According to IIA guidance, which of the following is a typical risk associated with the tender process and contracting stage of an organization ' s IT outsourcing life cycle?

Options:

A.

The process is not sustained and is not optimized as planned.

B.

There is a lack of alignment to organizational strategies.

C.

The operational quality is less than projected.

D.

There is increased potential for loss of assets.

Question 45

Which of the following controls is the most effective for ensuring confidentially of transmitted information?

Options:

A.

Firewall.

B.

Antivirus software.

C.

Passwords.

D.

Encryption.

Question 46

Which of the following practices circumvents administrative restrictions on smart devices, thereby increasing data security risks?

Options:

A.

Rooting.

B.

Eavesdropping.

C.

Man in the middle.

D.

Session hijacking.

Question 47

Which of the following techniques would best detect on inventory fraud scheme?

Options:

A.

Analyze invoice payments just under individual authorization limits.

B.

Analyze stratification of inventory adjustments by warehouse location.

C.

Analyze Inventory Invoice amounts and compare with approved contract amounts.

D.

Analyze differences discovered curing duplicate payment testing.

Question 48

Which of the following situations best applies to an organization that uses a project, rather than a process, to accomplish its business activities?

Options:

A.

A clothing company designs, makes, and sells a new item

B.

A commercial construction company is hired to build a warehouse

C.

A city department sets up a new firefighter training program

D.

A manufacturing organization acquires component parts from a contracted vendor

Question 49

Which of the following backup methodologies would be most efficient in backing up a database in the production environment?

Options:

A.

Disk mirroring of the data being stored on the database.

B.

A differential backup that is performed on a weekly basis.

C.

An array of independent disks used to back up the database.

D.

An incremental backup of the database on a daily basis.

Question 50

Senior management has decided to implement the Three Lines of Defense model for risk management. Which of the following best describes senior management ' s duties with regard to this model?

Options:

A.

Ensure compliance with the model.

B.

Identify management functions.

C.

Identify emerging issues.

D.

Set goals for implementation.

Question 51

Which of the following is a primary driver behind the creation and prloritteation of new strategic Initiatives established by an organization?

Options:

A.

Risk tolerance

B.

Performance

C.

Threats and opportunities

D.

Governance

Question 52

During the last year, an organization had an opening inventory of $300,000, purchases of $980,000, sales of $1,850,000, and a gross margin of 40 percent. What is the closing inventory if the periodic inventory system is used?

Options:

A.

$170,000

B.

$280,000

C.

$300,000

D.

$540,000

Question 53

Which of the following statements is accurate regarding the use of Secure Sockets Layer (SSL) as a control?

Options:

A.

It supports the authentication of information sent to a server.

B.

It prevents phishing attacks that redirect users to malicious sites.

C.

It prevents malware infections.

D.

It identifies each client-server session using temporary tokens.

Question 54

Which of the following statements is true regarding IT controls within an organization?

Options:

A.

IT risks and controls should be assessed at least once every five years.

B.

Responsibility for effective IT controls rests exclusively with management.

C.

An effective IT control environment should consist of all possible general IT and application controls.

D.

Regardless of how well an IT control is designed it may be subject to error and management override.

Question 55

Which of the following describes a third-party network that connects an organization specifically with its trading partners?

Options:

A.

Value-added network (VAN).

B.

Local area network (LAN).

C.

Metropolitan area network (MAN).

D.

Wide area network (WAN).

Question 56

According to IIA guidance, a business impact analysis would include which of the following steps?

Options:

A.

Defining staffing alternatives needed for recovery.

B.

Selecting recovery solutions and recovery sites.

C.

Identifying the business processes.

D.

Defining alternative sourcing of critical functions.

Question 57

Which of the following descriptions of the internal control system are indicators that risks are managed effectively?

    Existing controls promote compliance with applicable laws and regulations.

    The control environment is designed to address all identified risks to the organization.

    Key controls for significant risks to the organization remain consistent over time.

    Monitoring systems are in place to alert management to unexpected events.

Options:

A.

1 and 3.

B.

1 and 4.

C.

2 and 3.

D.

2 and 4.

Question 58

When reviewing application controls using the four-level model, which of the following processes are associated with level 4 of the business process method?

Options:

A.

Activity

B.

Subprocess

C.

Major process

D.

Mega process

Question 59

Which of the following is true of bond financing, compared to common stock, when alJ other variables are equal?

Options:

A.

Lower shareholder control

B.

lower indebtedness

C.

Higher company earnings per share.

D.

Higher overall company earnings

Question 60

During which phase of the contracting process are contracts drafted for a proposed business activity?

Options:

A.

Initiation phase.

B.

Bidding phase.

C.

Development phase.

D.

Management phase.

Question 61

Which of the following principles s shared by both hierarchies and open organizational structures?

1. A superior can delegate the authority to make decisions but cannot delegate the ultimate responsibility for the results of those decisions.

2. A supervisor ' s span of control should not exceed seven subordinates.

3. Responsibility should be accompanied by adequate authority.

4. Employees at all levels should be empowered to make decisions.

Options:

A.

1 and 3 only

B.

1 and 4 only

C.

2 and 3 only

D.

3 and 4 only

Question 62

Which of the following best describes the use of predictive analytics?

Options:

A.

A supplier of electrical parts analyzed an instances where different types of spare parts were out of stock prior to scheduled deliveries of those parts.

B.

A supplier of electrical parts analyzed sales, applied assumptions related to weather conditions, and identified locations where stock levels would decrease more quickly.

C.

A supplier of electrical parts analyzed all instances of a part being, out of stock poor to its scheduled delivery date and discovered that increases in sales of that part consistently correlated with stormy weather.

D.

A supplier of electrical parts analyzed sales and stock information and modelled different scenarios for making decisions on stock reordering and delivery

Question 63

During a review of payments to supplier invoices, the internal auditor identified that the IT process allows invoice processing staff to ignore the auto-generated alert triggered when the invoice amount is different from the purchase order value. The manager explained that staff must be able to bypass the alert because of small differences in transport charges. Which of the following would be the most appropriate internal audit recommendation?

Options:

A.

The alert is a control that should never be ignored, and suppliers should be advised that invoices will not be paid unless the invoice is equal to or less than purchase order value

B.

The manager should raise a purchase order amendment each time the amounts differ, and the supplier should be asked to quote the amended order number in the invoice

C.

The manager should establish a monetary limit on the amount of difference that will be tolerated, where the IT process will allow the staff to ignore the alert

D.

No additional controls are needed, as it is appropriate for a process to allow staff to exercise discretion when processing invoices

Question 64

For which of the following scenarios would the most recent backup of the human resources database be the best source of information to use?

Options:

A.

An incorrect program fix was implemented just prior to the database backup.

B.

The organization is preparing to train all employees on the new self-service benefits system.

C.

There was a data center failure that requires restoring the system at the backup site.

D.

There is a need to access prior year-end training reports for all employees in the human resources database

Question 65

According to Maslow ' s hierarchy of needs theory, which of the following would likely have the most impact on retaining staff, if their lower-level needs are already met?

Options:

A.

Social benefits.

B.

Compensation.

C.

Job safety.

D.

Recognition

Question 66

A large retail customer made an offer to buy 10,000 units at a special price of $7 per unit. The manufacturer usually sells each unit for $10. Variable manufacturing costs are $5 per unit and fixed manufacturing costs are $3 per unit. For the manufacturer to accept the offer, which of the following assumptions needs to be true?

Options:

A.

Fixed and variable manufacturing costs are less than the special offer selling price

B.

The manufacturer can fulfill the order without expanding the capacities of the production facilities

C.

Costs related to accepting this offer can be absorbed through the sale of other products

D.

The manufacturer’s production facilities are currently operating at full capacity

Question 67

What is the primary purpose of data and systems backup?

Options:

A.

To restore all data and systems immediately after the occurrence of an incident.

B.

To set the maximum allowable downtime to restore systems and data after the occurrence of an incident.

C.

To set the point in time to which systems and data must be recovered after the occurrence of an incident.

D.

To restore data and systems to a previous point in time after the occurrence of an incident

Question 68

Which of the following management approaches may help eliminate employee dissatisfaction, but would not necessarily motivate workers to high achievement levels?

Options:

A.

Providing growth opportunities for employees.

B.

Offering employee recognition incentives in the organization.

C.

Offering competitive employee compensation packages.

D.

Assigning more responsibility to successful employees.

Question 69

Which of the following best describes a cyberattacK in which an organization faces a denial-of-service threat created through malicious data encryption?

Options:

A.

Phishing.

B.

Ransomware.

C.

Hacking.

D.

Makvare

Question 70

Which of the following scenarios indicates an effective use of financial leverage?

Options:

A.

An organisation has a rate of return on equity of 20% and a rate of return on assets of 15%.

B.

An organization has a current ratio of 2 and an inventory turnover of 12.

C.

An organization has a debt to total assets ratio of 0.2 and an interest coverage ratio of 10.

D.

An organization has a profit margin of 30% and an assets turnover of 7%.

Question 71

Which of the following types of accounts must be closed at the end of the period?

Options:

A.

Income statement accounts.

B.

Balance sheet accounts.

C.

Permanent accounts.

D.

Real accounts.

Question 72

Which audit approach should be employed to test the accuracy of information housed in a database on an un-networked computer?

Options:

A.

Submit batches of test transactions through the current system and verify with expected results.

B.

Use a test program to simulate the normal data entering process.

C.

Select a sample of records from the database and ensure it matches supporting documentation.

D.

Evaluate compliance with the organization ' s change management process.

Question 73

Which of the following security controls would be me most effective in preventing security breaches?

Options:

A.

Approval of identity request

B.

Access logging.

C.

Monitoring privileged accounts

D.

Audit of access rights

Question 74

An internal audit function did not conform with the Global Internal Audit Standards in only one of many engagements, as the engagement was performed with a lack of adequate knowledge of the subject matter. Which of the following is appropriate in relation to declaring conformance with the Standards?

Options:

A.

The internal audit function can still declare conformance with the Standards for all engagements

B.

The internal audit function can still declare conformance with the Standards for all other engagements that satisfy the requirements

C.

The internal audit function can declare partial conformance with the Standards for all engagements

D.

The internal audit function needs to evaluate the impact of the nonconformance before it can declare nonconformance with the Standards

Question 75

A organization finalized a contract in which a vendor is expected to design, procure, and construct a power substation for $3,000,000. In this scenario, the organization agreed to which of the following types of contracts?

Options:

A.

A cost-reimbursable contract.

B.

A lump-sum contract.

C.

A time and material contract.

D.

A bilateral contract.

Question 76

Which of the following is an example of a physical control?

Options:

A.

Providing fire detection and suppression equipment

B.

Establishing a physical security policy and promoting it throughout the organization

C.

Performing business continuity and disaster recovery planning

D.

Keeping an offsite backup of the organization’s critical data

Question 77

Which of the following would be most likely found in an internal audit procedures manual?

Options:

A.

A summary of the strategic plan of the area under review

B.

Appropriate response options for when findings are disputed by management

C.

An explanation of the resources needed for each engagement

D.

The extent of the auditor ' s authority to collect data from management

Question 78

According to IIA guidance, which of the following is an IT project success factor?

Options:

A.

Streamlined decision-making, rather than building consensus among users.

B.

Consideration of the facts, rather than consideration of the emotions displayed by project stakeholders.

C.

Focus on flexibility and adaptability, rather than use of a formal methodology.

D.

Inclusion of critical features, rather than inclusion of an array of supplementary features.

Question 79

The process of scenario planning begins with which of the following steps?

Options:

A.

Determining the trends that will influence key factors in the organization ' s environment.

B.

Selecting the issue or decision that will impact how the organization conducts future business.

C.

Selecting leading indicators to alert the organization of future developments.

D.

Identifying how customers, suppliers, competitors, employees, and other stakeholders will react.

Question 80

Which of the following financial statements provides the best disclosure of how a company ' s money was used during a particular period?

Options:

A.

Income statement.

B.

Owner ' s equity statement.

C.

Balance sheet.

D.

Statement of cash flows.

Question 81

Which of the following capital budgeting techniques considers the tune value of money?

Options:

A.

Annual rate of return.

B.

Incremental analysis.

C.

Discounted cash flow.

D.

Cash payback

Question 82

Which of the following is true regarding an organization ' s relationship with external stakeholders?

Options:

A.

Specific guidance must be followed when interacting with nongovernmental organizations.

B.

Disclosure laws tend to be consistent from one jurisdiction to another.

C.

There are several internationally recognized standards for dealing with financial donors.

D.

Legal representation should be consulted before releasing internal audit information to other assurance providers.

Question 83

Which of the following key performance indicators would serve as the best measurement of internal audit innovation?

Options:

A.

The number of scheduled and completed audits and percentage of substantial recommendations

B.

The board’s satisfaction index and internal audit staff commitment ratings

C.

Internal audit staff’s application of technology in audit fieldwork and participation in professional organizations and publications

D.

Internal audit staff’s compliance with the audit manual and technical knowledge in auditing, information security, and cloud computing issues

Question 84

As an organization introduces new technologies, what is internal audit ' s primary consideration for evaluating the organization ' s change management system?

Options:

A.

How the organization handles emergency change requests.

B.

Whether a change management system exists and can meet the organization ' s objectives.

C.

How the organization adjusts as business risks change.

D.

Whether the organization considers changes in capacity requirements.

Question 85

Which of the following capital budgeting techniques considers the expected total net cash flows from investment?

Options:

A.

Cash payback

B.

Annual rate of return

C.

Incremental analysis

D.

Net present value

Question 86

An IT auditor is evaluating IT controls of a newly purchased information system. The auditor discovers that logging is not configured al database and application levels. Operational management explains that they do not have enough personnel to manage the logs and they see no benefit in keeping logs. Which of the fallowing responses best explains risks associated with insufficient or absent logging practices?

Options:

A.

The organization will be unable to develop preventative actions based on analytics.

B.

The organization will not be able to trace and monitor the activities of database administers.

C.

The organization will be unable to determine why intrusions and cyber incidents took place.

D.

The organization will be unable to upgrade the system to newer versions.

Question 87

Which of the following types of date analytics would be used by a hospital to determine which patients are likely to require remittance for additional treatment?

Options:

A.

Predictive analytics.

B.

Prescriptive analytics.

C.

Descriptive analytics.

D.

Diagnostic analytics.

Question 88

Which of the following can be classified as debt investments?

Options:

A.

Investments in the capital stock of a corporation

B.

Acquisition of government bonds.

C.

Contents of an investment portfolio,

D.

Acquisition of common stock of a corporation

Question 89

Which of the following statements is true regarding the management-by-objectives method?

Options:

A.

Management by objectives is most helpful in organizations that have rapid changes.

B.

Management by objectives is most helpful in mechanistic organizations with rigidly defined tasks.

C.

Management by objectives helps organizations to keep employees motivated.

D.

Management by objectives helps organizations to distinguish clearly strategic goals from operational goals.

Question 90

An organization suffered significant damage to its local: file and application servers as a result of a hurricane. Fortunately, the organization was able to recover all information backed up by its overseas third-party contractor. Which of the following approaches has been used by the organization?

Options:

A.

Application management

B.

Data center management

C.

Managed security services

D.

Systems integration

Question 91

According to Maslow ' s hierarchy of needs theory, which of the following best describes a strategy where a manager offers an assignment to a subordinate specifically to support his professional growth and future advancement?

Options:

A.

Esteem by colleagues.

B.

Self-fulfillment

C.

Series of belonging in the organization

D.

Job security

Question 92

The IT department maintains logs of user identification and authentication for all requests for access to the network. What is the primary purpose of these logs?

Options:

A.

To ensure proper segregation of duties

B.

To create a master repository of user passwords

C.

To enable monitoring for systems efficiencies

D.

To enable tracking of privileges granted to users over time

Question 93

An organization with global headquarters in the United States has subsidiaries in eight other nations. If the organization operates with an ethnocentric attitude, which of the following statements is true?

Options:

A.

Standards used for evaluation and control are determined at local subsidiaries, not set by headquarters.

B.

Orders, commands, and advice are sent to the subsidiaries from headquarters.

C.

Poop o of local nationality are developed for the best positions within their own country.

D.

There is a significant amount of collaboration between headquarters and subs diaries.

Question 94

The profile of an internal auditor ' s personality traits reveals that the auditor is most motivated by self-actualization needs.

Given this, which of the following is likely to serve as the best motivator for this auditor?

Options:

A.

Rotate the auditor to work within a multi-disciplinary audit team.

B.

Assign the auditor to work on complex and challenging audits.

C.

Reassure the auditor that the internal audit budget is stable and the auditor ' s job is secure.

D.

Offer increased benefits in the auditor ' s compensation package.

Question 95

An organization allows employees to use their personal mobile devices to access its database. Which of the following best maintains the confidentiality of different records within the database?

Options:

A.

Regular remote wiping of the mobile devices accessing the database.

B.

Encrypted data transmissions between mobile devices and the database.

C.

Restrictions on the access permissions when mobile devices are used.

D.

The use of two-factor authentication algorithms for those who use remote access.

Question 96

Listening effectiveness is best increased by:

Options:

A.

Resisting both internal and external distractions.

B.

Waiting to review key concepts until the speaker has finished talking.

C.

Tuning out messages that do not seem to fit the meeting purpose.

D.

Factoring in biases in order to evaluate the information being given.

Question 97

A small chain of grocery stores made a reporting error and understated its ending inventory. What effect would this have on the income statement for the following year?

Options:

A.

Net income would be understated.

B.

Net income would not be affected.

C.

Net income would be overstated.

D.

Net income would be negative.

Question 98

Which of the following would an organization execute to effectively mitigate and manage risks created by a crisis or event?

Options:

A.

Only preventive measures.

B.

Alternative and reactive measures.

C.

Preventive and alternative measures.

D.

Preventive and reactive measures.

Question 99

An analytical model determined that on Friday and Saturday nights the luxury brands stores should be open for extended hours and with a doubled number of employees

present; while on Mondays and Tuesdays costs can be minimized by reducing the number of employees to a minimum and opening only for evening hours Which of the

following best categorizes the analytical model applied?

Options:

A.

Descriptive.

B.

Diagnostic.

C.

Prescriptive.

D.

Prolific.

Question 100

Which of the following is useful for forecasting the required level of inventory?

    Statistical modeling.

    Information about seasonal variations in demand.

    Knowledge of the behavior of different business cycles.

    Pricing models linked to seasonal demand.

Options:

A.

1 and 2 only

B.

2 and 3 only

C.

1, 2, and 3 only

D.

1, 2, 3, and 4

Question 101

An internal auditor conducts a preliminary privacy and data protection risk assessment. Which of the following is the most essential question to start the assessment?

Options:

A.

How does the cybersecurity unit investigate instances of data leakage or allegations?

B.

What are potential fines applicable to the organization for data protection breaches?

C.

What type of private data is collected and maintained by the organization?

D.

In what instances is data pseudonymization is applied in the organization?

Question 102

When assessing the adequacy of a risk mitigation strategy, an internal auditor should consider which of the following?

    Management’s tolerance for specific risks.

    The cost versus benefit of implementing a control.

    Whether a control can mitigate multiple risks.

    The ability to test the effectiveness of the control.

Options:

A.

1, 2, and 3

B.

1, 2, and 4

C.

1, 3, and 4

D.

2, 3, and 4

Question 103

An internal auditor identified a database administrator with an incompatible dual role. Which of the following duties should not be performed by the identified administrator?

Options:

A.

Designing and maintaining the database.

B.

Preparing input data and maintaining the database.

C.

Maintaining the database and providing its security,

D.

Designing the database and providing its security

Question 104

Which of the following statements is true regarding the data dictionary?

Options:

A.

The data dictionary includes system tables and program files of a database.

B.

The data dictionary describes the content of information stored in the database.

C.

The data dictionary specifies objects such as users, permissions, and groups.

D.

The data dictionary includes system backup and encryption keys.

Question 105

The board and senior management agree to outsource the internal audit function. Which of the following is true regarding the company’s quality assurance and improvement program (QAIP)?

Options:

A.

The organization is responsible for maintaining an effective QAIP

B.

The organization is responsible for the internal assessment of the QAIP

C.

The service provider is responsible for the external assessment of the QAIP every three years

D.

The QAIP should be postponed until the organization insources or cosources the internal audit function

Question 106

Which of the following would be the best indicator that the organization is saving money?

Options:

A.

No duplicate payments occurred during the past quarter.

B.

During the past quarter, 95% of invoices were paid by the due date.

C.

During the past quarter, 85% of invoices eligible for early-pay discounts were paid in time to obtain the discount.

D.

During the past quarter, 100% of payments made matched the invoiced amounts.

Question 107

Which of the following actions should an internal auditor take to clean the data obtained for analytics purposes?

Options:

A.

Deploys data visualization tool.

B.

Adopt standardized data analysis software.

C.

Define analytics objectives and establish outcomes.

D.

Eliminate duplicate records.

Question 108

While conducting ' audit procedures at the organization ' s data center an internal auditor noticed the following:

- Backup media was located on data center shelves.

- Backup media was organized by date.

- Backup schedule was one week in duration.

The system administrator was able to present restore logs.

Which of the following is reasonable for the internal auditor to conclude?

Options:

A.

Backup media is not properly stored, as the storage facility should be off-site.

B.

Backup procedures are adequate and appropriate according to best practices.

C.

Backup media is not properly indexed, as backup media should be indexed by system, not date.

D.

Backup schedule is not sufficient, as full backup should be conducted daily.

Question 109

Which of the following is a key factor in the development of a production budget for a manufacturing organization?

Options:

A.

Direct materials units required.

B.

Estimated ending unit inventory.

C.

Projected sales revenue.

D.

Variable overhead costs.

Question 110

Which of the following purchasing scenarios would gain the greatest benefit from implementing electronic data interchange (EDI)?

Options:

A.

A just-in-time purchasing environment

B.

A large volume of custom purchases

C.

A variable volume sensitive to material cost

D.

A currently inefficient purchasing process

Question 111

According to IIA guidance on IT, which of the following best describes a situation where data backup plans exist to ensure that critical data can be restored at some point in the future, but recovery and restore processes have not been defined?

Options:

A.

Hot recovery plan

B.

Warm recovery plan

C.

Cold plan

D.

Absence of recovery plan

Question 112

An organization filters data packets from public networks to send to an internal private network.

Which of the following devices would accomplish this?

Options:

A.

A router.

B.

A switch.

C.

A hub.

D.

A proxy gateway.

Question 113

During an audit of the payroll system, the internal auditor identifies and documents the following condition:

" Once a user is logged into the system, the user has access to all functionality within the system. "

What is the most likely root cause for tins issue?

Options:

A.

The authentication process relies on a simple password only, which is a weak method of authorization.

B.

The system authorization of the user does not correctly reflect the access rights intended.

C.

There was no periodic review to validate access rights.

D.

The application owner apparently did not approve the access request during the provisioning process.

Question 114

Which of the following IT-related activities is most commonly performed by the second line of defense?

Options:

A.

Block unauthorized traffic.

B.

Encrypt data.

C.

Review disaster recovery test results.

D.

Provide independent assessment of IT security.

Question 115

A company that supplies medications to large hospitals relies heavily on subcontractors to replenish any shortages within 24 hours. Where should internal auditors look for evidence that subcontractors are held responsible for this obligation?

Options:

A.

The company ' s code of ethics.

B.

The third-party management risk register.

C.

The signed service-level agreement.

D.

The subcontractors ' annual satisfaction survey.

Question 116

Which of the following describes a benefit of using data analytics during an audit engagement?

Options:

A.

An increased number of data extracts obtained from IT personnel.

B.

A reduced audit risk by focusing risk assessment and stratifying the population.

C.

A broadened scope of assurance services through the increase of audit staff.

D.

An increased performance level of data analysis that enables reduced time for audit planning.

Question 117

Which of the following physical access controls is most likely to be based on the " something you have " concept?

Options:

A.

A retina characteristics reader.

B.

A PIN code reader.

C.

A card-key scanner.

D.

A fingerprint scanner.

Question 118

Which of the following are likely indicators of ineffective change management?

    IT management is unable to predict how a change will impact interdependent systems or business processes.

    There have been significant increases in trouble calls or in support hours logged by programmers.

    There is a lack of turnover in the systems support and business analyst development groups.

    Emergency changes that bypass the normal control process frequently are deemed necessary.

Options:

A.

1 and 3 only

B.

2 and 4 only

C.

1, 2, and 4 only

D.

1, 2, 3, and 4

Question 119

Which of the following is most appropriate for the chief audit executive to keep in mind when establishing policies and procedures to guide the internal audit function?

Options:

A.

The nature of the internal audit function

B.

The size of the organization

C.

The size and maturity of the internal audit function

D.

The structure of the organization

Question 120

Which type of bond sells at a discount from face value, then increases in value annually until it reaches maturity and provides the owner with the total payoff?

Options:

A.

High-yield bonds

B.

Commodity-backed bonds

C.

Zero-coupon bonds

D.

Junk bonds

Question 121

Through meetings with management, an organization ' s chief audit executive (CAE) learns of a risk that exceeds the established risk tolerance. What would be an appropriate next action for the CAE to take?

Options:

A.

Design and recommend an appropriate response to the risk

B.

Discuss the risk and the implications of the risk with management responsible for the risk area

C.

Schedule an audit of the risk area to assess the risk likelihood and impact

D.

Prepare a memo to report the risk to the board

Question 122

An organization requires an average of 58 days to convert raw materials into finished products to sell. An additional 42 days is required to collect receivables. If the organization takes an average of 10 days to pay for raw materials, how long is its total cash conversion cycle?

Options:

A.

26 days.

B.

90 days.

C.

100 days.

D.

110 days.

Question 123

The chief audit executive (CAE) and management of the area under review disagree over managing a significant risk item. According to IIA guidance, which of the following actions should the CAE take first?

Options:

A.

Refer the matter to the board for resolution

B.

Consult the approved audit charter on supremacy of internal auditors’ decisions

C.

Record management’s and the internal auditor ' s positions in the audit report

D.

Discuss the issue in question further with senior management

Question 124

Which of the following authentication device credentials is the most difficult to revoke when an employee ' s access rights need to be removed?

Options:

A.

A traditional key lock.

B.

A biometric device.

C.

A card-key system.

D.

A proximity device.

Question 125

The comparable uncontrolled price (CUP) method may be used when setting transfer prices in an organization.

What is a common limitation of the CUP method?

Options:

A.

It may be difficult to find a transaction between independent companies that is similar enough to a controlled transaction.

B.

The CUP method is likely to lead to management decisions that are not optimal for the company.

C.

This approach to setting transfer prices is not flexible, as the CUP method does not allow for adjustments.

D.

It offers only an indirect way of ascertaining an arm’s-length price of a controlled transaction.

Question 126

A manager at a publishing company received an email that appeared to be from one of her vendors with an attachment that contained malware embedded in an Excel spreadsheet . When the spreadsheet was opened, the cybercriminal was able to attack the company ' s network and gain access to an unpublished and highly anticipated book. Which of the following controls would be most effective to prevent such an attack?

Options:

A.

Monitoring network traffic.

B.

Using whitelists and blacklists to manage network traffic.

C.

Restricting access and blocking unauthorized access to the network

D.

Educating employees throughout the company to recognize phishing attacks.

Question 127

Which of the following best describes depreciation?

Options:

A.

It is a process of allocating cost of assets between periods.

B.

It is a process of assets valuation.

C.

It is a process of accumulating adequate funds to replace assets.

D.

It is a process of measuring decline in the value of assets because of obsolescence

Question 128

After purchasing shoes from an online retailer, a customer continued to receive additional unsolicited offers from the retailer and other retailers who offer similar products.

Which of the following is the most likely control weakness demonstrated by the seller?

Options:

A.

Excessive collecting of information

B.

Application of social engineering

C.

Retention of incomplete information.

D.

Undue disclosure of information

Question 129

Which of the following is a limitation of the remote wipe for a smart device?

Options:

A.

Encrypted data cannot be locked to prevent further access

B.

Default settings cannot be restored on the device.

C.

All data, cannot be completely removed from the device

D.

Mobile device management software is required for successful remote wipe

Question 130

In light of increasing emission taxes in the European Union, a car manufacturer introduced a new middle-class hybrid vehicle specifically for the European market only. Which of the following competitive strategies has the manufacturer used?

Options:

A.

Reactive strategy.

B.

Cost leadership strategy.

C.

Differentiation strategy.

D.

Focus strategy

Question 131

Which of the following activities most significantly increases the risk that a bank will make poor-quality loans to its customers?

Options:

A.

Borrowers may not sign all required mortgage loan documentation.

B.

Fees paid by the borrower at the time of the loan may not be deposited in a timely manner.

C.

The bank ' s loan documentation may not meet the government ' s disclosure requirements.

D.

Loan officers may override the lending criteria established by senior management.

Question 132

The engagement supervisor prepares the final engagement communication for dissemination. Since the chief audit executive (CAE) is on leave, the supervisor is delegated to disseminate the final engagement communication to all relevant parties. Who should be accountable for the final engagement communication?

Options:

A.

Engagement supervisor

B.

Chief audit executive

C.

The board

D.

The internal audit team

Question 133

An organization has instituted a bring-your-own-device (BYOD) work environment. Which of the following policies best addresses the increased risk to the organization’s network incurred by this environment?

Options:

A.

Limit the use of the employee devices for personal use to mitigate the risk of exposure to organizational data

B.

Ensure that relevant access to key applications is strictly controlled through an approval and review process

C.

Institute detection and authentication controls for all devices used for network connectivity and data storage

D.

Use management software to scan and then prompt patch reminders when devices connect to the network

Question 134

Which of the following statements regarding organizational governance is not correct?

Options:

A.

An effective internal audit function is one of the four cornerstones of good governance.

B.

Those performing governance activities are accountable to the customer.

C.

Accountability is one of the key elements of organizational governance.

D.

Governance principles and the need for an internal audit function are applicable to governmental and not-for-profit activities.

Question 135

A retail organization is considering acquiring a composite textile company. The retailer ' s due diligence team determined the value of the textile company to be $50 million. The financial experts forecasted net present value of future cash flows to be $60 million. Experts at the textile company determined their company ' s market value to be $55 million if purchased by another entity. However, the textile company could earn more than $70 million from the retail organization due to synergies. Therefore, the textile company is motivated to make the negotiation successful. Which of the following approaches is most likely to result in a successful negotiation?

Options:

A.

Develop a bargaining zone that lies between $50 million and $70 million and create sets of outcomes between $50 million and $70 million.

B.

Adopt an added-value negotiating strategy, develop a bargaining zone between $50 million and $70 million, and create sets of outcomes between $50 million and $70 million.

C.

Involve a mediator as a neutral party who can work with the textile company ' s management to determine a bargaining zone.

D.

Develop a bargaining zone that lies between $55 million and $60 million and create sets of outcomes between $55 million and $60 million.

Question 136

Which of the following types of data analytics would be used by a hospital to determine which patients are likely to require readmittance for additional treatment?

Options:

A.

Predictive analytics

B.

Prescriptive analytics

C.

Descriptive analytics

D.

Diagnostic analytics

Question 137

Which of the following statements is true regarding the management-by-objectives (MBO) approach?

Options:

A.

Management by objectives is most helpful in organizations that have rapid changes

B.

Management by objectives is most helpful in mechanistic organizations with rigidly defined tasks

C.

Management by objectives helps organizations to keep employees motivated

D.

Management by objectives helps organizations to distinguish clearly strategic goals from operational goals

Question 138

According to Herzberg ' s Two-Factor Theory of Motivation, which of the following is a factor mentioned most often by satisfied employees?

Options:

A.

Relationship with supervisor

B.

Salary

C.

Security.

D.

Achievement

Question 139

An organization produces two products, X and Y. The materials used for the production of both products are limited to 500 kilograms (kg) per month. All other resources are unlimited and their costs are fixed.

Individual product details are as follows:

Product X: Selling price per unit: $10; Materials per unit at $1/kg: 2 kg; Monthly demand: 100 units.

Product Y: Selling price per unit: $13; Materials per unit at $1/kg: 6 kg; Monthly demand: 120 units.

In order to maximize profit, how much of product Y should the organization produce each month?

Options:

A.

50 units.

B.

60 units.

C.

100 units.

D.

120 units.

Question 140

Which of the following is a cybersecurity monitoring activity intended to deter disruptive codes from being installed on an organizations systems?

Options:

A.

Boundary defense

B.

Malware defense.

C.

Penetration tests

D.

Wireless access controls

Question 141

According to the COSO enterprise risk management framework, which of the following is not a typical responsibility of the chief risk officer?

Options:

A.

Establishing risk category definitions and a common risk language for likelihood and impact measures.

B.

Defining enterprise risk management roles and responsibilities.

C.

Providing the board with an independent, objective risk perspective on financial reporting.

D.

Guiding integration of enterprise risk management with other management activities.

Question 142

How should internal auditors respond when the manager of an area under review disagrees with a finding?

Options:

A.

Escalate the disagreements to the CEO

B.

Ignore the manager’s concerns and proceed with finalizing the audit report

C.

Escalate the disagreements to the chief audit executive

D.

Reperform the audit process where there are disagreements

Question 143

A chief audit executive (CAE) is calculating the available internal audit resource hours while planning the annual internal audit plan. The CAE needs to calculate the total number of hours available for audits. Which of the following should be deducted in order to have time available only for engagements?

Options:

A.

Time spent on coaching the internal audit function on new engagement procedures

B.

Time spent on the preliminary risk assessment of the engagement

C.

Time spent for the documentation of supporting files for the engagement

D.

Time spent on reporting the results of the engagement

Question 144

A software that translates hypertext markup language (HTML) documents and allows a user to view a remote web page is called:

Options:

A.

A transmission control protocol/Internet protocol (TCP/IP).

B.

An operating system.

C.

A web browser.

D.

A web server.

Question 145

Which of the following networks is best for an organization to use when employees are granted access rights to authenticate themselves to the IT resources from outside the organization?

Options:

A.

Local area network.

B.

Wide area network.

C.

Metropolitan area network.

D.

Virtual private network.

Question 146

An internal audit activity is piloting a data analytics model, which aims to identify anomalies in payments to vendors and potential fraud indicators. Which of the following would be the most appropriate criteria for assessing the success of the piloted model?

Options:

A.

The percentage of cases flagged by the model and confirmed as positives.

B.

The development and maintenance costs associated with the model

C.

The feedback of auditors involved with developing the model.

D.

The number of criminal investigations initiated based on the outcomes of the model

Question 147

During her annual performance review, a sales manager admits that she experiences significant stress due to her job but stays with the organization because of the high bonuses she earns. Which of the following best describes her primary motivation to remain in the job?

Options:

A.

Intrinsic reward.

B.

Job enrichment

C.

Extrinsic reward.

D.

The hierarchy of needs.

Question 148

Which of the following statements is true regarding the term " flexible budgets " as it is used in accounting?

Options:

A.

The term describes budgets that exclude fixed costs.

B.

Flexible budgets exclude outcome projections, which are hard to determine, and instead rely on the most recent actual outcomes.

C.

The term is a red flag for weak budgetary control activities.

D.

Flexible budgets project data for different levels of activity.

Question 149

According to Herzberg ' s Two-Factor Theory of Motivation, which of the following is a factor mentioned most often by satisfied employees?

Options:

A.

Security.

B.

Status.

C.

Recognition.

D.

Relationship with coworkers

Question 150

Which of the following is likely to have an expiration date and may contain stored clear text passwords?

Options:

A.

Cookie.

B.

Universal resource locator (URL).

C.

Hypertext transport protocol (HTTP).

D.

Browser.

Question 151

An organization has recorded the following profit and expenses:

Profit before interest and tax: $200,000

Sales: $2,300,000

Purchases of materials: $700,000

Interest expenses: $30,000

If the value-added tax rate is 20 percent and the corporate tax rate is 30 percent, which of the following is the amount of VAT that the organization has to pay?

Options:

A.

$34,000

B.

$51,000

C.

$60,000

D.

$320,000

Question 152

Which of the following sites would an Internet service provider most likely use to restore operations after its servers were damaged by a natural disaster?

Options:

A.

On site.

B.

Cold site.

C.

Hot site.

D.

Warm site

Question 153

The internal audit function is instructed by the audit committee to assess and give an opinion annually on risk management process effectiveness. However, lacking in-house expertise, the chief audit executive (CAE) initially appoints an independent consultant to assist with this engagement. Which of the following approaches is the most appropriate?

Options:

A.

The engagement is wholly performed by the independent consultant and the CAE forms the opinion

B.

The independent consultant accomplishes the entire engagement and forms the opinion

C.

Internal auditors work with the independent consultant and the CAE forms the opinion

D.

Internal auditors carry out the entire engagement and the independent consultant forms the opinion

Question 154

During the second half of the audit year, the chief audit executive (CAE) identified significant negative variances to the approved audit budget required to complete the internal audit plan. Which of the following actions should the CAE take?

Options:

A.

Revise the internal audit plan to reduce coverage of new strategic critical areas so that the approved budget can be met

B.

Reduce the scope of the remainder of the engagements in the internal audit plan to reduce overall costs

C.

Communicate to senior management and the board the risk of not being able to complete the audit plan

D.

Continue to complete the plan regardless of the budget variances, as the audit function is invaluable to sound corporate governance

Question 155

When using the absorption costing approach, which of the following should be categorized as a period cost?

Options:

A.

Selling expenses.

B.

Fixed manufacturing overhead.

C.

Direct labor.

D.

Variable manufacturing overhead.

Question 156

An organization is testing its data recovery plan. The crisis scenario includes disruption to the internet and mobile connections and the need to recover the production management information system from a backup server. Since it is not possible to call a third-party service provider, an employee was sent to receive backup hard drives. However, the office of the service provider was closed, and the organization had to abort testing.

Which of the following has the organization failed to foresee in its recovery plan?

Options:

A.

Offline backup retrieval process.

B.

Online backup recovery process.

C.

Mobile connection recovery process.

D.

Onsite backup preservation process.

Question 157

Which of the following is considered a physical security control?

Options:

A.

Transaction logs are maintained to capture a history of system processing.

B.

System security settings require the use of strong passwords and access controls.

C.

Failed system login attempts are recorded and analyzed to identify potential security incidents.

D.

System servers are secured by locking mechanisms with access granted to specific individuals.

Question 158

During a review of the tendering process, an internal auditor observes that unusual bidding requirements for IT hardware across several tenders appears to consistently favor one supplier. The internal auditor suspects that a bid-rigging scheme is occurring. Which of the following best describes the methodology used by the internal auditor?

Options:

A.

Diagnostic analysis.

B.

Predictive analysis.

C.

Textual analysis.

D.

Network analysis.

Question 159

Which of the following controls would be the most effective in preventing the disclosure of an organization ' s confidential electronic information?

Options:

A.

Nondisclosure agreements between the firm and its employees.

B.

Logs of user activity within the information system.

C.

Two-factor authentication for access into the information system.

D.

limited access so information, based on employee duties

Question 160

Which of the following describes the most appropriate set of tests for auditing a workstation ' s logical access controls?

Options:

A.

Review the list of people with access badges to the room containing the workstation and a log of those who accessed the room.

B.

Review the password length, frequency of change, and list of users for the workstation ' s login process.

C.

Review the list of people who attempted to access the workstation and failed, as well as error messages.

D.

Review the passwords of those who attempted unsuccessfully to access the workstation and the log of their activity

Question 161

An internal auditor reviews a data population and calculates the mean, median, and range. What is the most likely purpose of performing this analytic technique?

Options:

A.

To inform the classification of the data population.

B.

To determine the completeness and accuracy of the data.

C.

To identify whether the population contains outliers.

D.

To determine whether duplicates in the data inflate the range.

Question 162

A restaurant decided to expand its business to include delivery services, rather than relying on third-party food delivery services. Which of the following best describes the restaurants strategy?

Options:

A.

Diversification

B.

Vertical integration

C.

Risk avoidance

D.

Differentiation

Question 163

Which of the following is a characteristic of just-in-time inventory management systems?

Options:

A.

Users determine the optimal level of safety stocks.

B.

They are applicable only to large organizations.

C.

They do not really increase overall economic efficiency because they merely shift inventory levels further up the supply chain.

D.

They rely heavily on high-quality materials.

Question 164

In terms of international business strategy, which of the following is true regarding a multi-domestic strategy?

Options:

A.

It uses the same products in all countries.

B.

It centralizes control with little decision-making authority given to the local level.

C.

It is an effective strategy when large differences exist between countries.

D.

It provides cost advantages, improves coordinated activities, and speeds product development.

Question 165

Refer to the exhibit. The figure below shows the network diagram for the activities of a large project. What is the shortest number of days in which the project can be completed?

Options:

A.

21 days.

B.

22 days.

C.

27 days.

D.

51 days.

Question 166

A company records income from an investment in common stock when it does which of the following?

Options:

A.

Purchases bonds.

B.

Receives interest.

C.

Receives dividends

D.

Sells bonds.

Question 167

Which of the following database components stores metadata regarding the database’s own configuration, setup, and objects?

Options:

A.

Database table.

B.

Program files.

C.

Backup system.

D.

Data dictionary.

Question 168

Which of the following statements describes the typical benefit of using a flat organizational structure for the internal audit activity, compared to a hierarchical structure?

Options:

A.

A flat structure results in lower operating and support costs than a hierarchical structure.

B.

A flat structure results in a stable and very collaborative environment.

C.

A flat structure enables field auditors to report to and learn from senior auditors.

D.

A flat structure is more dynamic and offers more opportunities for advancement than a hierarchical structure.

Question 169

Which of the following information security controls has the primary function of preventing unauthorized outside users from accessing an organization ' s data through the organization ' s network?

Options:

A.

Firewall.

B.

Encryption.

C.

Antivirus.

D.

Biometrics.

Question 170

Which of the following is true of matrix organizations?

Options:

A.

A unity-of-command concept requires employees to report technically, functionally, and administratively to the same manager.

B.

A combination of product and functional departments allows management to utilize personnel from various functions.

C.

Authority, responsibility, and accountability of the units involved may vary based on the project ' s life or the organization ' s culture.

D.

It is best suited for firms with scattered locations or for multi-line, large-scale firms.

Question 171

In an organization that produces chocolate, the leadership team decides that the organization will open a milk production facility for its milk chocolate. Which of the following strategies have the organization chosen?

Options:

A.

Vertical integration.

B.

Unrelated diversification.

C.

Differentiation

D.

Focus

Question 172

Which of the following is the primary goal of an effective business impact analysis?

Options:

A.

It includes business continuity program governance and risk management.

B.

It identifies key assets, critical processes, resources, and technology.

C.

It sets testing requirements for the organization wide continuity functions.

D.

It outlines and communicates recovery points and objectives.

Question 173

Which of the following statements is true regarding the use of public key encryption to secure data while it is being transmitted across a network?

Options:

A.

Both the key used to encrypt the data and the key used to decrypt the data are made public.

B.

The key used to encrypt the data is kept private but the key used to decrypt the data is made public.

C.

The key used to encrypt the data is made public but the key used to decrypt the data is kept private.

D.

Both the key used to encrypt the data and the key used to decrypt the data are made private.

Question 174

Which of the following is the most appropriate way lo record each partner ' s initial Investment in a partnership?

Options:

A.

At the value agreed upon by the partners.

B.

At book value.

C.

At fair value

D.

At the original cost.

Question 175

Which of the following accurately describes the proper order of steps for an internal auditor to use when analyzing data?

Options:

A.

Obtain the data, clean and normalize the data, define the question, analyze the data.

B.

Define the question, obtain the data, analyze the data, clean and normalize the data.

C.

Define the question, obtain the data, clean and normalize the data, analyze the data.

D.

Obtain the data, analyze the data, clean and normalize the data, define the question.

Question 176

Which of the following should software auditors do when reporting internal audit findings related to enterprisewide resource planning?

Options:

A.

Draft separate audit reports for business and IT management.

B.

Conned IT audit findings to business issues.

C.

Include technical details to support IT issues.

D.

Include an opinion on financial reporting accuracy and completeness.

Question 177

Which of the following security controls would be appropriate to protect the exchange of information?

Options:

A.

Firewalls.

B.

Activity logs.

C.

Antivirus software.

D.

File encryption.

Question 178

Which of the following serves as a safeguard to protect the confidentiality of information being transmitted from an internal network to an external network?

Options:

A.

A cloud network.

B.

A mobile network.

C.

An intranet.

D.

A virtual private network.

Question 179

An organization uses radio frequency identification (RFID) technology to identify vehicles authorized to enter a gated facility. The RFID reader scans the vehicle ' s license plate number, and if the number is on a pre-authorized list, a green light flashes, indicating to the security guard that he can push a button to open the gate.

Which of the following controls should be added to ensure that a particular vehicle is authorized to enter the facility?

Options:

A.

The security guard should question the vehicle ' s driver, if the guard has any doubts.

B.

Physical characteristics of the vehicle should be described in the system.

C.

The security guard should send each access request to administrative personnel for validation prior to admitting the vehicle into the gated facility.

D.

Video surveillance cameras should be installed to provide a full view of the vehicle.

Question 180

The cost to enter a foreign market would be highest in which of the following methods of global expansion?

Options:

A.

Joint ventures.

B.

Licensing.

C.

Exporting.

D.

Overseas production.

Question 181

An organization has a declining inventory turnover but an increasing gross margin rate. Which of the following statements can best explain this situation?

Options:

A.

he organization ' s operating expenses are increasing.

B.

The organization has adopted just-in-time inventory.

C.

The organization is experiencing inventory theft.

D.

The organization ' s inventory is overstated.

Question 182

The board is considering outsourcing the internal audit function to an external service provider. Which of the following would always remain the responsibility of the organization?

Options:

A.

Ongoing monitoring of the quality of internal audit documents

B.

Defining audit scopes sufficient to achieve the engagements ' objectives

C.

Maintaining a quality assurance and improvement program

D.

Assessment of organizational risks for the annual audit plan

Question 183

Which of the following actions is most likely to gain support for process change?

Options:

A.

Set clear objectives.

B.

Engage the various communities of practice within the organization.

C.

Demonstrate support from senior management.

D.

Establish key competencies.

Question 184

Which of the following is a security feature that Involves the use of hardware and software to filter or prevent specific Information from moving between the inside network and the outs de network?

Options:

A.

Authorization

B.

Architecture model

C.

Firewall

D.

Virtual private network

Question 185

Which of the following statements is true concerning the basic accounting treatment of a partnership?

Options:

A.

The initial investment of each partner should be recorded at book value.

B.

The ownership ratio identifies the basis for dividing net income and net toss.

C.

A partner ' s capital only changes due to net income or net loss.

D.

The basis for sharing net incomes or net kisses must be fixed.

Question 186

Which of the following is the best reason for considering the acquisition of a nondomestic organization?

Options:

A.

Relatively fast market entry.

B.

Improved cash flow of the acquiring organization.

C.

Increased diversity of corporate culture.

D.

Opportunity to influence local government policy.

Question 187

Which of the following statements depicts a valid role of the internal audit function in ensuring the effectiveness of management action plans?

Options:

A.

Internal audit should not be involved in the design, implementation, or monitoring of management action plans in order to maintain independence and objectivity

B.

Internal audit supports the board in the design, implementation, and monitoring of effective management action plans

C.

Internal audit collaborates with management to evaluate whether the management action plans remediate audit observations effectively

D.

Internal audit designs the action plans and ensures that management implements them effectively

Question 188

Which of the following focuses on finding statistical relationships in order to create profiles?

Options:

A.

Process mining.

B.

Process analysis.

C.

Data mining.

D.

Data analysis.

Question 189

Which of the following best describes owner ' s equity?

Options:

A.

Assets minus liabilities.

B.

Total assets.

C.

Total liabilities.

D.

Owners contribution plus drawings.

Question 190

An organization has a declining inventory turnover but an Increasing gross margin rate, Which of the following statements can best explain this situation?

Options:

A.

The organization ' s operating expenses are increasing.

B.

The organization has adopted just-in-time inventory.

C.

The organization is experiencing Inventory theft

D.

The organization ' s inventory is overstated.

Question 191

With regard to project management, which of the following statements about project crashing Is true?

Options:

A.

It leads to an increase in risk and often results in rework.

B.

It is an optimization technique where activities are performed in parallel rather than sequentially.

C.

It involves a revaluation of project requirements and/or scope.

D.

It is a compression technique in which resources are added so the project.

Question 192

Internal auditors want to increase the likelihood of identifying very small control and transaction anomalies in their testing that could potentially be exploited to cause material breaches. Which of the following techniques would best meet this objective?

Options:

A.

Analysis of the full population of existing data.

B.

Verification of the completeness and integrity of existing data.

C.

Continuous monitoring on a repetitive basis.

D.

Analysis of the databases of partners, such as suppliers.

Question 193

When determining the level of physical controls required for a workstation, which of the following factors should be considered?

Options:

A.

Ease of use.

B.

Value to the business.

C.

Intrusion prevention.

D.

Ergonomic model.

Question 194

Which of the following performance measures would be appropriate for evaluating an investment center, which has responsibility for its revenues, costs, and investment base, but would not be appropriate for evaluating cost, revenue, or profit centers?

Options:

A.

A flexible budget.

B.

Variance analysis.

C.

A contribution margin income statement by segment.

D.

Residual income.

Question 195

Which of the following best describes the job design strategy used by the chief audit executive that encourages internal auditors to manage engagements from the beginning to the end?

Options:

A.

Job sharing.

B.

Job shadowing.

C.

Job enrichment.

D.

Job rotation.

Question 196

A manager decided to build his team ' s enthusiasm by giving encouraging talks about employee empowerment, hoping to change the perception that management should make all decisions in the department.

The manager is most likely trying to impact which of the following components of his team ' s attitude?

Options:

A.

Affective component.

B.

Cognition component.

C.

Thinking component.

D.

Behavioral component.

Question 197

An organization ' s technician was granted a role that enables him to prioritize projects throughout the organization. Which type of authority will the technician most likely be exercising?

Options:

A.

Legitimate authority

B.

Coercive authority.

C.

Referent authority.

D.

Expert authority.

Question 198

Which of the following disaster recovery plans includes recovery resources available at the site, but they may need to be configured to support the production system?

Options:

A.

Warm site recovery plan.

B.

Hot site recovery plan.

C.

Cool site recovery plan.

D.

Cold site recovery plan.

Question 199

Which of the following controls would be most efficient to protect business data from corruption and errors?

Options:

A.

Controls to ensure data is unable to be accessed without authorization.

B.

Controls to calculate batch totals to identify an error before approval.

C.

Controls to encrypt the data so that corruption is likely ineffective.

D.

Controls to quickly identify malicious intrusion attempts.

Question 200

Which of the following is not a method for implementing a new application system?

Options:

A.

Direct cutover.

B.

Parallel.

C.

Pilot.

D.

Test.

Question 201

Which of the following is a potential risk for an organization that allows employees to use their personal devices to conduct business?

Options:

A.

Less efficiency.

B.

Lower employee satisfaction.

C.

Higher organizational costs on devices.

D.

Increased exposure to malware attacks.

Question 202

Management is pondering the following question:

" How does our organization compete? "

This question pertains to which of the following levels of strategy?

Options:

A.

Functional-level strategy

B.

Corporate-level strategy.

C.

Business-level strategy,

D.

DepartmentsHevet strategy

Question 203

Which of the following should the chief audit executive agree upon with the board before starting an external assessment of the internal audit function?

Options:

A.

The audit areas that should be reviewed

B.

The level of testing that will be required

C.

The qualifications needed on the external assessment team

D.

The specialized skills that each external assessment team member needs

Question 204

Which of the following items represents a limitation with an impact the chief audit executive should report to the board?

Options:

A.

Audit procedures

B.

Reporting forms

C.

Available skills

D.

Available methods

Question 205

Which of the following is an advantage of a decentralized organizational structure, as opposed to a centralized structure?

Options:

A.

Greater cost-effectiveness

B.

Increased economies of scale

C.

Larger talent pool

D.

Strong internal controls

Question 206

An internal auditor considers the financial statement of an organization as part of a financial assurance engagement. The auditor expresses the organization ' s electricity and depreciation expenses as a percentage of revenue to be 10% and 7% respectively. Which of the following techniques was used by the internal auditor In this calculation?

Options:

A.

Horizontal analysis

B.

Vertical analysis

C.

Ratio analysis

D.

Trend analysis

Question 207

The project charter is an output from which of the following?

Options:

A.

Scope planning.

B.

Scope definition.

C.

Scope verification.

D.

Project initiation.

Question 208

Which of the following application controls, implemented by management, monitors data being processed to ensure the data remains consistent and accurate?

Options:

A.

Management trail controls

B.

Output controls.

C.

Integrity controls

D.

input controls

Question 209

Which of the following are the most common characteristics of big data?

Options:

A.

Visibility, validity, vulnerability

B.

Velocity, variety, volume

C.

Complexity, completeness, constancy

D.

Continuity, control, convenience

Question 210

Which of the following statements accurately describes the responsibility of the internal audit activity regarding IT governance?

    The internal audit activity does not have any responsibility because IT governance is the responsibility of the board and senior management of the organization.

    The internal audit activity must assess whether the IT governance of the organization supports the organization ' s strategies and objectives.

    The internal audit activity may assess whether the IT governance of the organization supports the organization ' s strategies and objectives.

    The internal audit activity may accept requests from management to perform advisory services regarding how the IT governance of the organization supports the organization ' s strategies and objectives.

Options:

A.

1 only

B.

4 only

C.

2 and 4

D.

3 and 4

Question 211

According to the International Professional Practices Framework, internal auditors who are assessing the adequacy of organizational risk management processes should not:

Options:

A.

Recognize that organizations use different techniques for managing risk.

B.

Seek assurance that the key objectives of the risk management processes are being met.

C.

Determine and accept the level of risk for the organization.

D.

Treat the evaluation of risk management processes differently from the risk analysis used to plan audit engagements.

Question 212

An intruder posing as the organization ' s CEO sent an email and tricked payroll staff into providing employees ' private tax information. What type of attack was perpetrated?

Options:

A.

Boundary attack.

B.

Spear phishing attack.

C.

Brute force attack.

D.

Spoofing attack.

Question 213

Which of the following best describes a detective control designed to protect an organization from cyberthreats and attacks?

Options:

A.

A list of trustworthy, good traffic and a list of unauthorized, blocked traffic.

B.

Monitoring for vulnerabilities based on industry intelligence.

C.

Comprehensive service level agreements with vendors.

D.

Firewall and other network perimeter protection tools.

Question 214

Which of the following controls would enable management to receive timely feedback and help mitigate unforeseen risks?

Options:

A.

Measure product performance against an established standard.

B.

Develop standard methods for performing established activities.

C.

Require the grouping of activities under a single manager.

D.

Assign each employee a reasonable workload.

Question 215

During a routine bank branch audit, the internal audit function observed that the sole security guard at the branch only worked part time. The chief audit executive (CAE) believed that this increased the risk of loss of property and life in the event of a robbery. The branch security manager informed the CAE that a full-time guard was not needed because the branch was in close proximity to a police station. Still, the CAE found this to be an unacceptable risk due to the recent increase in robberies in that area. Which of the following is the most appropriate next step for the CAE to take?

Options:

A.

Immediately report the issue to the board to ensure timely corrective actions are taken to resolve the risk

B.

Continue discussions with the security manager until he is persuaded and agrees to increase branch security

C.

Document the security manager’s decision to accept the risk in the audit workpapers

D.

Escalate the issue to the bank’s chief security officer to determine acceptability of the risk

Question 216

Which of the following roles would be least appropriate for the internal audit activity to undertake with regard to an organization ' s corporate social responsibility program?

Options:

A.

Consult on project design and implementation of the CSR program.

B.

Serve as an advisor on internal controls related to CSR.

C.

Identify and prioritize the CSR issues that are important to the organization.

D.

Evaluate the effectiveness of the organization ' s CSR efforts.

Question 217

Which of the following controls is the most effective in mitigating activities of bots that continuously attempt to access a user’s account?

Options:

A.

Password length.

B.

User session timeout.

C.

User account lockout.

D.

Password aging.

Question 218

An organization upgraded to a new accounting software. Which of the following activities should be performed by the IT software vendor immediately following the upgrade?

Options:

A.

Market analysis lo identify trends

B.

Services to manage and maintain the IT Infrastructure.

C.

Backup and restoration.

D.

Software testing and validation

Question 219

The management of working capital is most crucial for which of the following aspects of business?

Options:

A.

Liquidity

B.

Profitability

C.

Solvency

D.

Efficiency

Question 220

The board of directors wants to implement an incentive program for senior management that is specifically tied to the long-term health of the organization. Which of the following methods of compensation would be best to achieve this goal?

Options:

A.

Commissions.

B.

Stock options

C.

Gain-sharing bonuses.

D.

Allowances

Question 221

Which of the following cost of capital methods identifies the time period required to recover She cost of the capital investment from the annual inflow produced?

Options:

A.

Cash payback technique

B.

Annual rate of return technique.

C.

Internal rate of return method.

D.

Net present value method.

Question 222

An internal auditor is assigned to perform data analytics. Which of the following is the next step the auditor should undertake after she has ascertained the value expected from the review?

Options:

A.

Normalize the data,

B.

Obtain the data

C.

Identify the risks.Analyze the data.

Question 223

Which of the following best explains why an organization would enter into a capital lease contract?

Options:

A.

To increase the ability to borrow additional funds from creditors

B.

To reduce the organization ' s free cash flow from operations

C.

To Improve the organization ' s free cash flow from operations

D.

To acquire the asset at the end of the lease period at a price lower than the fair market value

Question 224

Which of the following dimensions relates to the quality of big data?

Options:

A.

Veracity.

B.

Validity.

C.

Value.

D.

Variety.

Question 225

What must be monitored in order to manage the risk of consumer product inventory obsolescence?

    Inventory balances.

    Market share forecasts.

    Sales returns.

    Sales trends.

Options:

A.

1 only

B.

4 only

C.

1 and 4 only

D.

1, 2, and 3 only

Question 226

Which of the following budgets must be prepared first?

Options:

A.

Cash budget.

B.

Production budget.

C.

Sales budget.

D.

Selling and administrative expenses budget.

Question 227

When auditing an application change control process, which of the following procedures should be included in the scope of the audit?

    Ensure system change requests are formally initiated, documented, and approved.

    Ensure processes are in place to prevent emergency changes from taking place.

    Ensure changes are adequately tested before being placed into the production environment.

    Evaluate whether the procedures for program change management are adequate.

Options:

A.

1 only

B.

1 and 3 only

C.

2 and 4 only

D.

1, 3, and 4 only

Question 228

Several organizations have developed a strategy to open co-owned shopping malls. What would be the primary purpose of this strategy?

Options:

A.

To exploit core competence.

B.

To increase market synergy.

C.

To deliver enhanced value.

D.

To reduce costs.

Question 229

During a payroll audit, the internal auditor is assessing the security of the local area network of the payroll department computers. Which of the following IT controls should the auditor test?

Options:

A.

IT application-based controls

B.

IT systems development controls

C.

Environmental controls

D.

IT governance controls

Question 230

A one-time password would most likely be generated in which of the following situations?

Options:

A.

When an employee accesses an online digital certificate

B.

When an employee ' s biometrics have been accepted.

C.

When an employee creates a unique digital signature,

D.

When an employee uses a key fob to produce a token.

Question 231

Which of the following statements is most accurate concerning the management and audit of a web server?

Options:

A.

The file transfer protocol (FTP) should always be enabled

B.

The simple mail transfer protocol (SMTP) should be operating under the most privileged accounts

C.

The number of ports and protocols allowed to access the web server should be maximized

D.

Secure protocols for confidential pages should be used instead of clear-text protocols such as HTTP or FTP

Question 232

A brand manager in a consumer food products organization suspected that several days of the point-of-sale data on the spreadsheet from one grocery chain were missing. The best approach for detecting missing rows in spreadsheet data would be to:

Options:

A.

Sort on product identification code and identify missing product identification codes.

B.

Review store identification code and identify missing product identification codes.

C.

Compare product identification codes for consecutive periods.

D.

Compare product identification codes by store for consecutive periods.

Question 233

Management has established a performance measurement focused on the accuracy of disbursements. The disbursement statistics, provided daily to ail accounts payable and audit staff, include details of payments stratified by amount and frequency. Which of the following is likely to be the greatest concern regarding this performance measurement?

Options:

A.

Articulation of the data

B.

Availability of the data.

C.

Measurability of the data

D.

Relevance of the data.

Question 234

A significant project is nearing its development stage end, and line management intends to apply for a final investment decision from senior management at an upcoming meeting. The internal audit function is at the fieldwork stage of an assurance engagement related to this project and discovers that tenders conducted for the project were not carried out transparently by line management. The audit report will not be ready by the upcoming senior management meeting. Which of the following actions is the most appropriate next step for the chief audit executive?

Options:

A.

Escalate the issue to the chief risk officer

B.

Raise the issue with senior management

C.

Continue with the assurance engagement as planned

D.

Place the assurance engagement on hold due to inappropriate timing

Question 235

An internal auditor is reviewing physical and environmental controls for an IT organization. Which control activity should not be part of this review?

Options:

A.

Develop and test the organization ' s disaster recovery plan.

B.

Install and test fire detection and suppression equipment.

C.

Restrict access to tangible IT resources.

D.

Ensure that at least one developer has access to both systems and operations.

Question 236

Which of the following physical access controls often functions as both a preventive and detective control?

Options:

A.

Locked doors.

B.

Firewalls.

C.

Surveillance cameras.

D.

Login IDs and passwords.

Question 237

An investor has acquired an organization that has a dominant position in a mature, slow-growth industry and consistently creates positive financial income. Which of the following terms would the investor most likely label this investment in her portfolio?

Options:

A.

A star

B.

A cash cow

C.

A question mark

D.

A dog

Demo: 237 questions
Total 791 questions