Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Internal Audit Function Question and Answers

Internal Audit Function

Last Update Jul 26, 2026
Total Questions : 791

We are offering FREE IIA-CIA-Part3 IIA exam questions. All you do is to just go and sign up. Give your details, prepare IIA-CIA-Part3 free exam questions and then go for complete pool of Internal Audit Function test questions that will help you more.

IIA-CIA-Part3 pdf

IIA-CIA-Part3 PDF

$36.75  $104.99
IIA-CIA-Part3 Engine

IIA-CIA-Part3 Testing Engine

$43.75  $124.99
IIA-CIA-Part3 PDF + Engine

IIA-CIA-Part3 PDF + Testing Engine

$57.75  $164.99
Questions 1

Which of the following data analytics methods involves analyzing event trends to determine what happened?

Options:

A.  

Diagnostic analytics.

B.  

Descriptive analytics.

C.  

Predictive analytics.

D.  

Prescriptive analytics.

Discussion 0
Questions 2

Which of the following statements is true with regard to capital budgeting?

Options:

A.  

Using the net present value method, a proposal is acceptable when the net present value is negative.

B.  

The internal rate of return is the highest interest rate that will cause the present value of the proposed capital expenditure to be less than the present value of expected net annual cash flows.

C.  

The cash payback technique is used to determine the period of time required to recover the capital investment, plus the expected return, from the annual cash flow produced by the investment.

D.  

The annual rate of return technique is used to estimate the profitability of a capital expenditure by dividing the expected annual net income by the average investment.

Discussion 0
Questions 3

Which of the following statements is accurate regarding the use of Secure Sockets Layer (SSL) as a control?

Options:

A.  

It supports the authentication of information sent to a server.

B.  

It prevents phishing attacks that redirect users to malicious sites.

C.  

It prevents malware infections.

D.  

It identifies each client-server session using temporary tokens.

Discussion 0
Questions 4

An intruder posing as the organization ' s CEO sent an email and tricked payroll staff into providing employees ' private tax information. What type of attack was perpetrated?

Options:

A.  

Boundary attack.

B.  

Spear phishing attack.

C.  

Brute force attack.

D.  

Spoofing attack.

Discussion 0
Questions 5

Which of the following concepts of managerial accounting is focused on achieving a point of low or no inventory?

Options:

A.  

Theory of constraints.

B.  

Just-in-time method.

C.  

Activity-based costing.

D.  

Break-even analysis

Discussion 0
Questions 6

A small software development firm designs and produces custom applications for businesses. The application development team consists of employees from multiple departments who all report to a single project manager. Which of the following organizational structures does this situation represent?

Options:

A.  

Functional departmentalization.

B.  

Product departmentalization

C.  

Matrix organization.

D.  

Divisional organization

Discussion 0
Questions 7

Which statement is true regarding the development of a risk-based internal audit plan?

Options:

A.  

It requires a previously conducted assurance engagement on the organization’s risk management maturity

B.  

It requires an assessment by the internal audit function of key risks identified within the organization ' s risk management system

C.  

It requires that at least 90% of planned engagements address areas critical to the organization ' s strategy

D.  

It requires that an organization adheres to a well-recognized risk management framework in order to identify and manage its risks

Discussion 0
Questions 8

Which of the following IT layers would require the organization to maintain communication with a vendor in a tightly controlled and monitored manner?

Options:

A.  

Applications

B.  

Technical infrastructure.

C.  

External connections.

D.  

IT management

Discussion 0
Questions 9

An internal auditor uses a risk and control questionnaire as part of the preliminary survey for an audit of the organization ' s anti-bribery and corruption program. What is the primary purpose of using this approach?

Options:

A.  

To compare records from one source to subsequently prepared records about the anti-bribery program

B.  

To ascertain the existence of certain controls in the organization ' s anti-bribery program

C.  

To obtain testimonial information about certain controls in the organization ' s anti-bribery program

D.  

To validate control information through outside parties independent of the anti-bribery program

Discussion 0
Questions 10

Which of the following controls is designed to mitigate a physical IT risk?

Options:

A.  

An automated fire prevention system.

B.  

Access control restrictions in a system.

C.  

Anti-malware protection software.

D.  

A network isolating firewall system.

Discussion 0
Questions 11

An internal auditor is auditing their organization’s termination process. A primary objective of this engagement is to verify that exit interviews were conducted for all terminated employees over the last two years. The auditor discovered that not all employees received exit interviews.

Which of the following risks could this lead to?

Options:

A.  

The risk of employee turnover.

B.  

The risk of noncompliance with a local labor law.

C.  

The risk of incorrect severance payments.

D.  

The risk of a confidentiality breach.

Discussion 0
Questions 12

When reviewing application controls using the four-level model, which of the following processes are associated with level 4 of the business process method?

Options:

A.  

Activity

B.  

Subprocess

C.  

Major process

D.  

Mega process

Discussion 0
Questions 13

Which of the following would be classified as IT general controls?

Options:

A.  

Error listings.

B.  

Distribution controls.

C.  

Transaction logging.

D.  

Systems development controls.

Discussion 0
Questions 14

Which of the following practices impacts copyright issues related to the manufacturer of a smart device?

Options:

A.  

Session hijacking.

B.  

Jailbreaking

C.  

Eavesdropping,

D.  

Authentication.

Discussion 0
Questions 15

Which of the following is an example of a physical control?

Options:

A.  

Providing fire detection and suppression equipment

B.  

Establishing a physical security policy and promoting it throughout the organization

C.  

Performing business continuity and disaster recovery planning

D.  

Keeping an offsite backup of the organization’s critical data

Discussion 0
Questions 16

An organization ' s technician was granted a role that enables him to prioritize projects throughout the organization. Which type of authority will the technician most likely be exercising?

Options:

A.  

Legitimate authority

B.  

Coercive authority.

C.  

Referent authority.

D.  

Expert authority.

Discussion 0
Questions 17

Which of the following is a typical activity performed by the help desk?

Options:

A.  

Monitoring the network

B.  

Troubleshooting

C.  

Backing up data

D.  

Assigning authorizations to a user, a role, or profile

Discussion 0
Questions 18

Which of the following techniques is the most relevant when an internal auditor conducts a valuation of an organization ' s physical assets?

Options:

A.  

Observation.

B.  

Inspection.

C.  

Original cost.

D.  

Vouching.

Discussion 0
Questions 19

Which of the following risks would Involve individuals attacking an oil company ' s IT system as a sign of solidarity against drilling in a local area?

Options:

A.  

Tampering

B.  

Hacking

C.  

Phishing

D.  

Piracy

Discussion 0
Questions 20

During a payroll audit, the internal auditor is assessing the security of the local area network of the payroll department computers. Which of the following IT controls should the auditor test?

Options:

A.  

IT application-based controls

B.  

IT systems development controls

C.  

Environmental controls

D.  

IT governance controls

Discussion 0
Questions 21

Based on test results, an IT auditor concluded that the organization would suffer unacceptable loss of data if there was a disaster at its data center. Which of the following test results would likely lead the auditor to this conclusion?

Options:

A.  

Requested backup tapes were not returned from the offsite vendor in a timely manner

B.  

Returned backup tapes from the offsite vendor contained empty spaces

C.  

Critical systems have been backed up more frequently than required

D.  

Critical system backup tapes are taken off site less frequently than required

Discussion 0
Questions 22

Capacity overbuilding is most likely to occur when management is focused on which of the following?

Options:

A.  

Marketing.

B.  

Finance.

C.  

Production.

D.  

Diversification.

Discussion 0
Questions 23

Which of the following are the most appropriate measures for evaluating the change in an organization ' s liquidity position?

Options:

A.  

Times interest earned, return on assets, and inventory turnover.

B.  

Accounts receivable turnover, inventory turnover in days, and the current ratio.

C.  

Accounts receivable turnover, return on assets, and the current ratio.

D.  

Inventory turnover in days, the current ratio, and return on equity.

Discussion 0
Questions 24

An internal auditor discusses user-defined default passwords with the database administrator. Such passwords will be reset as soon as the user logs in for the first time, but the initial value of the password is set as " 123456. " Which of the following are the auditor and the database administrator most likely discussing in this situation?

Options:

A.  

Whether it would be more secure to replace numeric values with characters.

B.  

What happens in the situations where users continue using the initial password.

C.  

What happens in the period between the creation of the account and the password change.

D.  

Whether users should be trained on password management features and requirements.

Discussion 0
Questions 25

Which of the following would be the strongest control to prevent unauthorized wireless network access?

Options:

A.  

Allowing access to the organization ' s network only through a virtual private network.

B.  

Logging devices that access the network, including the date. time, and identity of the user.

C.  

Tracking all mobile device physical locations and banning access from non-designated areas.

D.  

Permitting only authorized IT personnel to have administrative control of mobile devices.

Discussion 0
Questions 26

Which of the following analytical techniques would an internal auditor use to verify that none of an organization ' s employees are receiving fraudulent invoice payments?

Options:

A.  

Perform gap testing.

B.  

Join different data sources.

C.  

Perform duplicate testing.

D.  

Calculate statistical parameters.

Discussion 0
Questions 27

An organization produces products X and Y. The materials used for the production of both products are limited to 500 Kilograms

(kg ) per month. All other resources are unlimited and their costs are fixed. Individual product details are as follows in order to maximize profit, how much of product Y should the organization produce each month?

$10 $13

2 kg

70 units

6 kg

120 units

Options:

A.  

50 units

B.  

60 units

C.  

70 units

D.  

1:20 units

Discussion 0
Questions 28

Which of the following biometric access controls uses the most unique human recognition characteristic?

Options:

A.  

Facial comparison using photo identification.

B.  

Signature comparison.

C.  

Voice comparison.

D.  

Retinal print comparison.

Discussion 0
Questions 29

An organization has an agreement with a third-party vendor to have a fully operational facility, duplicate of the original site and configured to the organization ' s needs, in order to quickly recover operational capability in the event of a disaster, Which of the following best describes this approach to disaster recovery planning?

Options:

A.  

Cold recovery plan,

B.  

Outsourced recovery plan.

C.  

Storage area network recovery plan.

D.  

Hot recovery plan

Discussion 0
Questions 30

An organization’s account for office supplies on hand had a balance of $9,000 at the end of year one. During year two, the organization recorded an expense for purchasing office supplies. At the end of year two, a physical count determined that the organization has $11,500 in office supplies on hand. Based on this information, what would be recorded in the adjusting entry at the end of year two?

Options:

A.  

A debit to office supplies on hand for $2,500

B.  

A debit to office supplies on hand for $11,500

C.  

A debit to office supplies on hand for $20,500

D.  

A debit to office supplies on hand for $42,500

Discussion 0
Questions 31

Which of the following application controls is the most dependent on the password owner?

Options:

A.  

Password selection.

B.  

Password aging.

C.  

Password lockout.

D.  

Password rotation.

Discussion 0
Questions 32

Which of the following statements is true regarding a project life cycle?

Options:

A.  

Risk and uncertainty increase over the life of the project.

B.  

Costs and staffing levels are typically high as the project draws to a close.

C.  

Costs related to making changes increase as the project approaches completion.

D.  

The project life cycle corresponds with the life cycle of the product produced by or modified by the project.

Discussion 0
Questions 33

Which mindset promotes the most comprehensive risk management strategy?

Options:

A.  

Increase shareholder value.

B.  

Maximize market share.

C.  

Improve operational efficiency.

D.  

Mitigate losses.

Discussion 0
Questions 34

Data analysis indicates that a hospital pharmacy disbursed higher levels of controlled drugs than similar pharmacies in the area. The hospital ' s internal auditor discusses the risk with the head of the hospital pharmacy, who believes that the risk is appropriately mitigated by controls and feels comfortable with the number of prescriptions written.

What should the auditor do next?

Options:

A.  

Document that the head of the pharmacy has accepted the risk and believes it is sufficiently mitigated, and conclude the risk assessment.

B.  

Request that an independent third party re-perform the data analysis to verify the accuracy of the initial findings.

C.  

Investigate the risk by requesting pharmacy policies, procedures, and detailed reports.

D.  

Add an audit of the hospital pharmacy to the annual audit plan to fully investigate the risk later in the year.

Discussion 0
Questions 35

Which of the following lists best describes the classification of manufacturing costs?

Options:

A.  

Direct materials, indirect materials, raw materials.

B.  

Overhead costs, direct labor, direct materials.

C.  

Direct materials, direct labor, depreciation on factory buildings.

D.  

Raw materials, factory employees ' wages, production selling expenses.

Discussion 0
Questions 36

Which of the following are appropriate functions for an IT steering committee?

    Assess the technical adequacy of standards for systems design and programming.

    Continually monitor the adequacy and accuracy of software and hardware in use.

    Assess the effects of new technology on the organization ' s IT operations.

    Provide broad oversight of implementation, training, and operation of new systems.

Options:

A.  

1, 2, and 3

B.  

1, 2, and 4

C.  

1, 3, and 4

D.  

2, 3, and 4

Discussion 0
Questions 37

An organization sells 1,000 shares of its treasury stock at $15 per share previously acquired at $10 per share.

Which of the following statements is true?

Options:

A.  

The organization should record a $5,000 gain on sale of treasury stock.

B.  

The organization should record $15,000 as a debit to treasury stock.

C.  

The organization should record $5,000 as a credit to paid-in capital.

D.  

The organization should record a $10,000 debit to paid-capital account.

Discussion 0
Questions 38

Which of the following is the most appropriate way lo record each partner ' s initial Investment in a partnership?

Options:

A.  

At the value agreed upon by the partners.

B.  

At book value.

C.  

At fair value

D.  

At the original cost.

Discussion 0
Questions 39

During her annual performance review, a sales manager admits that she experiences significant stress due to her job but stays with the organization because of the high bonuses she earns. Which of the following best describes her primary motivation to remain in the job?

Options:

A.  

Intrinsic reward.

B.  

Job enrichment

C.  

Extrinsic reward.

D.  

The hierarchy of needs.

Discussion 0
Questions 40

Management has established a performance measurement focused on the accuracy of disbursements. The disbursement statistics, provided daily to ail accounts payable and audit staff, include details of payments stratified by amount and frequency. Which of the following is likely to be the greatest concern regarding this performance measurement?

Options:

A.  

Articulation of the data

B.  

Availability of the data.

C.  

Measurability of the data

D.  

Relevance of the data.

Discussion 0
Questions 41

Which of the following is a security feature that involves the use of hardware and software to filter or prevent specific information from moving between the inside network and the outside network?

Options:

A.  

Authorization

B.  

Architecture model

C.  

Firewall

D.  

Virtual private network

Discussion 0
Questions 42

During an internal audit engagement, numerous deficiencies in the organization ' s management of customer data were discovered, entailing the risk of breaching personal data protection legislation. An improvement plan was approved by senior management. Which of the following conditions observed during the periodic follow-up process best justifies the chief audit executive ' s decision to escalate the issue to the board?

Options:

A.  

The organization ' s customer satisfaction index does not show any signs of improvement

B.  

No budget or resources have been allocated to implement corrective measures

C.  

The board has not been informed about the planned improvements approved by senior management

D.  

Employees responsible for improvements are resisting any additional workload

Discussion 0
Questions 43

An organization that sells products to a foreign subsidiary wants to charge a price that will decrease import tariffs. Which of the following is the best course of action for the organization?

Options:

A.  

Decrease the transfer price.

B.  

Increase the transfer price.

C.  

Charge at the arm’s length price.

D.  

Charge at the optimal transfer price.

Discussion 0
Questions 44

An internal auditor reviews a data population and calculates the mean, median, and range. What is the most likely purpose of performing this analytic technique?

Options:

A.  

To inform the classification of the data population.

B.  

To determine the completeness and accuracy of the data.

C.  

To identify whether the population contains outliers.

D.  

To determine whether duplicates in the data inflate the range.

Discussion 0
Questions 45

Maintenance cost at a hospital was observed to increase as activity level increased. The following data was gathered:

January: 5,600 patient days; maintenance cost $7,900

February: 7,100 patient days; maintenance cost $8,500

March: 5,000 patient days; maintenance cost $7,400

April: 6,500 patient days; maintenance cost $8,200

May: 7,300 patient days; maintenance cost $9,100

June: 8,000 patient days; maintenance cost $9,800

If the cost of maintenance is expressed in an equation, what is the independent variable for this data?

Options:

A.  

Fixed cost.

B.  

Variable cost.

C.  

Total maintenance cost.

D.  

Patient days.

Discussion 0
Questions 46

According to IIA guidance, which of the following statements is true with regard to workstation computers that access company information stored on the network?

Options:

A.  

Individual workstation computer controls are not as important as companywide server controls

B.  

Particular attention should be paid to housing workstations away from environmental hazards

C.  

Cybersecurity issues can be controlled at an enterprise level, making workstation-level controls redundant

D.  

With security risks near an all-time high, workstations should not be connected to the company network

Discussion 0
Questions 47

Which of the following can be classified as debt investments?

Options:

A.  

Investments in the capital stock of a corporation

B.  

Acquisition of government bonds.

C.  

Contents of an investment portfolio,

D.  

Acquisition of common stock of a corporation

Discussion 0
Questions 48

A large retail customer made an offer to buy 10.000 units at a special price of $7 per unit. The manufacturer usually sells each unit for §10, Variable Manufacturing costs are 55 per unit and fixed manufacturing costs are $3 per unit. For the manufacturer to accept the offer, which of the following assumptions needs to be true?

Options:

A.  

Fixed and Variable manufacturing costs are less than the special offer selling price.

B.  

The manufacturer can fulfill the order without expanding the capacities of the production facilities.

C.  

Costs related to accepting this offer can be absorbed through the sale of other products.

D.  

The manufacturer’s production facilities are currently operating at full capacity.

Discussion 0
Questions 49

According to Porter ' s model of competitive strategy, which of the following is a generic strategy?

    Differentiation.

    Competitive advantage.

    Focused differentiation.

    Cost focus.

Options:

A.  

2 only

B.  

3 and 4 only

C.  

1, 3, and 4 only

D.  

1, 2, 3, and 4

Discussion 0
Questions 50

An organization uses radio frequency identification (RFID) technology to identify vehicles authorized to enter a gated facility. The RFID reader scans the vehicle ' s license plate number, and if the number is on a pre-authorized list, a green light flashes, indicating to the security guard that he can push a button to open the gate.

Which of the following controls should be added to ensure that a particular vehicle is authorized to enter the facility?

Options:

A.  

The security guard should question the vehicle ' s driver, if the guard has any doubts.

B.  

Physical characteristics of the vehicle should be described in the system.

C.  

The security guard should send each access request to administrative personnel for validation prior to admitting the vehicle into the gated facility.

D.  

Video surveillance cameras should be installed to provide a full view of the vehicle.

Discussion 0
Questions 51

Which of the following describes the primary advantage of using data analytics in internal auditing?

Options:

A.  

It helps support the internal audit conclusions with factual evidence.

B.  

It reduces the time and effort needed to prepare the audit report.

C.  

It helps prevent internal auditors from unknowingly disregarding key process risks.

D.  

It enables internal auditors to meet their responsibility for monitoring controls.

Discussion 0
Questions 52

Which of the following types of date analytics would be used by a hospital to determine which patients are likely to require remittance for additional treatment?

Options:

A.  

Predictive analytics.

B.  

Prescriptive analytics.

C.  

Descriptive analytics.

D.  

Diagnostic analytics.

Discussion 0
Questions 53

Which of the following best describes owner ' s equity?

Options:

A.  

Assets minus liabilities.

B.  

Total assets.

C.  

Total liabilities.

D.  

Owners contribution plus drawings.

Discussion 0
Questions 54

The main reason to establish internal controls in an organization is to:

Options:

A.  

Encourage compliance with policies and procedures.

B.  

Safeguard the resources of the organization.

C.  

Ensure the accuracy, reliability, and timeliness of information.

D.  

Provide reasonable assurance on the achievement of objectives.

Discussion 0
Questions 55

Which of the following statements is true regarding multi-report summaries for members of senior management and the board?

Options:

A.  

Multi-report summaries should be used to describe the work performed by the internal audit function

B.  

In developing multi-report summaries, internal auditors should use multi-row and multi-column tables

C.  

Multi-report summaries are not useful to boards that see every engagement report

D.  

Multi-report summaries are readily developed if each finding is rated

Discussion 0
Questions 56

Which of the following disaster recovery plans includes recovery resources available at the site, but they may need to be configured to support the production system?

Options:

A.  

Warm site recovery plan.

B.  

Hot site recovery plan.

C.  

Cool site recovery plan.

D.  

Cold site recovery plan.

Discussion 0
Questions 57

The profile of an internal auditor ' s personality traits reveals that the auditor is most motivated by self-actualization needs.

Given this, which of the following is likely to serve as the best motivator for this auditor?

Options:

A.  

Rotate the auditor to work within a multi-disciplinary audit team.

B.  

Assign the auditor to work on complex and challenging audits.

C.  

Reassure the auditor that the internal audit budget is stable and the auditor ' s job is secure.

D.  

Offer increased benefits in the auditor ' s compensation package.

Discussion 0
Questions 58

Which of the following best describes the chief audit executive ' s responsibility for assessing the organization ' s residual risk?

Options:

A.  

Create an action plan to mitigate the risk

B.  

Incorporate management acceptance of risk in the workpapers as internal audit evidence

C.  

Report deviations immediately to the board

D.  

Communicate the matter with senior management

Discussion 0
Questions 59

Which of the following is an indicator of liquidity that is more dependable than working capital?

Options:

A.  

Acid-test (quick) ratio

B.  

Average collection period

C.  

Current ratio.

D.  

Inventory turnover.

Discussion 0
Questions 60

Which of the following is a distinguishing feature of managerial accounting, which is not applicable to financial accounting?

Options:

A.  

Managerial accounting uses double-entry accounting and cost data.

B.  

Managerial accounting uses general accepted accounting principles.

C.  

Managerial accounting involves decision making based on quantifiable economic events.

D.  

Managerial accounting involves decision making based on predetermined standards.

Discussion 0
Questions 61

For employees, the primary value of implementing job enrichment is which of the following?

Options:

A.  

Validation of the achievement of their goals and objectives

B.  

Increased knowledge through the performance of additional tasks

C.  

Support for personal growth and a meaningful work experience

D.  

An increased opportunity to manage better the work done by their subordinates

Discussion 0
Questions 62

Which of the following can be viewed as a potential benefit of an enterprisewide resource planning system?

Options:

A.  

Real-time processing of transactions and elimination of data redundancies.

B.  

Fewer data processing errors and more efficient data exchange with trading partners.

C.  

Exploitation of opportunities and mitigation of risks associated with e-business.

D.  

Integration of business processes into multiple operating environments and databases.

Discussion 0
Questions 63

When using data analytics during a review of the procurement process, what is the first step in the analysis process?

Options:

A.  

Identify data anomalies and outliers

B.  

Define questions to be answered

C.  

Identify data sources available

D.  

Determine the scope of the data extract

Discussion 0
Questions 64

Which of the following is true of bond financing, compared to common stock, when alJ other variables are equal?

Options:

A.  

Lower shareholder control

B.  

lower indebtedness

C.  

Higher company earnings per share.

D.  

Higher overall company earnings

Discussion 0
Questions 65

Which of the following statements is in accordance with COBIT?

    Pervasive controls are general while detailed controls are specific.

    Application controls are a subset of pervasive controls.

    Implementation of software is a type of pervasive control.

    Disaster recovery planning is a type of detailed control.

Options:

A.  

1 and 4 only

B.  

2 and 3 only

C.  

2, 3, and 4 only

D.  

1, 2, and 4 only

Discussion 0
Questions 66

According to IIA guidance on IT, which of the following best describes a situation where data backup plans exist to ensure that critical data can be restored at some point in the future, but recovery and restore processes have not been defined?

Options:

A.  

Hot recovery plan

B.  

Warm recovery plan

C.  

Cold plan

D.  

Absence of recovery plan

Discussion 0
Questions 67

According to IIA guidance, which of the following is a broad collection of integrated policies, standards, and procedures used to guide the planning and execution of a project?

Options:

A.  

Project portfolio.

B.  

Project development

C.  

Project governance.

D.  

Project management methodologies

Discussion 0
Questions 68

How should a chief audit executive learn about emerging risk areas in an organization?

Options:

A.  

Build and maintain a collaborative network with management

B.  

Build an organization-wide risk management process

C.  

Review the organization ' s procedures for conducting an annual risk assessment

D.  

Review the organization ' s procedures for establishing its risk appetite

Discussion 0
Questions 69

Which of the following statements is true regarding IT controls within an organization?

Options:

A.  

IT risks and controls should be assessed at least once every five years.

B.  

Responsibility for effective IT controls rests exclusively with management.

C.  

An effective IT control environment should consist of all possible general IT and application controls.

D.  

Regardless of how well an IT control is designed it may be subject to error and management override.

Discussion 0
Questions 70

According to Maslow ' s hierarchy of needs theory, which of the following would likely have the most impact on retaining staff, if their lower-level needs are already met?

Options:

A.  

Social benefits.

B.  

Compensation.

C.  

Job safety.

D.  

Recognition

Discussion 0
Questions 71

Which of the following is a potential risk for an organization that allows employees to use their personal devices to conduct business?

Options:

A.  

Less efficiency.

B.  

Lower employee satisfaction.

C.  

Higher organizational costs on devices.

D.  

Increased exposure to malware attacks.

Discussion 0
Questions 72

What kind of strategy would be most effective for an organization to adopt in order to Implement a unique advertising campaign for selling identical product lines across all of its markets?

Options:

A.  

Export strategy.

B.  

Transnational strategy

C.  

Multi-domestic strategy

D.  

Globalization strategy

Discussion 0
Questions 73

A retail organization is considering acquiring a composite textile company. The retailer ' s due diligence team determined the value of the textile company to be $50 million. The financial experts forecasted net present value of future cash flows to be $60 million. Experts at the textile company determined their company ' s market value to be $55 million if purchased by another entity. However, the textile company could earn more than $70 million from the retail organization due to synergies. Therefore, the textile company is motivated to make the negotiation successful. Which of the following approaches is most likely to result in a successful negotiation?

Options:

A.  

Develop a bargaining zone that lies between $50 million and $70 million and create sets of outcomes between $50 million and $70 million.

B.  

Adopt an added-value negotiating strategy, develop a bargaining zone between $50 million and $70 million, and create sets of outcomes between $50 million and $70 million.

C.  

Involve a mediator as a neutral party who can work with the textile company ' s management to determine a bargaining zone.

D.  

Develop a bargaining zone that lies between $55 million and $60 million and create sets of outcomes between $55 million and $60 million.

Discussion 0
Questions 74

In light of increasing emission taxes in the European Union, a car manufacturer introduced a new middle-class hybrid vehicle specifically for the European market only. Which of the following competitive strategies has the manufacturer used?

Options:

A.  

Reactive strategy.

B.  

Cost leadership strategy.

C.  

Differentiation strategy.

D.  

Focus strategy

Discussion 0
Questions 75

Which of the following describes a mechanistic organizational structure?

Options:

A.  

Primary direction of communication tends to be lateral.

B.  

Definition of assigned tasks tends to be broad and general.

C.  

Type of knowledge required tends to be broad and professional.

D.  

Reliance on self-control tends to be low.

Discussion 0
Questions 76

As part of internal audit ' s risk assessment, a chief audit executive is determining certain factors as part of planning the areas to audit within an organization that makes silicon chips. Which of the following would be considered a subjective factor as part of the risk assessment?

Options:

A.  

The number of vendors able to meet the supply demand request from the organization

B.  

The quality of the staff supervision of silicon chips produced by the organization

C.  

The length of time since the last audit of the organization ' s manufacturing facilities

D.  

The asset value of the silicon chips that the organization did not produce because of a shortage in raw materials

Discussion 0
Questions 77

When writing a business memorandum, the writer should choose a writing style that achieves all of the following except:

Options:

A.  

Draws positive attention to the writing style.

B.  

Treats all receivers with respect.

C.  

Suits the method of presentation and delivery.

D.  

Develops ideas without overstatement.

Discussion 0
Questions 78

What must be monitored in order to manage the risk of consumer product inventory obsolescence?

    Inventory balances.

    Market share forecasts.

    Sales returns.

    Sales trends.

Options:

A.  

1 only

B.  

4 only

C.  

1 and 4 only

D.  

1, 2, and 3 only

Discussion 0
Questions 79

A global business organization is selecting managers to post to various international expatriate assignments. In the screening process, which of the following traits would be required to make a manager a successful expatriate?

    Superior technical competence.

    Willingness to attempt to communicate in a foreign language.

    Ability to empathize with other people.

Options:

A.  

1 and 2 only

B.  

1 and 3 only

C.  

2 and 3 only

D.  

1, 2, and 3

Discussion 0
Questions 80

According to IIA guidance, which of the following would be a primary reason for an internal auditor to test the organization ' s IT contingency plan?

Options:

A.  

To ensure that adequate controls exist to prevent any significant business interruptions.

B.  

To identify and address potential security weaknesses within the system.

C.  

To ensure that tests contribute to improvement of the program.

D.  

To ensure that deficiencies identified by the audit are promptly addressed.

Discussion 0
Questions 81

Which of the following represents an inventory costing technique that can be manipulated by management to boost net income by selling units purchased at a low cost?

Options:

A.  

First-in. first-out method (FIFO).

B.  

Last-in, first-out method (LIFO).

C.  

Specific identification method.

D.  

Average-cost method

Discussion 0
Questions 82

When developing an effective risk-based plan to determine audit priorities, an internal audit activity should start by:

Options:

A.  

Identifying risks to the organization ' s operations.

B.  

Observing and analyzing controls.

C.  

Prioritizing known risks.

D.  

Reviewing organizational objectives.

Discussion 0
Questions 83

An organization filters data packets from public networks to send to an internal private network.

Which of the following devices would accomplish this?

Options:

A.  

A router.

B.  

A switch.

C.  

A hub.

D.  

A proxy gateway.

Discussion 0
Questions 84

Which of the following statements about assurance maps is true?

Options:

A.  

They help identify gaps and duplications in an organization’s assurance coverage

B.  

They allow the board to coordinate activities of internal and external assurance providers

C.  

They help identify which assurance provider is responsible for performing each audit listed in the annual internal audit plan

D.  

They allow internal auditors to map competencies and specialty areas of the assurance providers in an organization

Discussion 0
Questions 85

Which of the following scenarios best illustrates a spear phishing attack?

Options:

A.  

Numerous and consistent attacks on the company ' s website caused the server to crash and service was disrupted.

B.  

A person posing as a representative of the company’s IT help desk called several employees and played a generic prerecorded message requesting password data.

C.  

A person received a personalized email regarding a golf membership renewal, and he click a hyperlink to enter his credit card data into a fake website

D.  

Many users of a social network service received fake notifications of e unique opportunity to invest in a new product.

Discussion 0
Questions 86

The sole internal auditor of a municipality wants to implement proper supervision over internal audit workpapers. Which of the following would be the most appropriate?

Options:

A.  

According to the Global Internal Audit Standards, in this situation the internal auditor can perform a self-review of selected workpapers

B.  

Request each engagement client to conduct a review of a sample of workpapers at the end of the engagement

C.  

Ask the board or management to sign off on workpapers

D.  

Engage peer reviewers from other organizations with legal precautions in place

Discussion 0
Questions 87

Which of the following is true regarding an organization ' s relationship with external stakeholders?

Options:

A.  

Specific guidance must be followed when interacting with nongovernmental organizations.

B.  

Disclosure laws tend to be consistent from one jurisdiction to another.

C.  

There are several internationally recognized standards for dealing with financial donors.

D.  

Legal representation should be consulted before releasing internal audit information to other assurance providers.

Discussion 0
Questions 88

According to Maslow’s hierarchy of needs theory, which of the following best describes a strategy where a manager offers an assignment to a subordinate specifically to support his professional growth and future advancement?

Options:

A.  

Esteem by colleagues

B.  

Self-fulfillment

C.  

Sense of belonging in the organization

D.  

Job security

Discussion 0
Questions 89

Which of the following risks would involve individuals attacking an oil company’s IT system as a sign of solidarity against drilling in a local area?

Options:

A.  

Tampering

B.  

Hacking

C.  

Phishing

D.  

Piracy

Discussion 0
Questions 90

A new clerk in the managerial accounting department applied the high-low method and computed the difference between the high and low levels of maintenance costs. Which type of maintenance costs did the clerk determine?

Options:

A.  

Fixed maintenance costs.

B.  

Variable maintenance costs.

C.  

Mixed maintenance costs.

D.  

Indirect maintenance costs.

Discussion 0
Questions 91

When would a contract be dosed out?

Options:

A.  

When there ' s a dispute between the contracting parties

B.  

When ail contractual obligations have been discharged.

C.  

When there is a force majenre.

D.  

When the termination clause is enacted.

Discussion 0
Questions 92

Following an evaluation of an organization ' s IT controls, an internal auditor suggested improving the process where results are compared against the input. Which of the following IT controls would the Internal auditor recommend?

Options:

A.  

Output controls.

B.  

Input controls

C.  

Processing controls.

D.  

Integrity controls.

Discussion 0
Questions 93

Which of the following steps should an internal auditor take during an audit of an organization ' s business continuity plans?

    Evaluate the business continuity plans for adequacy and currency.

    Prepare a business impact analysis regarding the loss of critical business.

    Identify key personnel who will be required to implement the plans.

    Identify and prioritize the resources required to support critical business processes.

Options:

A.  

1 only

B.  

2 and 4 only

C.  

1, 3, and 4 only

D.  

1, 2, 3, and 4

Discussion 0
Questions 94

Which of the following conditions could lead an organization to enter into a new business through internal development rather than through acquisition?

Options:

A.  

It is expected that there will be slow retaliation from incumbents.

B.  

The acquiring organization has information that the selling organization is weak.

C.  

The number of bidders to acquire the organization for sale is low.

D.  

The condition of the economy is poor.

Discussion 0
Questions 95

While auditing an organization ' s customer call center, an internal auditor notices that Key performance indicators show a positive trend, despite the fact that there have been increasing customer complaints over the same period. Which of the following audit recommendations would most likely correct the cause of this inconsistency?

Options:

A.  

Review the call center script used by customer service agents to interact with callers, and update the script if necessary.

B.  

Be-emphasize the importance of call center employees completing a certain number of calls per hour.

C.  

Retrain call center staff on area processes and common technical issues that they will likely be asked to resolve.

D.  

Increase the incentive for call center employees to complete calls quickly and raise the number of calls completed daily

Discussion 0
Questions 96

An organization that produces backpacks of standard quality is considering manufacturing high-quality packs. Which of the following costs is most relevant when deciding whether to manufacture the new product?

Options:

A.  

Fixed costs.

B.  

Variable costs.

C.  

Conversion costs.

D.  

Incremental costs.

Discussion 0
Questions 97

Which of the following accounting methods is an investor organization likely to use when buying 40 percent of the stock of another organization?

Options:

A.  

Cost method.

B.  

Equity method .

C.  

Consolidation method.

D.  

Fair value method.

Discussion 0
Questions 98

Which of the following accurately describes a difference between phishing and spear phishing?

Options:

A.  

Phishing targets individuals indiscriminately, while spear phishing targets specific individuals.

B.  

Phishing uses emails in attacks, while spear phishing uses other methods.

C.  

Phishing requires unauthorized access to a system, while spear phishing requires successful social engineering attempts.

D.  

Phishing aims to acquire personal information, while spear phishing aims to send unsolicited notifications or advertisements.

Discussion 0
Questions 99

Which of the following is an advantage of a decentralized organizational structure, as opposed to a centralized structure?

Options:

A.  

Greater cost-effectiveness

B.  

Increased economies of scale

C.  

Larger talent pool

D.  

Strong internal controls

Discussion 0
Questions 100

A significant project is nearing its development stage end, and line management intends to apply for a final investment decision from senior management at an upcoming meeting. The internal audit function is at the fieldwork stage of an assurance engagement related to this project and discovers that tenders conducted for the project were not carried out transparently by line management. The audit report will not be ready by the upcoming senior management meeting. Which of the following actions is the most appropriate next step for the chief audit executive?

Options:

A.  

Escalate the issue to the chief risk officer

B.  

Raise the issue with senior management

C.  

Continue with the assurance engagement as planned

D.  

Place the assurance engagement on hold due to inappropriate timing

Discussion 0
Questions 101

Which of the following is not a potential area of concern when an internal auditor places reliance on spreadsheets developed by users?

Options:

A.  

Increasing complexity over time.

B.  

Interface with corporate systems.

C.  

Ability to meet user needs.

D.  

Hidden data columns or worksheets.

Discussion 0
Questions 102

Which of the following is an element of effective negotiating?

Options:

A.  

Ensuring that the other party has a personal stake in the agreement.

B.  

Focusing on interests rather than on obtaining a winning position.

C.  

Considering a few select choices during the settlement phase.

D.  

Basing the agreement on negotiating power and positioning leverage.

Discussion 0
Questions 103

According to IIA guidance, which of the following is an IT project success factor?

Options:

A.  

Streamlined decision-making, rather than building consensus among users.

B.  

Consideration of the facts, rather than consideration of the emotions displayed by project stakeholders.

C.  

Focus on flexibility and adaptability, rather than use of a formal methodology.

D.  

Inclusion of critical features, rather than inclusion of an array of supplementary features.

Discussion 0
Questions 104

Which of the following does not provide operational assurance that a computer system is operating properly?

Options:

A.  

Performing a system audit.

B.  

Making system changes.

C.  

Testing policy compliance.

D.  

Conducting system monitoring.

Discussion 0
Questions 105

A line on a spreadsheet includes an employee ' s name, date of hire, job title, and monthly salary. Which of the following correctly describes this line information?

Options:

A.  

Field.

B.  

File.

C.  

Record.

D.  

Database.

Discussion 0
Questions 106

An organization ' s financial statements indicate a note that the financial statements have been prepared on the basis of the organization continuing operations for the foreseeable future. Which of the following accounting principles has been applied based on this note?

Options:

A.  

Monetary unit assumption.

B.  

Going concern assumption.

C.  

Time period assumption.

D.  

Economic entity assumption.

Discussion 0
Questions 107

Which of the following bring-your-own-device (BYOD) practices is likely to increase the risk of Infringement on local regulations, such as copyright or privacy laws?

Options:

A.  

Not installing anti-malware software

B.  

Updating operating software in a haphazard manner,

C.  

Applying a weak password for access to a mobile device.

D.  

JoIIbreaking a locked smart device

Discussion 0
Questions 108

The finance department of an organization recently undertook an asset verification exercise. The internal audit function scheduled a review of the IT department’s operations, which includes verifying the existence of computers distributed and their assignment. Can the internal audit function consider relying on the asset verification work performed by the finance department?

Options:

A.  

Yes, in order to be efficient and make better use of internal audit resources

B.  

No, as the finance department is an internal department of the organization

C.  

Yes, but the finance manager would be responsible for supporting the conclusions of the work

D.  

No, the internal audit function should do its own verification and should not rely on the work of finance

Discussion 0
Questions 109

A company that uses the accrual basis of accounting can recognize revenue under which of the following conditions?

Options:

A.  

When cash is received as payment for a service.

B.  

When the receivable is recognized.

C.  

When a check is received as payment for a good that has been ordered.

D.  

When a good is provided or a service is performed.

Discussion 0
Questions 110

Which of the following is the most appropriate action an internal auditor would perform during an audit of his organization ' s IT change management process?

Options:

A.  

Validate that only authorized personnel can migrate changes into the production environment.

B.  

Perform a risk assessment to determine the likelihood that risk could occur due to insufficient patch application.

C.  

Publish a schedule that lists all approved changes and planned implementation dates.

D.  

Update change management processes on a consistent basis to keep up with changing technologies.

Discussion 0
Questions 111

With regard to disaster recovery planning, which of the following would most likely involve stakeholders from several departments?

Options:

A.  

Determining the frequency with which backups will be performed.

B.  

Prioritizing the order in which business systems would be restored.

C.  

Assigning who in the IT department would be involved in the recovery procedures.

D.  

Assessing the resources needed to meet the data recovery objectives.

Discussion 0
Questions 112

After identifying and reporting a control deficiency, which of the following actions should an internal auditor perform next?

Options:

A.  

Ensure full documentation of the control deficiency and close out the audit file

B.  

Follow up on the remediation status with business management periodically

C.  

Note this control area “audited” and mark it as out-of-scope for the following year

D.  

Design a remediation plan and ensure operational management follows through

Discussion 0
Questions 113

An organization prepares a statement of privacy to protect customers ' personal information. Which of the following might violate the privacy principles?

Options:

A.  

Customers can access and update personal information when needed.

B.  

The organization retains customers ' personal information indefinitely.

C.  

Customers reserve the right to reject sharing personal information with third parties.

D.  

The organization performs regular maintenance on customers ' personal information.

Discussion 0
Questions 114

Which of the following financial statements provides the best disclosure of how a company ' s money was used during a particular period?

Options:

A.  

Income statement.

B.  

Owner ' s equity statement.

C.  

Balance sheet.

D.  

Statement of cash flows.

Discussion 0
Questions 115

Which of the following situations best applies to an organisation that uses a project, rather than a process, to accomplish its business activities?

Options:

A.  

Clothing company designs, makes, and sells a new item.

B.  

A commercial construction company is hired to build a warehouse.

C.  

A city department sets up a new firefighter training program.

D.  

A manufacturing organization acquires component parts from a contracted vendor

Discussion 0
Questions 116

Which of the following controls would enable management to receive timely feedback and help mitigate unforeseen risks?

Options:

A.  

Measure product performance against an established standard.

B.  

Develop standard methods for performing established activities.

C.  

Require the grouping of activities under a single manager.

D.  

Assign each employee a reasonable workload.

Discussion 0
Questions 117

According to the COSO enterprise risk management framework, which of the following is not a typical responsibility of the chief risk officer?

Options:

A.  

Establishing risk category definitions and a common risk language for likelihood and impact measures.

B.  

Defining enterprise risk management roles and responsibilities.

C.  

Providing the board with an independent, objective risk perspective on financial reporting.

D.  

Guiding integration of enterprise risk management with other management activities.

Discussion 0
Questions 118

A manager decided to build his team ' s enthusiasm by giving encouraging talks about employee empowerment, hoping to change the perception that management should make all decisions in the department.

The manager is most likely trying to impact which of the following components of his team ' s attitude?

Options:

A.  

Affective component.

B.  

Cognition component.

C.  

Thinking component.

D.  

Behavioral component.

Discussion 0
Questions 119

Which of the following is an example of a physical control designed to prevent security breaches?

Options:

A.  

Preventing database administrators from initiating program changes

B.  

Blocking technicians from getting into the network room.

C.  

Restricting system programmers ' access to database facilities

D.  

Using encryption for data transmitted over the public internet

Discussion 0
Questions 120

Which of the following bring-your-own-device (BYOD) practices is likely to increase the risk of infringement on local regulations, such as copyright or privacy laws?

Options:

A.  

Not installing anti-malware software.

B.  

Updating operating software in a haphazard manner.

C.  

Applying a weak password for access to a mobile device.

D.  

Jailbreaking a locked smart device.

Discussion 0
Questions 121

An organization has adopted a bring-your-own-device (BYOD) policy, and employees can access organizational data via their smart devices.

Which of the following authentication policy requirements is the most advisable?

Options:

A.  

Require a virtual private network (VPN).

B.  

Require at least an eight-digit passcode or a complicated swipe pattern.

C.  

Require the remote wipe function and encryption of local data.

D.  

Require a passcode followed by a response requiring verification message.

Discussion 0
Questions 122

A software that translates hypertext markup language (HTML) documents and allows a user to view a remote web page is called:

Options:

A.  

A transmission control protocol/Internet protocol (TCP/IP).

B.  

An operating system.

C.  

A web browser.

D.  

A web server.

Discussion 0
Questions 123

Which of the following is true regarding the use of remote wipe for smart devices?

Options:

A.  

It can restore default settings and lock encrypted data when necessary.

B.  

It enables the erasure and reformatting of secure digital (SD) cards.

C.  

It can delete data backed up to a desktop for complete protection if required.

D.  

It can wipe data that is backed up via cloud computing

Discussion 0
Questions 124

Which of the following security controls would provide the most efficient and effective authentication for customers to access these online shopping account?

Options:

A.  

12-digit password feature.

B.  

Security question feature.

C.  

Voice recognition feature.

D.  

Two-level sign-on feature

Discussion 0
Questions 125

Which of the following actions should an internal auditor take to clean the data obtained for analytics purposes?

Options:

A.  

Deploys data visualization tool.

B.  

Adopt standardized data analysis software.

C.  

Define analytics objectives and establish outcomes.

D.  

Eliminate duplicate records.

Discussion 0
Questions 126

An internal auditor for a pharmaceutical company as planning a cybersecurity audit and conducting a risk assessment. Which of the following would be considered the most significant cyber threat to the organization?

Options:

A.  

Cybercriminals hacking into the organization ' s time and expense system to collect employee personal data.

B.  

Hackers breaching the organization ' s network to access research and development reports

C.  

A denial-of-service attack that prevents access to the organization ' s website.

D.  

A hacker accessing she financial information of the company

Discussion 0
Questions 127

Which of the following is used during all three stages of project management?

Options:

A.  

Earned Value Management (EVM).

B.  

Organizational procedures.

C.  

Performance measurement.

D.  

Project Management Information System (PMIS).

Discussion 0
Questions 128

A rapidly expanding retail organization continues to be tightly controlled by its original small management team. Which of the following is a potential risk in this vertically centralized organization?

Options:

A.  

Lack of coordination among different business units

B.  

Operational decisions are inconsistent with organizational goals

C.  

Suboptimal decision-making

D.  

Duplication of business activities

Discussion 0
Questions 129

An organization outsources its IT function and help desk services. A service-level agreement has been signed and a business continuity plan (BCP) has been developed.

Which of the following should be included in the BCP?

Options:

A.  

The capacity management plans for the critical business applications.

B.  

An intellectual property clause.

C.  

Solutions for recovery of critical business functions.

D.  

A data protection clause.

Discussion 0
Questions 130

An internal audit engagement team found that the risk register of the project under review did not include significant risks identified by the internal audit function. The project manager explained that risk register preparations are facilitated by risk managers and that each project’s risk review follows the same set of questions. Which of the following recommendations will likely add the greatest value to the project management process of the organization?

Options:

A.  

Update the risk register of the project with the newly identified risks

B.  

Train senior management on risk management principles

C.  

Revise the methodology of the project risk identification process

D.  

Reassign the responsibility of risk register completion to risk managers

Discussion 0
Questions 131

A capital investment project will have a higher net present value, everything else being equal, if it has:

Options:

A.  

A higher initial investment level.

B.  

A higher discount rate.

C.  

Cash inflows that are larger in the later years of the life of the project.

D.  

Cash inflows that are larger in the earlier years of the life of the project.

Discussion 0
Questions 132

An organization requires an average of 58 days to convert raw materials into finished products to sell. An additional 42 days is required to collect receivables. If the organization takes an average of 10 days to pay for raw materials, how long is its total cash conversion cycle?

Options:

A.  

26 days.

B.  

90 days.

C.  

100 days.

D.  

110 days.

Discussion 0
Questions 133

An internal auditor discovered that the organization was not in full compliance with a regulatory labeling requirement for one of its products. The responsible manager indicated that the current product labeling has been in use for several years without any problems. If discovered, this regulatory breach could result in significant fines for the organization. What should be the chief audit executive ' s next course of action?

Options:

A.  

Discuss the matter with the CEO and other senior management

B.  

Recommend that disciplinary action be taken against the manager for exposing the company to such risk

C.  

Communicate to the board the current situation, including the risk exposure to the company

D.  

Take on the initiative of implementing corrective actions to mitigate the identified risks

Discussion 0
Questions 134

The process of scenario planning begins with which of the following steps?

Options:

A.  

Determining the trends that will influence key factors in the organization ' s environment.

B.  

Selecting the issue or decision that will impact how the organization conducts future business.

C.  

Selecting leading indicators to alert the organization of future developments.

D.  

Identifying how customers, suppliers, competitors, employees, and other stakeholders will react.

Discussion 0
Questions 135

An internal auditor is assessing the risks related to an organization’s mobile device policy. She notes that the organization allows third parties (vendors and visitors) to use outside smart devices to access its proprietary networks and systems. Which of the following types of smart device risks should the internal auditor be most concerned about?

Options:

A.  

Compliance.

B.  

Privacy.

C.  

Strategic.

D.  

Physical security.

Discussion 0
Questions 136

Which of the following descriptions of the internal control system are indicators that risks are managed effectively?

    Existing controls promote compliance with applicable laws and regulations.

    The control environment is designed to address all identified risks to the organization.

    Key controls for significant risks to the organization remain consistent over time.

    Monitoring systems are in place to alert management to unexpected events.

Options:

A.  

1 and 3.

B.  

1 and 4.

C.  

2 and 3.

D.  

2 and 4.

Discussion 0
Questions 137

Management is designing its disaster recovery plan. In the event that there is significant damage to the organization ' s IT systems this plan should enable the organization to resume operations at a recovery site after some configuration and data restoration. Which of the following is the ideal solution for management in this scenario?

Options:

A.  

A warm recovery plan.

B.  

A cold recovery plan.

C.  

A hot recovery plan.

D.  

A manual work processes plan

Discussion 0
Questions 138

Which of the following would be the best method to collect information about employees ' job satisfaction?

Options:

A.  

Online surveys sent randomly to employees.

B.  

Direct onsite observations of employees.

C.  

Town hall meetings with employees.

D.  

Face-to-face interviews with employees.

Discussion 0
Questions 139

The board of directors wants to implement an incentive program for senior management that is specifically tied to the long-term health of the organization. Which of the following methods of compensation would be best to achieve this goal?

Options:

A.  

Commissions.

B.  

Stock options

C.  

Gain-sharing bonuses.

D.  

Allowances

Discussion 0
Questions 140

Based on lest results, an IT auditor concluded that the organization would suffer unacceptable loss of data if there was a disaster at its data center. Which of the following test results would likely lead the auditor to this conclusion?

Options:

A.  

Requested backup tapes were not returned from the offsite vendor In a timely manner.

B.  

Returned backup tapes from the offsite vendor contained empty spaces.

C.  

Critical systems have boon backed up more frequently than required.

D.  

Critical system backup tapes are taken off site less frequently than required

Discussion 0
Questions 141

What relationship exists between decentralization and the degree, importance, and range of lower-level decision making?

Options:

A.  

Mutually exclusive relationship.

B.  

Direct relationship.

C.  

Intrinsic relationship.

D.  

Inverse relationship.

Discussion 0
Questions 142

An organization has an established bring-your-own-device policy. Due to this policy, which of the following privacy risks would be most relevant to the organization?

Options:

A.  

Employees who consider updates of software or operating systems degrading to the performance of their devices might choose not to install the updates.

B.  

Confidential intellectual property of the organization may be compromised if the smart device is physically lost.

C.  

Concern by employees that the organization could intrusively monitor them through their smart devices.

D.  

Malware may infect smart devices that contain the organization ' s confidential data if the device does not have adequate security restrictions.

Discussion 0
Questions 143

How do data analysis technologies affect internal audit testing?

Options:

A.  

They improve the effectiveness of spot check testing techniques

B.  

They allow greater insight into high-risk areas

C.  

They reduce the overall scope of the audit engagement

D.  

They increase the internal auditor’s objectivity

Discussion 0
Questions 144

Which of the following price adjustment strategies encourages prompt payment?

Options:

A.  

Cash discounts.

B.  

Quantity discounts.

C.  

Functional discounts.

D.  

Seasonal discounts.

Discussion 0
Questions 145

An organization’s income and retained earnings statement is as follows:

Sales: $3,000

Cost of goods sold: $1,600

Gross profit: $1,400

Operating expenses: $970

Operating income: $430

Interest expense: $30

Income before tax: $400

Income tax: $200

Net income: $200

Plus Jan. 1 retained earnings: $150

Less dividends: $60

Dec. 31 retained earnings: $290

Which of the following is the dividend payout ratio?

Options:

A.  

20 percent.

B.  

30 percent.

C.  

40 percent.

D.  

50 percent.

Discussion 0
Questions 146

An organization ' s internal audit activity performed an engagement regarding recent contract bidding. Who should the internal audit activity meet with in order to obtain reliable and relevant information about potential questionable practices related to the contract bidding?

Options:

A.  

Senior management, to obtain an understanding about the justification for contract bidding.

B.  

Personnel responsible for the organization ' s fraud and ethics hotline, to obtain information related to contract bidding.

C.  

Potential vendors, to obtain information about the bid packages related to contract bidding.

D.  

Contracting department personnel to obtain information related to contract bidding practices.

Discussion 0
Questions 147

When management uses the absorption costing approach, fixed manufacturing overhead costs are classified as which of the following types of costs?

Options:

A.  

Direct product costs

B.  

Indirect costs

C.  

Direct period costs

D.  

Indirect period costs

Discussion 0
Questions 148

The head of the research and development department at a manufacturing organization believes that his team lacks expertise in some areas and decides to hire more experienced researchers to assist in the development of a new product. Which of the following variances are likely to occur as the result of this decision?

Favorable labor efficiency variance

Adverse labor rate variance

Adverse labor efficiency variance

Favorable labor rate variance

Options:

A.  

1 and 2.

B.  

1 and 4.

C.  

3 and 4.

D.  

2 and 3.

Discussion 0
Questions 149

An analytical model determined that on Friday and Saturday nights the luxury brands stores should be open for extended hours and with a doubled number of employees

present; while on Mondays and Tuesdays costs can be minimized by reducing the number of employees to a minimum and opening only for evening hours Which of the

following best categorizes the analytical model applied?

Options:

A.  

Descriptive.

B.  

Diagnostic.

C.  

Prescriptive.

D.  

Prolific.

Discussion 0
Questions 150

During the second half of the audit year, the chief audit executive (CAE) identified significant negative variances to the approved audit budget required to complete the internal audit plan. Which of the following actions should the CAE take?

Options:

A.  

Revise the internal audit plan to reduce coverage of new strategic critical areas so that the approved budget can be met

B.  

Reduce the scope of the remainder of the engagements in the internal audit plan to reduce overall costs

C.  

Communicate to senior management and the board the risk of not being able to complete the audit plan

D.  

Continue to complete the plan regardless of the budget variances, as the audit function is invaluable to sound corporate governance

Discussion 0
Questions 151

An organization that relies heavily on IT wants to contain the impact of potential business disruption to a period of approximately four to seven days. Which of the following

business recovery strategies would most efficiently meet this organization ' s needs?

Options:

A.  

A recovery strategy whereby a separate site has not yet been determined, but hardware has been reserved for purchase and data backups.

B.  

A recovery strategy whereby a separate site has been secured and is ready for use, with fully configured hardware and real-time synchronized data

C.  

A recovery strategy whereby a separate site has been secured and the necessary funds for hardware and data backups have been reserved.

D.  

A recovery strategy whereby a separate site has been secured with configurable hardware and data backups.

Discussion 0
Questions 152

An organization produces two products, X and Y. The materials used for the production of both products are limited to 500 kilograms (kg) per month. All other resources are unlimited and their costs are fixed.

Individual product details are as follows:

Product X: Selling price per unit: $10; Materials per unit at $1/kg: 2 kg; Monthly demand: 100 units.

Product Y: Selling price per unit: $13; Materials per unit at $1/kg: 6 kg; Monthly demand: 120 units.

In order to maximize profit, how much of product Y should the organization produce each month?

Options:

A.  

50 units.

B.  

60 units.

C.  

100 units.

D.  

120 units.

Discussion 0
Questions 153

Which of the following network types should an organization choose if it wants to allow access only to its own personnel?

Options:

A.  

An extranet.

B.  

A local area network (LAN).

C.  

An intranet.

D.  

The internet.

Discussion 0
Questions 154

Which of the following management approaches may help eliminate employee dissatisfaction, but would not necessarily motivate workers to high achievement levels?

Options:

A.  

Providing growth opportunities for employees.

B.  

Offering employee recognition incentives in the organization.

C.  

Offering competitive employee compensation packages.

D.  

Assigning more responsibility to successful employees.

Discussion 0
Questions 155

A small furniture-manufacturing firm with 100 employees is located in a two-story building and does not plan to expand. The furniture manufactured is not special-ordered or custom-made. The most likely structure for this organization would be:

Options:

A.  

Functional departmentalization.

B.  

Product departmentalization.

C.  

Matrix organization.

D.  

Divisional organization.

Discussion 0
Questions 156

An organization is considering integration of governance, risk., and compliance (GRC) activities into a centralized technology-based resource. In implementing this GRC

resource, which of the following is a key enterprise governance concern that should be fulfilled by the final product?

Options:

A.  

The board should be fully satisfied that there is an effective system of governance in place through accurate, quality information provided.

B.  

Compliance, audit, and risk management can find and seek efficiencies between their functions through integrated information reporting.

C.  

Key compliance and risk metrics can be tracked and compared throughout the enterprise, aiding in identifying problem departments.

D.  

Data analytics can be utilized for trending of the data to ensure that patterns and ongoing monitoring occurs throughout the organization.

Discussion 0
Questions 157

Which of the following job design techniques would most likely be used to increase employee motivation through job responsibility and recognition?

Options:

A.  

Job complicating

B.  

Job rotation

C.  

Job enrichment

D.  

Job enlargement

Discussion 0
Questions 158

Which of the following is a characteristic of using a hierarchical control structure?

Options:

A.  

Less use of policies and procedures.

B.  

Less organizational commitment by employees.

C.  

Less emphasis on extrinsic rewards.

D.  

Less employee’s turnover.

Discussion 0
Questions 159

Which of the following scenarios would cause a chief audit executive (CAE) to immediately discontinue using any statements that would indicate conformance with the Global Internal Audit Standards in an audit report?

Options:

A.  

The internal audit function used a risk-based approach to create the internal audit plan

B.  

The engagement supervisor considered requests from senior management regarding engagements to include in the internal audit plan

C.  

The CAE only accepted engagements that the internal audit function collectively had the knowledge to perform

D.  

The activity under review restricted the internal audit function ' s ability to access records, impacting the audit results

Discussion 0
Questions 160

Which of the following controls helps protect externally stored sensitive or confidential data from cyberthreats?

Options:

A.  

Secure configurations and access controls.

B.  

Strong vendor contracts with control reports provided by service organizations.

C.  

Active and frequent monitoring of network traffic activities.

D.  

Firewalls to block unauthorized processing of transactions.

Discussion 0
Questions 161

At a manufacturing plant, how would using Internet of Things during the production process benefit the organization?

Options:

A.  

It would provide the ability to monitor in real-time.

B.  

It would assist in securing sensitive data.

C.  

It would help detect cyberattacks in a more timely fashion.

D.  

It would assist in ensuring that data integrity is maintained.

Discussion 0
Questions 162

Which of the following situations best illustrates a " false positive " in the performance of a spam filter?

Options:

A.  

The spam filter removed Incoming communication that included certain keywords and domains.

B.  

The spam filter deleted commercial ads automatically, as they were recognized as unwanted.

C.  

The spam filter routed to the " junk|r folder a newsletter that appeared to include links to fake websites.

D.  

The spam filter blocked a fitness club gift card that coworkers sent to an employee for her birthday.

Discussion 0
Questions 163

Which of the following best describes the primary objective of cybersecurity?

Options:

A.  

To protect the effective performance of IT general and application controls.

B.  

To regulate users ' behavior it the web and cloud environment.

C.  

To prevent unauthorized access to information assets.

D.  

To secure application of protocols and authorization routines.

Discussion 0
Questions 164

The internal audit function conducted an engagement on maintenance operations of a construction organization and identified several issues of medium importance. The head of maintenance proposed an improvement plan with deadlines and personnel responsible. The internal audit function issued the final report to senior management. Senior management was dissatisfied with the report as they believed that improvement plan deadlines should be considerably shorter. Which of the following should the internal audit function change in the reporting process?

Options:

A.  

Discontinue discussing draft reports with responsible employees, as their input is needed during fieldwork only

B.  

Involve senior management at the draft report stage and in the development of action plans

C.  

Request senior management to issue a separate memo regarding their changes to deadlines

D.  

Invite senior management to the board meeting regarding engagement results so that they can express their concerns

Discussion 0
Questions 165

Which of the following physical security controls would most likely be used as a corrective control?

Options:

A.  

Monitored closed circuit televisions.

B.  

Doors that lock automatically.

C.  

Biometric locks.

D.  

Identification badges.

Discussion 0
Questions 166

Which of the following statements is true regarding outsourced business processes?

Options:

A.  

Outsourced business processes should not be considered in the internal audit universe because the controls are owned by the external service provider.

B.  

Generally, independence is improved when the internal audit activity reviews outsourced business processes.

C.  

The key controls of outsourced business processes typically are more difficult to audit because they are designed and managed externally.

D.  

The system of internal controls may be better and more efficient when the business process is outsourced compared to internally sourced.

Discussion 0
Questions 167

At one organization, the specific terms of a contract require both the promisor and promisee to sign the contract in the presence of an independent witness. What is the primary role to the witness to these signatures?

Options:

A.  

A witness verifies the quantities of the copies signed.

B.  

A witness verifies that the contract was signed with the free consent of the promisor and promisee.

C.  

A witness ensures the completeness of the contract between the promisor and promisee.

D.  

A witness validates that the signatures on the contract were signed by the promisor and promisee.

Discussion 0
Questions 168

The project charter is an output from which of the following?

Options:

A.  

Scope planning.

B.  

Scope definition.

C.  

Scope verification.

D.  

Project initiation.

Discussion 0
Questions 169

The chief audit executive (CAE) has been asked to evaluate the chief technology officer ' s proposal to outsource several key functions in the organization ' s IT department. Which of the following would be the most appropriate action for the CAE to determine whether the proposal aligns with the organization ' s strategy?

Options:

A.  

Understand strategic context and evaluate whether supporting information is reliable and complete.

B.  

Ascertain whether governance and approval processes are transparent, documented, and completed.

C.  

Perform a due diligence review or asses management ' s review of provider operations.

D.  

Identify key performance measures and data sources.

Discussion 0
Questions 170

Which of the following data privacy concerns can be attributed specifically to blockchain technologies?

Options:

A.  

Cybercriminals mainly resort to blockchain technologies to phish for private data

B.  

Since blockchain transactions can be easily tampered with, the risk of private data leakage is high

C.  

Data privacy regulations overregulate the usage of private data in blockchain transactions

D.  

Immutability of blockchain technologies makes private data erasure a challenge

Discussion 0
Questions 171

A major IT project is scheduled to be implemented over a three-month period during the year. The chief audit executive (CAE) scheduled significant audit resources to provide consultation. Due to technical challenges from a supplier, the project is postponed until the following year. What should the CAE do in this case?

Options:

A.  

Communicate to the IT project manager that the audit resources are still available to his department for other projects

B.  

Reassign the available audit resources to other areas of risk and advise the respective managers in those areas

C.  

Amend the plan accordingly and advise the board and senior management for their review and approval

D.  

Keep the available resources unassigned so that they are able to take on any ad hoc assignment that may arise

Discussion 0
Questions 172

Which of the following IT-related activities is most commonly performed by the second line of defense?

Options:

A.  

Block unauthorized traffic.

B.  

Encrypt data.

C.  

Review disaster recovery test results.

D.  

Provide an independent assessment of IT security.

Discussion 0
Questions 173

For employees, the primary value of implementing job enrichment is which of the following?

Options:

A.  

Validation of the achievement of their goals anti objectives

B.  

Increased knowledge through the performance of additional tasks

C.  

Support for personal growth and a meaningful work experience

D.  

An increased opportunity to manage better the work done by their subordinates

Discussion 0
Questions 174

Which of the following statements regarding the necessary resources to achieve the internal audit plan is true?

Options:

A.  

Ultimate oversight and responsibility for the internal audit function can be outsourced

B.  

Relying upon the work of other assurance providers decreases the efficiency with which to retain auditors with high knowledge and experience

C.  

Internal audit resources can be obtained entirely from outside the organization

D.  

Co-sourcing, where experts from outside the organization perform specialized work, must be used by chief audit executives instead of outsourcing

Discussion 0
Questions 175

When initiating international ventures, an organization should consider cultural dimensions in order to prevent misunderstandings. Which of the following does not represent a recognized cultural dimension in a work environment?

Options:

A.  

Self-control.

B.  

Power distance.

C.  

Masculinity versus femininity.

D.  

Uncertainty avoidance.

Discussion 0
Questions 176

An organization produces finished lumber for the construction industry.

Which of the following inventory valuation methods will lead to the highest profit, assuming all other variables remain the same in a period of rising material costs?

Options:

A.  

Average-cost method.

B.  

Weighted cost method.

C.  

First-in, first-out (FIFO).

D.  

Specific identification.

Discussion 0
Questions 177

For a multinational organization, which of the following is a disadvantage of an ethnocentric staffing policy?

    It significantly raises compensation and staffing costs.

    It produces resentment among the organization ' s employees in host countries.

    It limits career mobility for parent-country nationals.

    It can lead to cultural myopia.

Options:

A.  

1 and 4 only

B.  

2 and 3 only

C.  

1, 2, and 3 only

D.  

1, 2, and 4 only

Discussion 0
Questions 178

Which of the following statements best describes the concept of Internet of Things?

Options:

A.  

Interconnectivity of physical devices through the internet.

B.  

Delivery of different services through the internet.

C.  

The practice whereby employees and partners use their personal devices for conducting business.

D.  

Computer-to-computer exchange of business documents in electronic form through the internet between an organization and its trading partners.

Discussion 0
Questions 179

Which of the following statements is true regarding cost-volume-profit analysis?

Options:

A.  

Contribution margin is the amount remaining from sales revenue after fixed expenses have been deducted

B.  

Breakeven is the amount of units sold to cover variable costs

C.  

Breakeven occurs when the contribution margin covers fixed costs

D.  

Following breakeven, net operating income will increase by the excess of fixed costs less the variable costs per unit sold

Discussion 0
Questions 180

Which of the following would be most effective in preventing phishing attacks from impacting business systems?

Options:

A.  

Training users on security awareness.

B.  

Monitoring the usage of IT systems.

C.  

Using software to detect malware.

D.  

Blocking access to a user ' s accounts.

Discussion 0
Questions 181

In reviewing an organization ' s IT infrastructure risks, which of the following controls is to be tested as pan of reviewing workstations?

Options:

A.  

Input controls

B.  

Segregation of duties

C.  

Physical controls

D.  

Integrity controls

Discussion 0
Questions 182

Which of the following is an example of two-factor authentication?

Options:

A.  

The user ' s facial geometry and voice recognition.

B.  

The user ' s password and a separate passphrase.

C.  

The user ' s key fob and a smart card.

D.  

The user ' s fingerprint and a personal Identification number.

Discussion 0
Questions 183

Which of the following common quantitative techniques used in capital budgeting is best associated with the use of a table that describes the present value of an annuity?

Options:

A.  

Cash payback technique.

B.  

Discounted cash flow technique: net present value.

C.  

Annual rate of return

D.  

Discounted cash flow technique: internal rate of return.

Discussion 0
Questions 184

A chief audit executive wants to implement an enterprisewide resource planning software. Which of the following internal audit assessments could provide overall assurance on the likelihood of the software implementation ' s success?

Options:

A.  

Readiness assessment.

B.  

Project risk assessment.

C.  

Post-implementation review.

D.  

Key phase review.

Discussion 0
Questions 185

An internal auditor identified a database administrator with an incompatible dual role. Which of the following duties should not be performed by the identified administrator?

Options:

A.  

Designing and maintaining the database.

B.  

Preparing input data and maintaining the database.

C.  

Maintaining the database and providing its security,

D.  

Designing the database and providing its security

Discussion 0
Questions 186

When examining; an organization ' s strategic plan, an internal auditor should expect to find which of the following components?

Options:

A.  

Identification of achievable goals and timelines

B.  

Analysis of the competitive environment.

C.  

Plan for the procurement of resources

D.  

Plan for progress reporting and oversight.

Discussion 0
Questions 187

The first stage in the development of a crisis management program is to:

Options:

A.  

Formulate contingency plans.

B.  

Conduct a risk analysis.

C.  

Create a crisis management team.

D.  

Practice the response to a crisis.

Discussion 0
Questions 188

According to IIA guidance, which of the following would be the best first stop to manage risk when a third party is overseeing the organization ' s network and data?

Options:

A.  

Creating a comprehensive reporting system for vendors to demonstrate their ongoing due diligence in network operations.

B.  

Drafting a strong contract that requires regular vendor control reports end a right-to-audit clause.

C.  

Applying administrative privileges to ensure right to access controls are appropriate.

D.  

Creating a standing cyber-security committee to identify and manage risks related to data security

Discussion 0
Questions 189

A clothing company sells shirts for $8 per shirt. In order to break even, the company must sell 25.000 shirts. Actual sales total S300.000. What is margin of safety sales for the company?

Options:

A.  

$100.000

B.  

$200,000

C.  

$275,000

D.  

$500,000

Discussion 0
Questions 190

An Internal auditor is using data analytics to focus on high-risk areas during an engagement. The auditor has obtained data and is working to eliminate redundancies in the data. Which of the following statements is true regarding this scenario?

Options:

A.  

The auditor is normalizing data in preparation for analyzing it.

B.  

The auditor is analyzing the data in preparation for communicating the results,

C.  

The auditor is cleaning the data in preparation for determining which processes may be involves .

D.  

The auditor is reviewing trio data prior to defining the question

Discussion 0
Questions 191

With regard to project management, which of the following statements about project crashing Is true?

Options:

A.  

It leads to an increase in risk and often results in rework.

B.  

It is an optimization technique where activities are performed in parallel rather than sequentially.

C.  

It involves a revaluation of project requirements and/or scope.

D.  

It is a compression technique in which resources are added so the project.

Discussion 0
Questions 192

Which of the following budgets must be prepared first?

Options:

A.  

Cash budget.

B.  

Production budget.

C.  

Sales budget.

D.  

Selling and administrative expenses budget.

Discussion 0
Questions 193

An organization is planning to outsource its payroll function to an external service provider. The internal auditors advised management of the risks related to outsourcing and the typical controls that should be provided by the external service provider.

Which of the following statements is true regarding the internal auditors’ advice?

Options:

A.  

Independence was compromised by recommending internal controls, as the internal auditors will be testing the same controls in the future.

B.  

Objectivity was compromised by intervening before the outsourcing procedures and controls were established.

C.  

The internal auditors should work directly with the external service provider to ensure basic controls are in place and working as intended.

D.  

The external service provider controls recommended by the internal auditors may be insufficient to protect the organization.

Discussion 0
Questions 194

An organization buys equity securities for trading purposes and sells them within a short time period. Which of the following is the correct way to value and report those securities at a financial statement date?

Options:

A.  

At fair value with changes reported in the shareholders ' equity section.

B.  

At fair value with changes reported in net income.

C.  

At amortized cost in the income statement.

D.  

As current assets in the balance sheet

Discussion 0
Questions 195

Which of the following responsibilities would ordinarily fall under the help desk function of an organization?

Options:

A.  

Maintenance service items such as production support

B.  

Management of infrastructure services, including network management

C.  

Physical hosting of mainframes and distributed servers

D.  

End-to-end security architecture design

Discussion 0
Questions 196

According to internal organizational rules, procurement specialists are responsible for carrying out procurement procedures in accordance with legal acts, but have little knowledge of the equipment and services being procured. Business unit engineers are responsible for preparing the technical descriptions of the desired equipment.

Which of the following controls should be implemented to mitigate potential fraud risks that may occur in the described arrangement?

Options:

A.  

Require technical descriptions to be reviewed by a group of internal experts.

B.  

Require procurement specialists to obtain higher education in a technical field.

C.  

Assign the task of writing technical descriptions to procurement specialists.

D.  

Assign the task of writing technical descriptions to potential bidders.

Discussion 0
Questions 197

Which of the following is an example of a smart device security control intended to prevent unauthorized users from gaining access to a device’s data or applications?

Options:

A.  

Anti-malware software

B.  

Authentication

C.  

Spyware

D.  

Rooting

Discussion 0
Questions 198

Which of the following measures would best protect an organization from automated attacks whereby the attacker attempts to identify weak or leaked passwords in order to log into employees ' accounts?

Options:

A.  

Requiring users to change their passwords every two years.

B.  

Requiring two-step verification for all users

C.  

Requiring the use of a virtual private network (VPN) when employees are out of the office.

D.  

Requiring the use of up-to-date antivirus, security, and event management tools.

Discussion 0
Questions 199

Which of the following best describes a transformational leader, as opposed to a transactional leader?

Options:

A.  

The leader searches for deviations from the rules and standards and intervenes when deviations exist.

B.  

The leader intervenes only when performance standards are not met.

C.  

The leader intervenes to communicate high expectations.

D.  

The leader does not intervene to promote problem-solving

Discussion 0
Questions 200

Which of the following responsibilities would ordinary fall under the help desk function of an organization?

Options:

A.  

Maintenance service items such as production support.

B.  

Management of infrastructure services, including network management.

C.  

Physical hosting of mainframes and distributed servers

D.  

End-to -end security architecture design.

Discussion 0
Questions 201

Internal audit observed an increase in defects of newly installed spare parts. An investigation revealed that vendors delivered spare parts of worse quality than required by contract. Which of the following recommendations would most helpfully mitigate this risk?

Options:

A.  

Add higher level managers to invoice approval process

B.  

Request quality-related confirmations from vendors

C.  

Conduct random inspections and testing of deliveries

D.  

Improve technical specifications of procurement documents

Discussion 0
Questions 202

Which of the following describes the most appropriate set of tests for auditing a workstation ' s logical access controls?

Options:

A.  

Review the list of people with access badges to the room containing the workstation and a log of those who accessed the room.

B.  

Review the password length, frequency of change, and list of users for the workstation ' s login process.

C.  

Review the list of people who attempted to access the workstation and failed, as well as error messages.

D.  

Review the passwords of those who attempted unsuccessfully to access the workstation and the log of their activity

Discussion 0
Questions 203

Which of the following statements pertaining to a market skimming pricing strategy is not true?

Options:

A.  

The strategy is favored when unit costs fall with the increase in units produced.

B.  

The strategy is favored when buyers are relatively insensitive to price increases.

C.  

The strategy is favored when there is insufficient market capacity and competitors cannot increase market capacity.

D.  

The strategy is favored when high price is perceived as high quality.

Discussion 0
Questions 204

Which of the following would be the best indicator that the organization is saving money?

Options:

A.  

No duplicate payments occurred during the past quarter.

B.  

During the past quarter, 95% of invoices were paid by the due date.

C.  

During the past quarter, 85% of invoices eligible for early-pay discounts were paid in time to obtain the discount.

D.  

During the past quarter, 100% of payments made matched the invoiced amounts.

Discussion 0
Questions 205

A large retail customer made an offer to buy 10,000 units at a special price of $7 per unit. The manufacturer usually sells each unit for $10. Variable manufacturing costs are $5 per unit and fixed manufacturing costs are $3 per unit. For the manufacturer to accept the offer, which of the following assumptions needs to be true?

Options:

A.  

Fixed and variable manufacturing costs are less than the special offer selling price

B.  

The manufacturer can fulfill the order without expanding the capacities of the production facilities

C.  

Costs related to accepting this offer can be absorbed through the sale of other products

D.  

The manufacturer’s production facilities are currently operating at full capacity

Discussion 0
Questions 206

Which of the following standards would be most useful in evaluating the performance of a customer-service group?

Options:

A.  

The average time per customer inquiry should be kept to a minimum.

B.  

Customer complaints should be processed promptly.

C.  

Employees should maintain a positive attitude when dealing with customers.

D.  

All customer inquiries should be answered within seven days of receipt.

Discussion 0
Questions 207

Which of the following statements is true regarding user-developed applications (UDAs)?

Options:

A.  

UDAs are less flexible and more difficult to configure than traditional IT applications.

B.  

Updating UDAs may lead to various errors resulting from changes or corrections.

C.  

UDAs typically are subjected to application development and change management controls.

D.  

Using UDAs typically enhances the organization ' s ability to comply with regulatory factors.

Discussion 0
Questions 208

Which of the following are typical audit considerations for a review of authentication?

    Authentication policies and evaluation of controls transactions.

    Management of passwords, independent reconciliation, and audit trail.

    Control self-assessment tools used by management.

    Independent verification of data integrity and accuracy.

Options:

A.  

1, 2, and 3

B.  

1, 2, and 4

C.  

1, 3, and 4

D.  

2, 3, and 4

Discussion 0
Questions 209

An organization plans to upgrade its IT network to address a recent ransomware incident that hampered operations for weeks. The ransomware was the result of lapses in access to the network that exposed sensitive information.

Which of the following is a risk that could significantly be impacted by the organization’s planned change to its IT network?

Options:

A.  

The organization lacks the necessary senior management to ensure that project objectives are met.

B.  

The organization’s recent hiring of additional staff to the IT department would create more scrutiny of end user activity.

C.  

The organization creates new processes and policies that employees feel are too burdensome.

D.  

The organization experiences continuing issues that hamper employees’ ability to provide quality customer service.

Discussion 0
Questions 210

The comparable uncontrolled price (CUP) method may be used when setting transfer prices in an organization.

What is a common limitation of the CUP method?

Options:

A.  

It may be difficult to find a transaction between independent companies that is similar enough to a controlled transaction.

B.  

The CUP method is likely to lead to management decisions that are not optimal for the company.

C.  

This approach to setting transfer prices is not flexible, as the CUP method does not allow for adjustments.

D.  

It offers only an indirect way of ascertaining an arm’s-length price of a controlled transaction.

Discussion 0
Questions 211

An organization with global headquarters in the United States has subsidiaries in eight other nations. If the organization operates with an ethnocentric attitude, which of the following statements is true?

Options:

A.  

Standards used for evaluation and control are determined at local subsidiaries, not set by headquarters

B.  

Orders, commands, and advice are sent to the subsidiaries from headquarters

C.  

People of local nationality are developed for the best positions within their own country

D.  

There is a significant amount of collaboration between headquarters and subsidiaries

Discussion 0
Questions 212

Which of the following statements is true regarding activity-based costing (ABC)?

Options:

A.  

An ABC costing system is similar to conventional costing systems in how it treats the allocation of manufacturing overhead.

B.  

An ABC costing system uses a single unit-level basis to allocate overhead costs to products.

C.  

An ABC costing system may be used with either a job order or a process cost accounting system.

D.  

The primary disadvantage of an ABC costing system is less accurate product costing.

Discussion 0
Questions 213

The IT department maintains logs of user identification and authentication for all requests for access to the network. What is the primary purpose of these logs?

Options:

A.  

To ensure proper segregation of duties

B.  

To create a master repository of user passwords

C.  

To enable monitoring for systems efficiencies

D.  

To enable tracking of privileges granted to users over time

Discussion 0
Questions 214

After auditing the treasury function, the internal audit team issued a final report, which included an action plan agreed with management. When the audit team returned three months later to follow up on the action plan, management indicated that the plan had not been implemented because the old treasury system was being replaced with a new system. Which of the following is the most appropriate audit response?

Options:

A.  

The internal audit team should propose a new, relevant action plan that takes into account the new treasury system

B.  

The internal audit team should disregard the original action plan and follow up next year, after management determines whether the new system poses any new risks

C.  

The internal audit team should report this issue to the chief audit executive, who should communicate management ' s noncompliance directly to the board

D.  

The internal audit team should report this issue to the chief audit executive, who should discuss the issue with senior management

Discussion 0
Questions 215

An organization had a gross profit margin of 40 percent in year one and in year two. The net profit margin was 18 percent in year one and 13 percent in year two. Which of the following could be the reason for the decline in the net profit margin for year two?

Options:

A.  

Cost of sales increased relative to sales.

B.  

Total sales increased relative to expenses.

C.  

The organization had a higher dividend payout rate in year two.

D.  

The government increased the corporate tax rate

Discussion 0
Questions 216

Which of the following are likely indicators of ineffective change management?

    IT management is unable to predict how a change will impact interdependent systems or business processes.

    There have been significant increases in trouble calls or in support hours logged by programmers.

    There is a lack of turnover in the systems support and business analyst development groups.

    Emergency changes that bypass the normal control process frequently are deemed necessary.

Options:

A.  

1 and 3 only

B.  

2 and 4 only

C.  

1, 2, and 4 only

D.  

1, 2, 3, and 4

Discussion 0
Questions 217

An organization decided to outsource its human resources function. As part of its process migration, the organization is implementing controls over sensitive employee data.

What would be the most appropriate directive control in this area?

Options:

A.  

Require a Service Organization Controls (SOC) report from the service provider

B.  

Include a data protection clause in the contract with the service provider.

C.  

Obtain a nondisclosure agreement from each employee at the service provider who will handle sensitive data.

D.  

Encrypt the employees ' data before transmitting it to the service provider

Discussion 0
Questions 218

An internal auditor found that several employees of a vendor were authorized to remotely access the internal assets management system.

Which of the following should the auditor determine next?

Options:

A.  

Whether there is a documented business need for the access.

B.  

Whether access rights granted to vendor employees are read-only.

C.  

Who to inform regarding the need to remove vendor employees’ access rights.

D.  

Who manages vendor employees’ devices used to access the system.

Discussion 0
Questions 219

An organization ' s IT systems can only be accessed using the organization ' s virtual private network. However, organizational emails, videoconferencing, and file-sharing tools are cloud-based and can be accessed using multi-factor authentication via any device. Which of the following risks should the organization acknowledge?

Options:

A.  

The risk that internal data can be leaked via unapproved applications

B.  

The risk that virtual private networks are not secure

C.  

The risk that remote access controls are usually ineffective in cloud solutions

D.  

The risk that employees may read organizational emails outside of business hours

Discussion 0
Questions 220

An organization has an immediate need for servers, but no time to complete capital acquisitions. Which of the following cloud services would assist with this situation?

Options:

A.  

Infrastructure as a Service (laaS).

B.  

Platform as a Service (PaaS).

C.  

Enterprise as a Service (EaaS).

D.  

Software as a Service (SaaS).

Discussion 0
Questions 221

During which phase of the contracting process ere contracts drafted for a proposed business activity?

Options:

A.  

Initiation phase.

B.  

Bidding phase

C.  

Development phase

D.  

Management phase

Discussion 0
Questions 222

How do data analysis technologies affect internal audit testing?

Options:

A.  

They improve the effectiveness of spot check testing techniques.

B.  

They allow greater insight into high risk areas.

C.  

They reduce the overall scope of the audit engagement,

D.  

They increase the internal auditor ' s objectivity.

Discussion 0
Questions 223

An internal auditor was asked to review an equal equity partnership. In one sampled transaction, Partner A transferred equipment into the partnership with a self-declared value of $10,000, and Partner B contributed equipment with a self-declared value of $15,000. The capital accounts of each partner were subsequently credited with $12,500. Which of the following statements is true regarding this transaction?

Options:

A.  

The capital accounts of the partners should be increased by the original cost of the contributed equipment.

B.  

The capital accounts should be increased using a weighted average based on the current percentage of ownership.

C.  

No action is necessary as the capital account of each partner was increased by the correct amount.

D.  

The capital accounts of the partners should be increased by the fair market value of their contribution.

Discussion 0
Questions 224

A motivational technique generally used to overcome monotony and job-related boredom is:

Options:

A.  

Job specification.

B.  

Job objectives.

C.  

Job rotation.

D.  

Job description.

Discussion 0
Questions 225

For which of the following scenarios would the most recent backup of the human resources database be the best source of information to use?

Options:

A.  

An incorrect program fix was implemented just prior to the database backup.

B.  

The organization is preparing to train all employees on the new self-service benefits system.

C.  

There was a data center failure that requires restoring the system at the backup site.

D.  

There is a need to access prior year-end training reports for all employees in the human resources database

Discussion 0
Questions 226

Which of the following purchasing scenarios would gain the greatest benefit from implementing electronic cate interchange?

Options:

A.  

A just-in-time purchasing environment

B.  

A Large volume of custom purchases

C.  

A variable volume sensitive to material cost

D.  

A currently inefficient purchasing process

Discussion 0
Questions 227

An organization and its trading partner rely on a computer-to-computer exchange of digital business documents. Which of the following best describes this scenario?

Options:

A.  

Use of a central processing unit

B.  

Use of a database management system

C.  

Use of a local area network

D.  

Use of electronic data Interchange

Discussion 0
Questions 228

Which of the following is classified as a product cost using the variable costing method?

Direct labor costs.

Insurance on a factory.

Manufacturing supplies.

Packaging and shipping costs.

Options:

A.  

1 and 2

B.  

1 and 3

C.  

2 and 4

D.  

3 and 4

Discussion 0
Questions 229

Which of the following authentication device credentials is the most difficult to revoke when an employee ' s access rights need to be removed?

Options:

A.  

A traditional key lock.

B.  

A biometric device.

C.  

A card-key system.

D.  

A proximity device.

Discussion 0
Questions 230

Which of the following security controls would be appropriate to protect the exchange of information?

Options:

A.  

Firewalls.

B.  

Activity logs.

C.  

Antivirus software.

D.  

File encryption.

Discussion 0
Questions 231

While conducting an audit of the accounts payable department, an internal auditor found that 3% of payments made during the period under review did not agree with the submitted invoices. Which of the following key performance indicators (KPIs) for the department would best assist the auditor in determining the significance of the test results?

Options:

A.  

A KPI that defines the process owner ' s tolerance for performance deviations.

B.  

A KPI that defines the importance of performance levels and disbursement statistics being measured.

C.  

A KPI that defines timeliness with regard to reporting disbursement data errors to authorized personnel.

D.  

A KPI that defines operating ratio objectives of the disbursement process.

Discussion 0
Questions 232

Which of the following situations best applies to an organization that uses a project, rather than a process, to accomplish its business activities?

Options:

A.  

A clothing company designs, makes, and sells a new item

B.  

A commercial construction company is hired to build a warehouse

C.  

A city department sets up a new firefighter training program

D.  

A manufacturing organization acquires component parts from a contracted vendor

Discussion 0
Questions 233

Which of the following best explains why an organization would enter into a capital lease contract?

Options:

A.  

To increase the ability to borrow additional funds from creditors

B.  

To reduce the organization ' s free cash flow from operations

C.  

To Improve the organization ' s free cash flow from operations

D.  

To acquire the asset at the end of the lease period at a price lower than the fair market value

Discussion 0
Questions 234

Which of the following is required in effective IT change management?

Options:

A.  

The sole responsibility for change management is assigned to an experienced and competent IT team

B.  

Change management follows a consistent process and is done in a controlled environment.

C.  

Internal audit participates in the implementation of change management throughout the organisation.

D.  

All changes to systems must be approved by the highest level of authority within an organization.

Discussion 0
Questions 235

Management is pondering the following question:

" How does our organization compete? "

This question pertains to which of the following levels of strategy?

Options:

A.  

Functional-level strategy

B.  

Corporate-level strategy.

C.  

Business-level strategy,

D.  

DepartmentsHevet strategy

Discussion 0
Questions 236

A small chain of grocery stores made a reporting error and understated its ending inventory. What effect would this have on the income statement for the following year?

Options:

A.  

Net income would be understated.

B.  

Net income would not be affected.

C.  

Net income would be overstated.

D.  

Net income would be negative.

Discussion 0