IIA IIA-CIA-Part2 - Internal Audit Engagement
An internal auditor wants to determine whether employees are complying with the information security policy, which prohibits leaving sensitive information on employee desks overnight. The auditor checked a sample of 90 desks and found eight that contained sensitive information. How should this observation be reported, if the organization tolerates 4 percent noncompliance?
If there is a significant error or omission in the final audit report that was communicated to management, which of the following is the key action for the internal audit activity?
An internal auditor determines that certain information from the engagement results is not appropriate for disclosure to all report recipients because it is privileged. In this situation, which of the following actions would be most appropriate?
Which of the following actions should the chief audit executive take when senior management decides to accept risks by choosing to do business with a questionable vendor?
Following an audit, management developed an action plan to improve controls over the handling of scrap metal. Which of the following would be the most appropriate course of action for the auditor to follow up?
An internal auditor is using computer-assisted audit techniques to examine employee expenses across several divisions of the organization. Which of the following is true in this situation?
Which of the following engagement supervision activities should be performed first?
Which of the following is true of matrix organizations?
The engagement supervisor would like lo change the audit program's scope poor to beginning fieldwork According to IIA guidance before any change is implemented what is the most important action that should be undertaken?
As a result of server managements assumption of risk there is residual risk that exceeds me organisation's risk appetite. Which of the following actions would be most appropriate for the chief audit executive to take?
According to IIA guidance, which of the following statements is true regarding reporting the results of the quality assurance and improvement program?
Which of the following represents a ratio that measures short term debt-paying ability?
Operational management In the IT department has developed key performance indicator reports, which are reviewed in detail during monthly staff meetings. This activity is designed to prevent which of the following conditions?
An internal audit activity is planning its first audit of IT shared services. Which of the following controls would typically be evaluated first?
Which of the following actions would an internal auditor perform primarily during a consulting engagement of a debt collections process?
