IIA IIA-CIA-Part3 - Internal Audit Function
According to IIA guidance on IT, which of the following best describes a situation where data backup plans exist to ensure that critical data can be restored at some point in the future, but recovery and restore processes have not been defined?
An organization produces products X and Y. The materials used for the production of both products are limited to 500 Kilograms

(kg ) per month. All other resources are unlimited and their costs are fixed. Individual product details are as follows in order to maximize profit, how much of product Y should the organization produce each month?
$10 $13
2 kg
70 units
6 kg
120 units
Which of the following data security policies is most likely to be the result of a data privacy law?
Which of the following statements is true regarding the capital budgeting procedure known as the discounted payback period?
According to 11A guidance on IT, which of the following spreadsheets is most likely to be considered a high-risk user-developed application?
Which of the following statements is true regarding user developed applications (UDAs) and traditional IT applications?
An organization has an agreement with a third-party vendor to have a fully operational facility, duplicate of the original site and configured to the organization's needs, in order to quickly recover operational capability in the event of a disaster, Which of the following best describes this approach to disaster recovery planning?
Which of the following actions should an internal auditor take to clean the data obtained for analytics purposes?
Which of the following scenarios best illustrates a spear phishing attack?
When determining the level of physical controls required for a workstation, which of the following factors should be considered?
Which of these instances accurately describes the responsibilities for big data governance?
The chief audit executive (CAE) and management of the area under review disagree over managing a significant risk item. According to IIA guidance, which of the following actions should the CAE take first?
Based on lest results, an IT auditor concluded that the organization would suffer unacceptable loss of data if there was a disaster at its data center. Which of the following test results would likely lead the auditor to this conclusion?
Which of the following disaster recovery plans includes recovery resources available at the site, but they may need to be configured to support the production system?
Which of the following organization structures would most likely be able to cope with rapid changes and uncertainties?
