Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

IIA IIA-CIA-Part3 - Business Knowledge for Internal Auditing

Page: 9 / 11
Total 516 questions

Which of the following actions is likely to reduce the risk of violating transfer pricing regulations?

A.

The organization sells inventory to an overseas subsidiary at fair value.

B.

The local subsidiary purchases inventory at a discounted price.

C.

The organization sells inventory to an overseas subsidiary at the original cost.

D.

The local subsidiary purchases inventory at the depreciated cost.A

When determining the level of physical controls required for a workstation, which of the following factors should be considered?

A.

Ease of use.

B.

Value to the business.

C.

Intrusion prevention.

D.

Ergonomic model.

An organization decided to reorganize into a flatter structure. Which of the following changes would be expected with this new structure?

A.

Lower costs.

B.

Slower decision making at the senior executive level.

C.

Limited creative freedom in lower-level managers.

D.

Senior-level executives more focused on short-term, routine decision making

An organization has a declining inventory turnover but an increasing gross margin rate. Which of the following statements can best explain this situation?

A.

he organization's operating expenses are increasing.

B.

The organization has adopted just-in-time inventory.

C.

The organization is experiencing inventory theft.

D.

The organization's inventory is overstated.

A chief audit executive (CAE) is developing a strategic plan for the internal audit function. In the last two years, the organization has faced significant IT risks, but the internal audit function has not been able to audit those areas due to a lack of knowledge. How could the CAE address this in the strategic plan?

A.

Purchase a data analytics program for the internal audit function

B.

Hold listening sessions to receive management's input on the strategic plan

C.

Develop a succession plan for the internal audit function to avoid staffing deficiencies

D.

Identify relevant training resources to strengthen staff skillsets

When would a contract be dosed out?

A.

When there's a dispute between the contracting parties

B.

When ail contractual obligations have been discharged.

C.

When there is a force majenre.

D.

When the termination clause is enacted.

Which of the following measures the operating success of a company for a given period of time?

A.

Liquidity ratios.

B.

Profitability ratios.

C.

Solvency ratios.

D.

Current ratios.

Which of the following would be most likely found in an internal audit procedures manual?

A.

A summary of the strategic plan of the area under review

B.

Appropriate response options for when findings are disputed by management

C.

An explanation of the resources needed for each engagement

D.

The extent of the auditor's authority to collect data from management

Which of the following practices circumvents administrative restrictions on smart devices, thereby increasing data security risks?

A.

Rooting.

B.

Eavesdropping.

C.

Man in the middle.

D.

Session hijacking.

Which of the following disaster recovery plans includes recovery resources available at the site, but they may need to be configured to support the production system?

A.

Warm site recovery plan.

B.

Hot site recovery plan.

C.

Cool site recovery plan.

D.

Cold site recovery plan.

Which of the following functions of a quality assurance and improvement program (QAIP) must be performed by personnel independent of the internal audit function?

A.

External assessments

B.

Communication of QAIP results to the board

C.

Disclosure of nonconformance

D.

Internal assessments

After auditing the treasury function, the internal audit team issued a final report, which included an action plan agreed with management. When the audit team returned three months later to follow up on the action plan, management indicated that the plan had not been implemented because the old treasury system was being replaced with a new system. Which of the following is the most appropriate audit response?

A.

The internal audit team should propose a new, relevant action plan that takes into account the new treasury system

B.

The internal audit team should disregard the original action plan and follow up next year, after management determines whether the new system poses any new risks

C.

The internal audit team should report this issue to the chief audit executive, who should communicate management's noncompliance directly to the board

D.

The internal audit team should report this issue to the chief audit executive, who should discuss the issue with senior management

Which of the following actions should an internal auditor take to clean the data obtained for analytics purposes?

A.

Deploys data visualization tool.

B.

Adopt standardized data analysis software.

C.

Define analytics objectives and establish outcomes.

D.

Eliminate duplicate records.

Which of the following scenarios best illustrates a spear phishing attack?

A.

Numerous and consistent attacks on the company's website caused the server to crash and service was disrupted.

B.

A person posing as a representative of the company's IT help desk called several employees and played a generic prerecorded message requesting password data.

C.

A person received a personalized email regarding a golf membership renewal, and he clicked a hyperlink to enter his credit card data into a fake website.

D.

Many users of a social network service received fake notifications of a unique opportunity to invest in a new product

Which of the following is an effective preventive control for data center security?

A.

Motion detectors.

B.

Key card access to the facility.

C.

Security cameras.

D.

Monitoring access to data center workstations