Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the IIA CIA IIA-CIA-Part3 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam IIA-CIA-Part3 Premium Access

View all detail and faqs for the IIA-CIA-Part3 exam


782 Students Passed

94% Average Score

90% Same Questions
Viewing page 4 out of 16 pages
Viewing questions 46-60 out of questions
Questions # 46:

An organization is considering outsourcing its IT services, and the internal auditor as assessing the related risks. The auditor grouped the related risks into three categories;

- Risks specific to the organization itself.

- Risks specific to the service provider.

- Risks shared by both the organization and the service provider

Which of the following risks should the auditor classify as specific to the service provider?

Options:

A.

Unexpected increases in outsourcing costs.

B.

Loss of data privacy.

C.

Inadequate staffing.

D.

Violation of contractual terms.

Questions # 47:

An internal auditor uses a risk and control questionnaire as part of the preliminary survey for an audit of the organization's anti-bribery and corruption program. What is the primary purpose of using this approach?

Options:

A.

To compare records from one source to subsequently prepared records about the anti-bribery program

B.

To ascertain the existence of certain controls in the organization's anti-bribery program

C.

To obtain testimonial information about certain controls in the organization's anti-bribery program

D.

To validate control information through outside parties independent of the anti-bribery program

Questions # 48:

Which of the following would be most likely found in an internal audit procedures manual?

Options:

A.

A summary of the strategic plan of the area under review

B.

Appropriate response options for when findings are disputed by management

C.

An explanation of the resources needed for each engagement

D.

The extent of the auditor's authority to collect data from management

Questions # 49:

An organization that relies heavily on IT wants to contain the impact of potential business disruption to a period of approximately four to seven days. Which of the following

business recovery strategies would most efficiently meet this organization's needs?

Options:

A.

A recovery strategy whereby a separate site has not yet been determined, but hardware has been reserved for purchase and data backups.

B.

A recovery strategy whereby a separate site has been secured and is ready for use, with fully configured hardware and real-time synchronized data

C.

A recovery strategy whereby a separate site has been secured and the necessary funds for hardware and data backups have been reserved.

D.

A recovery strategy whereby a separate site has been secured with configurable hardware and data backups.

Questions # 50:

Which of the following best describes a detective control designed to protect an organization from cyberthreats and attacks?

Options:

A.

A list of trustworthy, good traffic and a list of unauthorized, blocked traffic.

B.

Monitoring for vulnerabilities based on industry intelligence.

C.

Comprehensive service level agreements with vendors.

D.

Firewall and other network perimeter protection tools.

Questions # 51:

An organization created a formalized plan for a large project. Which of the following should be the first step in the project management plan?

Options:

A.

Estimate time required to complete the whole project.

B.

Determine the responses to expected project risks.

C.

Break the project into manageable components.

D.

Identify resources needed to complete the project

Questions # 52:

Which approach should a chief audit executive take when preparing the internal audit plan?

Options:

A.

Organize the auditable units within the organization into an audit universe to facilitate risk assessment

B.

Select auditable units within the organization based on monetary values

C.

Evaluate auditable units based on senior management's information about risks

D.

Eliminate auditable units not mandated to be audited by laws and regulations applicable to the organization

Questions # 53:

Which of the following lists best describes the classification of manufacturing costs?

Options:

A.

Direct materials, indirect materials, raw materials.

B.

Overhead costs, direct labor, direct materials.

C.

Direct materials, direct labor, depreciation on factory buildings.

D.

Raw materials, factory employees' wages, production selling expenses.

Questions # 54:

An internal auditor has finalized an engagement of the vendor master file. The results of the current engagement do not differ significantly from that of last year, in which several significant weaknesses in internal controls were reported. The internal auditor states in the final communication that the internal controls are as effective as that of the previous year. Which of the following elements of quality of communication could be improved?

Options:

A.

Conciseness

B.

Constructiveness

C.

Objectivity

D.

Accuracy

Questions # 55:

An internal audit function did not conform with the Global Internal Audit Standards in only one of many engagements, as the engagement was performed with a lack of adequate knowledge of the subject matter. Which of the following is appropriate in relation to declaring conformance with the Standards?

Options:

A.

The internal audit function can still declare conformance with the Standards for all engagements

B.

The internal audit function can still declare conformance with the Standards for all other engagements that satisfy the requirements

C.

The internal audit function can declare partial conformance with the Standards for all engagements

D.

The internal audit function needs to evaluate the impact of the nonconformance before it can declare nonconformance with the Standards

Questions # 56:

Which of the following statements depicts a valid role of the internal audit function in ensuring the effectiveness of management action plans?

Options:

A.

Internal audit should not be involved in the design, implementation, or monitoring of management action plans in order to maintain independence and objectivity

B.

Internal audit supports the board in the design, implementation, and monitoring of effective management action plans

C.

Internal audit collaborates with management to evaluate whether the management action plans remediate audit observations effectively

D.

Internal audit designs the action plans and ensures that management implements them effectively

Questions # 57:

Which of the following practices circumvents administrative restrictions on smart devices, thereby increasing data security risks?

Options:

A.

Rooting.

B.

Eavesdropping.

C.

Man in the middle.

D.

Session hijacking.

Questions # 58:

Which of the following key performance indicators would serve as the best measurement of internal audit innovation?

Options:

A.

The number of scheduled and completed audits and percentage of substantial recommendations

B.

The board’s satisfaction index and internal audit staff commitment ratings

C.

Internal audit staff’s application of technology in audit fieldwork and participation in professional organizations and publications

D.

Internal audit staff’s compliance with the audit manual and technical knowledge in auditing, information security, and cloud computing issues

Questions # 59:

An internal audit uncovered high-risk issues that needed to be addressed by the organization. During the exit conference, the audit team discussed the high-risk issues with the manager responsible for addressing them. How should the chief audit executive respond if the manager agrees to correct the issues identified during the audit?

Options:

A.

Include in the report that management has agreed to address the issue and set a date for follow-up

B.

Include an assignment in the annual internal audit plan to perform a follow-up audit

C.

Discuss the audit observation with senior management

D.

Solicit input from management and create the action plan

Questions # 60:

In an organization with a poor control environment, which of the following indicators would help an internal audit function measure its ability to provide risk-based assurance?

Options:

A.

The value of potential cost savings, or prevented losses, identified per year

B.

The percentage of observations that can be linked to significant organizational risks

C.

The extent of data mining or data analytics used during assurance engagements

D.

The amount of time dedicated to organization-wide risk assessments

Viewing page 4 out of 16 pages
Viewing questions 46-60 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.