
Free IIA (IIA-CIA-Part2) Certification Sample Questions with Online Practice Test
IIA-CIA-Part2 Certification Study Guide Pass IIA-CIA-Part2 Fast
NEW QUESTION # 72
The board has asked the internal audit activity (IAA) to be involved in the organization's enterprise risk management process. Which of the following activities is appropriate for IAA to perform without safeguards?
- A. Develop risk management strategies for board approval.
- B. Coach management in responding to risks.
- C. Facilitate identification and evaluation of risks.
- D. Evaluate risk management processes.
Answer: D
Explanation:
Section: Volume E
NEW QUESTION # 73
When constructing a staffing schedule for the internal audit activity (IAA), which of the following criteria are most important for the chief audit executive to consider for the effective use of audit resources?
1. The competency and qualifications of the audit staff for specific assignments.
2. The effectiveness of IAA staff performance measures.
3. The number of training hours received by staff auditors compared to the budget.
4. The geographical dispersion of audit staff across the organization.
- A. 1 and 3
- B. 2 and 3
- C. 1 and 4
- D. 2 and 4
Answer: C
Explanation:
Section: Volume E
NEW QUESTION # 74
According to IIA guidance, which of the following would be considered necessary for a one-person audit function?
- A. A memorandum stating policies and procedures
- B. A formalized technical audit manual
- C. A written administrative audit manual
- D. A comprehensive policy and procedure manual
Answer: A
Explanation:
For a one-person audit function, the primary focus is on ensuring that there is a clear understanding of the audit policies and procedures without the need for extensive documentation. According to the IIA's guidance, a memorandum stating the policies and procedures would suffice for a one-person audit function, providing a concise yet comprehensive outline of the necessary protocols to follow. This approach ensures that the sole auditor has clear directives while avoiding the administrative burden of maintaining a more extensive manual that might be necessary for larger audit teams.
Reference:
The Institute of Internal Auditors (IIA) - Practice Advisory 2040-1: Policies and Procedures
NEW QUESTION # 75
Which of the following would be an appropriate and effective control self-assessment approach in an organization with an authoritative culture?
I. Facilitated meeting
II. Survey
III. Management-produced analysis
- A. II and III only
- B. I, II, and III
- C. I and III only
- D. I only
Answer: A
NEW QUESTION # 76
Which of the following tasks would be considered unusual for planning a control self-assessment workshop?
- A. Identifying key stakeholders and ensuring they are represented in the group.
- B. Securing an external subject matter expert to arbitrate disputes.
- C. Conducting interviews to identify relevant issues for the discussion.
- D. Ensuring that managers are willing to accept constructive criticism.
Answer: B
NEW QUESTION # 77
The chief audit executive (CAE) determined that based on management's oral response, the action taken regarding an audit observation was sufficient when weighted against the relative importance of the audit recommendation. Which of the following is the most appropriate step for the internal auditor to take next?
- A. Note in the permanent file that follow-up needs to be performed as part of the next engagement.
- B. Escalate the issue to the board and get their position on the issue.
- C. Initiate a follow-up audit to ensure that action has really been taken.
- D. Follow-up with management until a written response is obtained.
Answer: A
NEW QUESTION # 78
An IT auditor is reviewing the access controls in an organization's accounting application. The auditor intends to deploy a tool that can help test the logical controls embedded in the system to ensure employee access is granted according to need. Which of the following would help achieve this objective?
- A. Audit expert systems.
- B. integrated test facility
- C. Utility software
- D. Generalized audit software
Answer: D
Explanation:
Generalized audit software (GAS) is designed to assist auditors in performing data analysis and testing the logical controls embedded within information systems. This type of software can help an IT auditor review access controls by analyzing user permissions, access logs, and other relevant data to ensure that access is granted according to the principle of least privilege and organizational policies. GAS tools are versatile and can handle large volumes of data, making them suitable for testing logical controls in an accounting application.
Reference:
The Institute of Internal Auditors (IIA) - Global Technology Audit Guide (GTAG) 1: Information Technology Controls
NEW QUESTION # 79
Which of the following is a red flag associated with fictitious revenues?
- A. Significant transactions with related parties.
- B. Unusual decrease in the number of days' sales in receivables.
- C. Substantial increase in receivables turnover.
- D. Slow growth or unusually low profitability.
Answer: A
NEW QUESTION # 80
During an assurance engagement, an internal auditor discovered that a sales manager approved numerous sales contracts for values exceeding his authorization limit. The auditor reported the finding to the audit supervisor, noting that the sales manager had additional new contracts under negotiation. According to IIA guidance, which of the following would be the most appropriate next step?
- A. The audit supervisor should include the new contracts in the finding for the final audit report.
- B. The auditor should not reference the new contracts, because they are not yet signed and therefore cannot be included in the final report.
- C. The audit supervisor should remind the sales manager of his authority limit for the contracts under negotiation.
- D. The audit supervisor should communicate the finding to the supervisor of the sales manager through an interim report.
Answer: D
NEW QUESTION # 81
Which of the following best defines an audit opinion?
- A. A summary of the significant audit observations and recommendations.
- B. An auditor's evaluation of the effects of the observations and recommendations on the activities reviewed.
- C. A recommendation for corrective action.
- D. A conclusion which must be included in the audit report.
Answer: B
NEW QUESTION # 82
A key to effective benchmarking in a consulting engagement is identifying the issues that can be:
- A. Shared with all internal audit customers.
- B. Reviewed by all internal audit staff members.
- C. Discussed with the board or audit committee.
- D. Measured and controlled by the engagement client.
Answer: D
Explanation:
Section: Volume B
NEW QUESTION # 83
A bakery chain has a statistical model that can be used to predict daily sales at individual stores based on a direct relationship to the cost of ingredients used and an inverse relationship to rainy days. What conditions would an auditor look for as an indicator of employee theft of food from a specific store?
- A. Both total sales and cost of ingredients used are greater than expected.
- B. On a rainy day, total sales are greater than expected when compared to the cost of ingredients used.
- C. Both total sales and cost of ingredients used are less than expected.
- D. On a sunny day, total sales are less than expected when compared to the cost of ingredients used.
Answer: B
Explanation:
In the scenario provided, the bakery chain's statistical model predicts that daily sales should have an inverse relationship with rainy days, meaning that on rainy days, sales are generally expected to be lower. However, if an auditor notices that on a rainy day, total sales are greater than expected when compared to the cost of ingredients used, this could indicate potential employee theft of food. The reasoning is that if sales are unusually high despite weather conditions that typically depress sales, it may be that the reported sales are inflated or that ingredients are being used without corresponding sales being recorded, which could suggest theft.
IIA Reference:
IIA Standard 1220: Due Professional Care implies that auditors should consider the likelihood of significant errors, fraud, or noncompliance when assessing risks and performing audit procedures. Unusual patterns or deviations from expected results, as seen in this scenario, should raise red flags for potential fraudulent activity, such as theft.
NEW QUESTION # 84
The chief audit executive (CAE) should determine whether the internal audit activity has confirmed the status of all of management's corrective actions Doing so would help the CAE assess which of the following?
- A. Residual risk
- B. Compliance risk
- C. Disclosure risk.
- D. Inherent risk
Answer: A
Explanation:
When the CAE determines whether the internal audit activity has confirmed the status of all management's corrective actions, it helps in assessing residual risk. Residual risk is the risk that remains after management's actions to mitigate inherent risk. By confirming the status of corrective actions, the CAE can evaluate whether the risks identified during the audit have been adequately addressed and what level of risk still exists, ensuring that the internal control environment is effective and that management's risk responses are appropriate.
Reference: COSO's Enterprise Risk Management Framework and The IIA's International Standards for the Professional Practice of Internal Auditing.
NEW QUESTION # 85
An organization's internal audit plan includes a recurring assurance review of the human resources (HR) department. Which of the following statements is true regarding preliminary communication between the auditor in charge (AIC) and the HR department?
1. The AIC should notify HR management when the draft audit plan is being developed, as a courtesy.
2. The AIC should notify HR management before the planning stage begins.
3. The AIC should schedule formal status meetings with HR management at the start of the engagement.
4. The AIC should finalize the scope of the engagement before communicating with HR management.
- A. 1 and 3
- B. 2 and 3
- C. 2 and 4
- D. 1 and 4
Answer: B
Explanation:
Preliminary communication with HR management is essential to ensure a smooth audit process. According to IIA guidance, the auditor in charge (AIC) should notify HR management before the planning stage begins to facilitate cooperation and alignment. Additionally, scheduling formal status meetings at the start of the engagement helps in setting expectations, clarifying the scope, and ensuring ongoing communication throughout the audit process. These steps foster transparency and collaboration. Reference:
IIA Standards - 2200: Engagement Planning
IIA Practice Advisory - 2200-1: Engagement Planning
NEW QUESTION # 86
If an auditor expects to find numerous discrepancies between recorded values and audited values of sample selections, which sampling technique would be most appropriate?
- A. Difference estimation sampling.
- B. Probability-proportional-to-size sampling.
- C. Attributes sampling.
- D. Discovery sampling.
Answer: A
NEW QUESTION # 87
An internal auditor using the five-attribute approach to document deficiencies in a warehouse shipping process. Which of the following attributes will be included in the workpapers?
- A. Condition, cause, effect, recommendation
- B. Condition, cause effect test result
- C. Risk, impact test result recommendation
- D. Risk, impact likelihood existing control, recommendation
Answer: A
Explanation:
The five-attribute approach to documenting deficiencies typically includes the following attributes: condition (the current state or issue identified), cause (the reason for the condition), effect (the impact or potential impact of the condition), and recommendation (suggested actions to address the deficiency). These attributes provide a comprehensive framework for understanding the deficiency, its implications, and the steps needed to rectify it, ensuring clear and actionable audit findings.
Reference:
The Institute of Internal Auditors (IIA) - Practice Guide: Documenting Information
NEW QUESTION # 88
Which of the following would not be characteristic of control self-assessment implemented by an audit department?
- A. Participants discuss the control weaknesses that hinder the achievement of objectives.
- B. Auditors and business-unit employees work as a team.
- C. An auditor usually facilitates the discussion during the workshop phase while another records comments for subsequent use.
- D. Auditors perform traditional audit tests to identify control weaknesses.
Answer: D
Explanation:
Section: Volume B
Explanation
NEW QUESTION # 89
......
IIA-CIA-Part2 exam is designed to assess candidates' knowledge of internal audit practices, procedures, and techniques. It covers a wide range of topics, including risk management, internal control, governance, and fraud detection. IIA-CIA-Part2 exam consists of 100 multiple-choice questions and must be completed within two and a half hours. Candidates must achieve a minimum score of 600 (out of a possible 800) to pass the exam and earn their CIA designation.
Get Perfect Results with Premium IIA-CIA-Part2 Dumps Updated 465 Questions: https://www.actual4exams.com/IIA-CIA-Part2-valid-dump.html
IIA-CIA-Part2 Dumps PDF 2024 Program Your Preparation EXAM SUCCESS: https://drive.google.com/open?id=1rvpEn5DyyHgNdXaJzBMe5ks_ZAG07xn-