← All Certified Internal Auditor Flashcard Decks

Mixed Deck — All Certified Internal Auditor Topics Flashcards

100 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All Certified Internal Auditor Topics flashcards as text
  1. An auditor is evaluating the effectiveness of an organization's IT risk management process. Which finding would indicate the WEAKEST risk management maturity?

    Answer: IT risks are identified and addressed on an ad hoc basis with no formal process

    An ad hoc approach to IT risk identification and remediation indicates immature risk management with no repeatable process, leading to inconsistent and unreliable risk coverage.

  2. The IIA Standards require that final audit communications include which of the following?

    Answer: The engagement's objectives, scope, and applicable results

    Final communications must include the engagement objectives, scope, and the results, including conclusions, recommendations, and action plans.

  3. In a containerized application environment, which security risk is MOST specific to container technology?

    Answer: Container escape allowing access to the host system

    Container escape vulnerabilities allow malicious processes to break out of the container sandbox and gain access to the underlying host system.

  4. Which of the following BEST describes the purpose of client satisfaction surveys as part of a QAIP?

    Answer: To gather feedback on audit service quality and usefulness from auditees and stakeholders

    Client satisfaction surveys capture stakeholder perceptions of audit quality, relevance, and added value, which are important QAIP effectiveness measures.

  5. During an IT audit, the auditor determines that input validation controls are missing in a financial application. What is the MOST likely consequence?

    Answer: Entry of erroneous or malicious data into the system

    Without input validation, erroneous, incomplete, or malicious data can be entered and processed, potentially corrupting financial records or enabling injection attacks.

  6. Which of the following is a primary limitation of relying solely on historical data for risk assessment?

    Answer: Past events may not reflect future risk exposures accurately

    Historical data reflects past conditions; new technologies, markets, or operating environments can produce novel risks not captured in historical records.

  7. Under the IIA Standards, a quality assurance and improvement program (QAIP) must include:

    Answer: Both internal and external assessments

    A QAIP must include both ongoing internal assessments and periodic external assessments to evaluate the effectiveness of the internal audit activity.

  8. An auditor is testing controls over financial statement close. She finds that journal entries posted after period-end cutoff lack supporting documentation 40% of the time. Management says this is due to time pressure. What is the primary audit concern?

    Answer: Risk of unsupported or fraudulent manual journal entries manipulating reported results

    Unsupported post-close journal entries represent a high risk for earnings manipulation and are a key fraud indicator in financial reporting audits.

  9. Which type of engagement provides independent assessments of conformance with plans, policies, and regulations?

    Answer: Assurance engagement

    Assurance engagements involve objective assessments of evidence to provide independent opinions on governance, risk, and control processes.

  10. An auditor discovers that the results of two different data analysis techniques conflict. The BEST next step is to:

    Answer: Investigate the conflicting results to determine which technique is more appropriate

    Conflicting analytical results must be investigated to understand why the discrepancy exists and to determine which technique is most appropriate for the data.

  11. If an internal auditor lacks the knowledge required to perform an engagement, the Standards require the CAE to:

    Answer: Obtain competent advice and assistance

    Standard 1210 requires that when the internal audit activity lacks the necessary knowledge or skills, the CAE must obtain competent advice and assistance.

  12. When conducting a data analytics procedure, an internal auditor sorts all transactions by amount from highest to lowest and reviews the top 10%. This is an example of which technique?

    Answer: Stratification

    Stratification involves dividing a population into subgroups (e.g., by amount) to focus testing on higher-risk segments.

  13. When performing continuous auditing, what is the PRIMARY advantage over traditional periodic auditing?

    Answer: Near real-time detection of anomalies and control failures

    Continuous auditing enables near real-time monitoring of transactions and controls, allowing auditors to detect and respond to issues as they occur rather than after the fact.

  14. Standard 2600 addresses communicating senior management's acceptance of risk. If the CAE believes the accepted risk level is inappropriate, the CAE must:

    Answer: Escalate the matter to the board

    Standard 2600 requires the CAE to escalate the matter to the board when management accepts a level of residual risk that the CAE believes is inappropriate.

  15. What is the significance of a code of conduct for Certified Internal Auditor professionals?

    Answer: It establishes expected behaviors and ethical standards that protect the public and profession

    This is fundamental to Certified Internal Auditor practice. It establishes expected behaviors and ethical standards that protect the public and profession represents the professional standard for professional standards in the Certified Internal Auditor certification framework.

  16. Velocity of risk refers to:

    Answer: How quickly a risk can impact the organization once triggered

    Risk velocity measures how rapidly an event can manifest and cause harm, which affects the time available for detection and response.

  17. An auditor reviewing a vendor's SOC 2 Type II report is primarily evaluating which aspect of third-party risk?

    Answer: Effectiveness of the vendor's controls over a period of time

    A SOC 2 Type II report provides an independent assessment of whether a service organization's controls operated effectively over a specified review period.

  18. When an audit engagement identifies a potential fraud, the auditor's communication responsibility FIRST involves:

    Answer: Notifying appropriate levels of management and the audit committee per established protocols

    Potential fraud requires immediate notification to appropriate management levels and the audit committee in accordance with the organization's fraud response protocols.

  19. An auditor discovers that an organization consistently records revenue one day before shipment occurs to meet quarterly targets. Under GAAP, this is most likely a violation of which accounting principle?

    Answer: Revenue recognition / matching principle

    Under GAAP/ASC 606, revenue must be recognized when performance obligations are satisfied (delivery), not before shipment is complete.

  20. When internal audit outsources a portion of work to an external service provider, the CAE is responsible for:

    Answer: Maintaining overall accountability for the quality and accuracy of the outsourced work

    The CAE retains full responsibility for the quality and integrity of all internal audit work, including work performed by external service providers.