Certified Internal Auditor Certified Internal Auditor MCQ 4 — Questions and Answers
Question 1: According to the IIA Standards, which of the following is the primary responsibility of the board regarding the internal audit activity?
- Approving individual audit engagement plans and selecting sampling methods
- Overseeing the internal audit activity, including approving the internal audit charter (Correct answer)
- Reviewing and signing off on every audit report before distribution
- Directly supervising the daily work of internal auditors
Correct answer: Overseeing the internal audit activity, including approving the internal audit charter
The board is responsible for oversight of the internal audit activity, which includes approving the audit charter and ensuring its independence.
Question 2: An internal auditor is asked to consult on the design of a new internal control for a high-risk process. After the consulting engagement, what must the auditor do to preserve objectivity for future assurance work on this area?
- Refuse all future assignments in the area permanently
- Disclose the consulting role and the potential impairment of objectivity to the CAE (Correct answer)
- Conduct the future assurance engagement without disclosure since it was consulting, not audit
- Require management to certify that the control was their own design
Correct answer: Disclose the consulting role and the potential impairment of objectivity to the CAE
Auditors who consulted on a control design must disclose the potential objectivity impairment to the CAE before conducting assurance work on that area.
Question 3: Which of the following audit evidence is generally considered most reliable?
- Oral representations from management
- Internal documents created by the auditee
- External confirmations obtained directly by the auditor (Correct answer)
- Copies of documents provided by process owners
Correct answer: External confirmations obtained directly by the auditor
External confirmations obtained directly by the auditor are most reliable because they are independent of the auditee.
Question 4: A CIA candidate is reviewing IT general controls (ITGCs). Which of the following is an example of an ITGC?
- Three-way matching of purchase orders, receiving reports, and vendor invoices
- Automated calculation of depreciation in the ERP system
- User access management and periodic access recertification (Correct answer)
- Segregation of duties in the cash receipts process
Correct answer: User access management and periodic access recertification
User access management and recertification are IT general controls that provide a foundation for the reliability of all application controls.
Question 5: During a fraud investigation, the internal auditor discovers evidence of possible criminal activity. What is the auditor's most appropriate immediate action?
- Confront the suspected employee directly to obtain a confession
- Continue the investigation independently until all evidence is gathered
- Notify appropriate authorities within the organization and consider involving legal counsel (Correct answer)
- Discard incomplete evidence and restart the investigation formally
Correct answer: Notify appropriate authorities within the organization and consider involving legal counsel
Upon discovering potential criminal activity, the auditor should notify appropriate management and legal counsel rather than acting unilaterally.
Question 6: Which of the following best distinguishes a 'preventive' control from a 'detective' control?
- Preventive controls are automated; detective controls are always manual
- Preventive controls stop errors or fraud before they occur; detective controls identify them after the fact (Correct answer)
- Preventive controls are applied at month-end; detective controls operate continuously
- Preventive controls are managed by IT; detective controls are managed by finance
Correct answer: Preventive controls stop errors or fraud before they occur; detective controls identify them after the fact
Preventive controls act before an event to stop errors or fraud, while detective controls identify problems after they have occurred.
Question 7: An internal auditor is performing a governance audit. Which of the following activities falls within the scope of governance evaluation?
- Verifying the mathematical accuracy of the general ledger
- Evaluating whether the board effectively oversees organizational strategy and ethical culture (Correct answer)
- Testing whether automated application controls function as programmed
- Assessing the adequacy of physical security at warehouse locations
Correct answer: Evaluating whether the board effectively oversees organizational strategy and ethical culture
Governance audits evaluate the structures and processes by which the board provides oversight of strategy, risk, and ethical culture.
According to the IIA Standards, which of the following is the primary responsibility of the board regarding the internal audit activity?