← All CIA Flashcard Decks

Mixed Deck — All CIA Topics Flashcards

100 cards from real CIA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CIA Topics flashcards as text
  1. What research standard applies to regulatory compliance?

    Answer: Thorough research using primary legal authorities and current precedent

    Legal professionals must conduct thorough research using primary authorities and current precedent to provide competent representation.

  2. What fiduciary duty applies to estate planning?

    Answer: Act in the client's best interest with loyalty, care, and full disclosure

    Fiduciary duty requires acting in the client's best interest with loyalty, care, and full disclosure of all material facts.

  3. How should risk be assessed in risk assessment?

    Answer: Evaluate risk tolerance, capacity, time horizon, and investment objectives systematically

    Comprehensive risk assessment considers tolerance, capacity, time horizon, and objectives to create appropriate strategies.

  4. What fiduciary duty applies to tax strategies?

    Answer: Act in the client's best interest with loyalty, care, and full disclosure

    Fiduciary duty requires acting in the client's best interest with loyalty, care, and full disclosure of all material facts.

  5. Data analytics can help detect payroll fraud by flagging which of the following anomalies?

    Answer: Employees with direct deposit to the same bank account as a payroll administrator

    Shared bank account numbers between employees and payroll administrators is a major red flag indicating ghost employee or paycheck diversion fraud.

  6. How does due diligence apply to regulatory compliance?

    Answer: Thorough investigation and verification of all relevant facts and circumstances

    Due diligence requires thorough investigation and verification of all relevant facts to ensure competent and ethical practice.

  7. Which internal control involves separating duties to reduce errors and fraud?

    Answer: Segregation of Duties

    Segregation of duties is a fundamental internal control principle that involves dividing responsibilities for related activities among different people. By separating the functions of authorization, record-keeping, and asset custody, it significantly reduces the opportunity for any single individual to commit and conceal errors or fraud. This enhances the reliability of financial reporting and protects organizational assets.

  8. The Association of Certified Fraud Examiners (ACFE) Report to the Nations identifies which category as causing the greatest median loss per case?

    Answer: Financial statement fraud

    Financial statement fraud, while less frequent than other schemes, causes the greatest median loss per case according to ACFE data.

  9. A company's code of conduct is primarily a governance tool that serves to:

    Answer: Communicate expected ethical standards and behavioral guidelines to all employees

    A code of conduct is a governance document that communicates the organization's ethical standards and expected behavior, helping establish the ethical culture throughout the organization.

  10. A 'lapping' scheme in accounts receivable involves:

    Answer: Stealing customer payments and covering the shortage with later receipts

    Lapping is a fraud where an employee steals cash receipts and conceals the theft by applying subsequent payments to earlier accounts.

  11. According to the fraud triangle, which of the following is NOT one of the three elements that contribute to fraudulent behavior?

    Answer: Greed

    The fraud triangle consists of pressure, rationalization, and opportunity — greed is not a recognized element of the model.

  12. Which financial statement manipulation technique involves recording revenue before it is earned?

    Answer: Channel stuffing and premature revenue recognition

    Channel stuffing involves pressuring distributors to accept excess inventory to record revenue prematurely before it is truly earned.

  13. In a well-designed corporate governance structure, which of the following relationships best reflects sound practice?

    Answer: The audit committee provides independent oversight of both internal and external auditors

    Sound governance requires the audit committee to independently oversee both internal and external audit functions, ensuring neither is unduly influenced by management.

  14. What is the purpose of a business continuity plan (BCP) from an IT audit perspective?

    Answer: Enable the organization to continue critical operations after a disruptive event

    A BCP provides documented procedures to sustain essential business functions during and after major disruptions such as natural disasters or cyberattacks.

  15. Which costing method assigns overhead based on activities driving cost?

    Answer: Activity-based costing

    Activity-based costing (ABC) is a costing method that identifies specific activities within an organization and assigns overhead costs to products or services based on the actual consumption of those activities. This approach provides a more accurate allocation of indirect costs than traditional methods. It recognizes that different products or services consume different amounts of resources based on the activities required for their production.

  16. What is considered a conflict of interest in accounting?

    Answer: Auditing a company you own shares in

    A conflict of interest arises when an accountant's personal interests or relationships could improperly influence their professional judgment or actions. Auditing a company in which the accountant owns shares creates such a conflict because their financial stake could compromise their objectivity and independence during the audit process. This situation undermines the credibility of the audit findings.

  17. Which of the following is the best example of a preventive IT control?

    Answer: Input validation that rejects invalid data entry at the source

    Input validation prevents invalid data from entering the system in the first place, making it a preventive rather than detective control.

  18. Which IT general control category is most directly concerned with ensuring that only authorized users can access financial systems?

    Answer: Logical access controls

    Logical access controls restrict system access to authorized users through passwords, roles, and authentication mechanisms.

  19. A CIA examiner reviewing a company's IT controls finds that system administrators also perform end-user functions. This is an example of a failure in:

    Answer: Segregation of duties

    Allowing system administrators to also perform end-user functions violates segregation of duties by giving one person excessive control.

  20. What is the purpose of an audit trail?

    Answer: To track transaction flow

    The purpose of an audit trail is to provide a chronological record of all financial transactions, showing the path from the source document to the general ledger and financial statements. This verifiable record allows auditors and management to trace individual transactions, ensuring accuracy, completeness, and proper authorization. It is crucial for detecting errors, fraud, and ensuring accountability within an organization.