Mixed Deck — All CIA Topics Flashcards
100 cards from real CIA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CIA Topics flashcards as text
What research standard applies to regulatory compliance?
Answer: Thorough research using primary legal authorities and current precedent
Legal professionals must conduct thorough research using primary authorities and current precedent to provide competent representation.
What fiduciary duty applies to estate planning?
Answer: Act in the client's best interest with loyalty, care, and full disclosure
Fiduciary duty requires acting in the client's best interest with loyalty, care, and full disclosure of all material facts.
How should risk be assessed in risk assessment?
Answer: Evaluate risk tolerance, capacity, time horizon, and investment objectives systematically
Comprehensive risk assessment considers tolerance, capacity, time horizon, and objectives to create appropriate strategies.
What fiduciary duty applies to tax strategies?
Answer: Act in the client's best interest with loyalty, care, and full disclosure
Fiduciary duty requires acting in the client's best interest with loyalty, care, and full disclosure of all material facts.
Data analytics can help detect payroll fraud by flagging which of the following anomalies?
Answer: Employees with direct deposit to the same bank account as a payroll administrator
Shared bank account numbers between employees and payroll administrators is a major red flag indicating ghost employee or paycheck diversion fraud.
How does due diligence apply to regulatory compliance?
Answer: Thorough investigation and verification of all relevant facts and circumstances
Due diligence requires thorough investigation and verification of all relevant facts to ensure competent and ethical practice.
Which internal control involves separating duties to reduce errors and fraud?
Answer: Segregation of Duties
Segregation of duties is a fundamental internal control principle that involves dividing responsibilities for related activities among different people. By separating the functions of authorization, record-keeping, and asset custody, it significantly reduces the opportunity for any single individual to commit and conceal errors or fraud. This enhances the reliability of financial reporting and protects organizational assets.
The Association of Certified Fraud Examiners (ACFE) Report to the Nations identifies which category as causing the greatest median loss per case?
Answer: Financial statement fraud
Financial statement fraud, while less frequent than other schemes, causes the greatest median loss per case according to ACFE data.
A company's code of conduct is primarily a governance tool that serves to:
Answer: Communicate expected ethical standards and behavioral guidelines to all employees
A code of conduct is a governance document that communicates the organization's ethical standards and expected behavior, helping establish the ethical culture throughout the organization.
A 'lapping' scheme in accounts receivable involves:
Answer: Stealing customer payments and covering the shortage with later receipts
Lapping is a fraud where an employee steals cash receipts and conceals the theft by applying subsequent payments to earlier accounts.
According to the fraud triangle, which of the following is NOT one of the three elements that contribute to fraudulent behavior?
Answer: Greed
The fraud triangle consists of pressure, rationalization, and opportunity — greed is not a recognized element of the model.
Which financial statement manipulation technique involves recording revenue before it is earned?
Answer: Channel stuffing and premature revenue recognition
Channel stuffing involves pressuring distributors to accept excess inventory to record revenue prematurely before it is truly earned.
In a well-designed corporate governance structure, which of the following relationships best reflects sound practice?
Answer: The audit committee provides independent oversight of both internal and external auditors
Sound governance requires the audit committee to independently oversee both internal and external audit functions, ensuring neither is unduly influenced by management.
What is the purpose of a business continuity plan (BCP) from an IT audit perspective?
Answer: Enable the organization to continue critical operations after a disruptive event
A BCP provides documented procedures to sustain essential business functions during and after major disruptions such as natural disasters or cyberattacks.
Which costing method assigns overhead based on activities driving cost?
Answer: Activity-based costing
Activity-based costing (ABC) is a costing method that identifies specific activities within an organization and assigns overhead costs to products or services based on the actual consumption of those activities. This approach provides a more accurate allocation of indirect costs than traditional methods. It recognizes that different products or services consume different amounts of resources based on the activities required for their production.
What is considered a conflict of interest in accounting?
Answer: Auditing a company you own shares in
A conflict of interest arises when an accountant's personal interests or relationships could improperly influence their professional judgment or actions. Auditing a company in which the accountant owns shares creates such a conflict because their financial stake could compromise their objectivity and independence during the audit process. This situation undermines the credibility of the audit findings.
Which of the following is the best example of a preventive IT control?
Answer: Input validation that rejects invalid data entry at the source
Input validation prevents invalid data from entering the system in the first place, making it a preventive rather than detective control.
Which IT general control category is most directly concerned with ensuring that only authorized users can access financial systems?
Answer: Logical access controls
Logical access controls restrict system access to authorized users through passwords, roles, and authentication mechanisms.
A CIA examiner reviewing a company's IT controls finds that system administrators also perform end-user functions. This is an example of a failure in:
Answer: Segregation of duties
Allowing system administrators to also perform end-user functions violates segregation of duties by giving one person excessive control.
What is the purpose of an audit trail?
Answer: To track transaction flow
The purpose of an audit trail is to provide a chronological record of all financial transactions, showing the path from the source document to the general ledger and financial statements. This verifiable record allows auditors and management to trace individual transactions, ensuring accuracy, completeness, and proper authorization. It is crucial for detecting errors, fraud, and ensuring accountability within an organization.