Certified Internal Auditor (CIA) Exam — Questions and Answers
Question 1: Which of the following best describes dual reporting for the Chief Audit Executive?
- The CAE reports to two external audit firms simultaneously
- The CAE reports to both the CFO and the CEO
- The CAE submits reports in both written and oral formats
- The CAE has administrative reporting to management and functional reporting to the board/audit committee (Correct answer)
Correct answer: The CAE has administrative reporting to management and functional reporting to the board/audit committee
Dual reporting means the CAE reports administratively to management (e.g., the CEO) for day-to-day operations while reporting functionally to the board or audit committee for independence and oversight.
Question 2: The Three Lines of Defense model assigns internal audit to which line?
- Fourth line
- Third line (Correct answer)
- Second line
- First line
Correct answer: Third line
Internal audit is the third line of defense, providing independent assurance over the effectiveness of risk management and controls established by the first and second lines.
Question 3: Which audit procedure evaluates the reasonableness of account balances by comparing to expectations?
- Inquiry Only
- Observation of Processes
- Analytical Procedures (Correct answer)
- Inspection of Records
Correct answer: Analytical Procedures
Analytical procedures evaluate financial information by studying plausible relationships among both financial and non-financial data. Auditors use these procedures to identify fluctuations or relationships that are inconsistent with other relevant information or that differ significantly from expected values. This helps in identifying areas of potential misstatement that require further investigation, making the audit process more efficient and effective.
Question 4: In evaluating IT general controls, which test procedure would an internal auditor most likely use to assess user access management?
- Tracing a transaction through the general ledger
- Reviewing a listing of user accounts and comparing to HR termination records (Correct answer)
- Confirming accounts receivable balances
- Re-performing a bank reconciliation
Correct answer: Reviewing a listing of user accounts and comparing to HR termination records
Comparing active user accounts to HR termination records identifies terminated employees who still have system access.
Question 5: Which cost behavior classification changes in total with production volume?
- Fixed costs
- Mixed costs
- Sunk costs
- Variable costs (Correct answer)
Correct answer: Variable costs
Variable costs are expenses that change in total directly and proportionally with the level of production volume or activity. As a company produces more units, the total variable cost increases, while the variable cost per unit remains constant. This direct relationship makes them distinct from fixed costs, which remain constant in total regardless of production changes.
Question 6: Which internal control is most effective at preventing check tampering fraud?
- Independent bank reconciliation performed by someone not involved in check preparation (Correct answer)
- Storing blank checks in an unlocked drawer for efficiency
- Requiring dual signatures on all checks
- Monthly bank reconciliations performed by the check preparer
Correct answer: Independent bank reconciliation performed by someone not involved in check preparation
An independent bank reconciliation performed by someone separate from check preparation detects unauthorized disbursements.
Question 7: What is the purpose of an audit trail?
- To increase sales
- To set budgets
- To track transaction flow (Correct answer)
- To manage payroll
Correct answer: To track transaction flow
The purpose of an audit trail is to provide a chronological record of all financial transactions, showing the path from the source document to the general ledger and financial statements. This verifiable record allows auditors and management to trace individual transactions, ensuring accuracy, completeness, and proper authorization. It is crucial for detecting errors, fraud, and ensuring accountability within an organization.
Question 8: Which analytical procedure would most likely detect a fictitious expense scheme in accounts payable?
- Comparison of budgeted vs. actual capital expenditures
- Trend analysis of expense accounts comparing current period to prior periods (Correct answer)
- Ratio of total assets to total liabilities
- Calculation of gross margin by product line
Correct answer: Trend analysis of expense accounts comparing current period to prior periods
Trend analysis comparing current expense balances to prior periods can reveal unexplained spikes that may indicate fictitious expenses.
Question 9: How should conflicts of interest be managed in estate planning?
- Identify, disclose, and mitigate all actual and potential conflicts of interest (Correct answer)
- Self-assessment of conflicts is sufficient
- Conflicts only matter in large transactions
- Conflicts are unavoidable and need not be disclosed
Correct answer: Identify, disclose, and mitigate all actual and potential conflicts of interest
All actual and potential conflicts of interest must be identified, disclosed to clients, and mitigated to maintain trust and compliance.
Question 10: Which internal control is most effective at preventing check tampering fraud?
- Annual external audits
- Dual authorization for check issuance (Correct answer)
- Periodic bank reconciliations
- Monthly expense reports
Correct answer: Dual authorization for check issuance
Dual authorization (requiring two approvers) prevents a single employee from issuing unauthorized checks without accomplice involvement.
Question 11: Data analytics can help detect payroll fraud by flagging which of the following anomalies?
- Departments with more than ten employees
- Employees who take more than two weeks of vacation per year
- Salary increases approved during the fiscal year
- Employees with direct deposit to the same bank account as a payroll administrator (Correct answer)
Correct answer: Employees with direct deposit to the same bank account as a payroll administrator
Shared bank account numbers between employees and payroll administrators is a major red flag indicating ghost employee or paycheck diversion fraud.
Question 12: What should an accountant do when facing an ethical dilemma?
- Follow the manager’s advice only
- Ignore the issue
- Refer to the code of ethics and seek guidance (Correct answer)
- Resign immediately
Correct answer: Refer to the code of ethics and seek guidance
When faced with an ethical dilemma, an accountant's primary step should be to refer to their professional code of ethics for guidance. This code provides a framework for ethical conduct and decision-making. If the code does not offer a clear solution, seeking advice from supervisors, legal counsel, or professional bodies can help navigate the situation responsibly and ethically.
Question 13: A 'fictitious vendor' scheme is best detected by:
- Performing physical inventory counts
- Reviewing customer satisfaction surveys
- Matching vendor addresses and bank accounts against employee records (Correct answer)
- Confirming accounts receivable with customers
Correct answer: Matching vendor addresses and bank accounts against employee records
Comparing vendor addresses, tax IDs, and bank accounts to employee data can reveal fictitious vendors set up by employees to divert company funds.
Question 14: What is the purpose of penetration testing in an IT audit context?
- Simulate attacks to identify exploitable security vulnerabilities (Correct answer)
- Measure system processing speed under load
- Assess IT staff knowledge of security policies
- Validate backup restoration procedures
Correct answer: Simulate attacks to identify exploitable security vulnerabilities
Penetration testing involves authorized simulated attacks on systems to proactively identify security weaknesses before malicious actors can exploit them.
Question 15: How should conflicts of interest be managed in financial planning?
- Self-assessment of conflicts is sufficient
- Conflicts are unavoidable and need not be disclosed
- Identify, disclose, and mitigate all actual and potential conflicts of interest (Correct answer)
- Conflicts only matter in large transactions
Correct answer: Identify, disclose, and mitigate all actual and potential conflicts of interest
All actual and potential conflicts of interest must be identified, disclosed to clients, and mitigated to maintain trust and compliance.
Question 16: An internal audit charter must be approved by:
- The Board or its delegated audit committee (Correct answer)
- The Chief Financial Officer only
- The external auditors
- The senior management team collectively
Correct answer: The Board or its delegated audit committee
Per IIA Standard 1000, the internal audit charter must be approved by the board or its delegated audit committee to establish the function's authority and independence.
Question 17: Which IT general control ensures that only authorized users can access an organization's financial systems?
- Backup and recovery controls
- Change management controls
- System development lifecycle controls
- Access controls (Correct answer)
Correct answer: Access controls
Access controls (logical security) restrict system entry to authorized users through authentication, authorization, and user account management.
Question 18: Which internal control activity involves management comparing actual results to budgets or forecasts?
- Authorization Procedures
- Physical Controls
- Segregation of Duties
- Performance Reviews (Correct answer)
Correct answer: Performance Reviews
Performance reviews, as an internal control activity, involve management comparing actual results to budgets, forecasts, or prior period results. This comparison helps identify significant variances and investigate their causes, ensuring that operations are proceeding as planned and financial goals are being met. It is a crucial control for monitoring operational efficiency, financial performance, and making timely corrective actions.
Question 19: How should estate planning performance be reported to clients?
- Only report positive results
- Let clients check their own accounts
- Provide accurate, complete, and timely performance reporting with appropriate benchmarks (Correct answer)
- Reporting is only required annually
Correct answer: Provide accurate, complete, and timely performance reporting with appropriate benchmarks
Accurate, complete, and timely reporting with appropriate benchmarks enables informed decision-making by clients.
Question 20: Under accrual accounting, when are revenues recognized?
- When the related expense is paid
- When cash is received
- When goods are shipped or services rendered (Correct answer)
- At the end of the fiscal year
Correct answer: When goods are shipped or services rendered
Under accrual accounting, revenues are recognized when they are earned, regardless of when cash is actually received. This means revenue is recorded once the company has substantially completed its obligation by delivering goods or performing services. This principle ensures that financial statements accurately reflect the economic activities of a period, providing a more complete picture of financial performance.
Question 21: How should risk be assessed in investment analysis?
- Evaluate risk tolerance, capacity, time horizon, and investment objectives systematically (Correct answer)
- Ignore risk for aggressive growth
- Risk assessment is only needed for retirees
- Use a one-size-fits-all risk profile
Correct answer: Evaluate risk tolerance, capacity, time horizon, and investment objectives systematically
Comprehensive risk assessment considers tolerance, capacity, time horizon, and objectives to create appropriate strategies.
Question 22: What is the difference between a Recovery Time Objective (RTO) and a Recovery Point Objective (RPO)?
- RTO measures data integrity; RPO measures system availability
- RTO applies to hardware; RPO applies to software
- RTO is the maximum tolerable downtime; RPO is the maximum acceptable data loss (Correct answer)
- RTO is the backup frequency; RPO is the time to restore a system
Correct answer: RTO is the maximum tolerable downtime; RPO is the maximum acceptable data loss
RTO defines how quickly systems must be restored after a disruption, while RPO defines how much data loss (measured in time) is acceptable.
Question 23: What does segregation of duties help prevent in an organization?
- Increased Efficiency
- Higher Sales
- Errors and Fraud (Correct answer)
- Better Communication
Correct answer: Errors and Fraud
Segregation of duties is a key internal control designed to prevent errors and fraud by ensuring that no single individual has control over all aspects of a financial transaction. By dividing responsibilities such as authorization, record-keeping, and asset custody among different employees, it creates a system of checks and balances. This makes it significantly more difficult for an individual to both commit and conceal improprieties.
Question 24: The IIA's Core Principles for the Professional Practice of Internal Auditing require that internal auditors demonstrate which quality to maintain their governance role?
- Profitability focus
- Objectivity (Correct answer)
- Executive authority
- Technical specialization only
Correct answer: Objectivity
Objectivity is a core principle requiring internal auditors to have an impartial, unbiased attitude and avoid conflicts of interest, which is essential to fulfilling their governance oversight role.
Question 25: A 'lapping' scheme in accounts receivable involves:
- Stealing customer payments and covering the shortage with later receipts (Correct answer)
- Issuing duplicate invoices to customers
- Writing off valid receivables as uncollectible
- Inflating revenue by recording fictitious sales
Correct answer: Stealing customer payments and covering the shortage with later receipts
Lapping is a fraud where an employee steals cash receipts and conceals the theft by applying subsequent payments to earlier accounts.
Question 26: How should conflicts of interest be managed in tax strategies?
- Conflicts only matter in large transactions
- Conflicts are unavoidable and need not be disclosed
- Identify, disclose, and mitigate all actual and potential conflicts of interest (Correct answer)
- Self-assessment of conflicts is sufficient
Correct answer: Identify, disclose, and mitigate all actual and potential conflicts of interest
All actual and potential conflicts of interest must be identified, disclosed to clients, and mitigated to maintain trust and compliance.
Question 27: How should risk be assessed in client relations?
- Ignore risk for aggressive growth
- Evaluate risk tolerance, capacity, time horizon, and investment objectives systematically (Correct answer)
- Use a one-size-fits-all risk profile
- Risk assessment is only needed for retirees
Correct answer: Evaluate risk tolerance, capacity, time horizon, and investment objectives systematically
Comprehensive risk assessment considers tolerance, capacity, time horizon, and objectives to create appropriate strategies.
Question 28: How should tax strategies performance be reported to clients?
- Provide accurate, complete, and timely performance reporting with appropriate benchmarks (Correct answer)
- Let clients check their own accounts
- Reporting is only required annually
- Only report positive results
Correct answer: Provide accurate, complete, and timely performance reporting with appropriate benchmarks
Accurate, complete, and timely reporting with appropriate benchmarks enables informed decision-making by clients.
Question 29: Which depreciation method allocates an asset’s cost evenly over its useful life?
- Declining Balance
- Straight‑Line (Correct answer)
- Sum‑of‑the‑Years’‑Digits
- Units of Production
Correct answer: Straight‑Line
The Straight-Line depreciation method allocates the cost of an asset evenly over its estimated useful life. It calculates depreciation expense by subtracting the salvage value from the asset's cost and dividing the result by the number of useful years. This method is simple to apply and results in a consistent depreciation expense each period, making it predictable for financial planning.
Question 30: Under a CIA audit, which of the following would be classified as an IT application control rather than a general control?
- Patch management procedures
- User access provisioning process
- Physical security of the data center
- Automated three-way match of purchase orders, receipts, and invoices (Correct answer)
Correct answer: Automated three-way match of purchase orders, receipts, and invoices
An automated three-way match is an application control embedded in the accounts payable system to prevent payment errors.
Question 31: Under the IIA's International Professional Practices Framework (IPPF), which document establishes the purpose, authority, and responsibility of the internal audit activity?
- The engagement work program
- The risk assessment matrix
- The internal audit charter (Correct answer)
- The annual audit report
Correct answer: The internal audit charter
The internal audit charter is the formal document that establishes the internal audit activity's purpose, authority, and responsibility, and must be consistent with the IIA's Definition of Internal Auditing and Core Principles.
Question 32: Which principle is fundamental to the integrity of the accounting profession?
- Integrity (Correct answer)
- Independence
- Confidentiality
- Due care
Correct answer: Integrity
Integrity is a fundamental ethical principle that requires accountants to be straightforward, honest, and fair in all professional and business relationships. It ensures that financial information is reliable and trustworthy, which is crucial for maintaining public confidence in the accounting profession. Upholding integrity means avoiding misrepresentation and acting with candor.
Question 33: How should risk assessment performance be reported to clients?
- Only report positive results
- Reporting is only required annually
- Provide accurate, complete, and timely performance reporting with appropriate benchmarks (Correct answer)
- Let clients check their own accounts
Correct answer: Provide accurate, complete, and timely performance reporting with appropriate benchmarks
Accurate, complete, and timely reporting with appropriate benchmarks enables informed decision-making by clients.
Question 34: Which of the following best describes 'tone at the top' in the context of fraud prevention?
- The strictness of the internal audit department's testing
- The ethical culture and values modeled by senior leadership and the board (Correct answer)
- Requiring executive sign-off on all journal entries
- The volume of anti-fraud training provided to employees
Correct answer: The ethical culture and values modeled by senior leadership and the board
Tone at the top refers to the ethical environment established by leadership; a strong ethical culture is the most powerful deterrent to fraud.
Question 35: In a well-designed corporate governance structure, which of the following relationships best reflects sound practice?
- The internal audit function reports solely to the CFO
- The audit committee provides independent oversight of both internal and external auditors (Correct answer)
- Management selects and dismisses the external auditor without board involvement
- The external auditor sets the internal audit agenda
Correct answer: The audit committee provides independent oversight of both internal and external auditors
Sound governance requires the audit committee to independently oversee both internal and external audit functions, ensuring neither is unduly influenced by management.
Question 36: How should risk be assessed in risk assessment?
- Use a one-size-fits-all risk profile
- Ignore risk for aggressive growth
- Evaluate risk tolerance, capacity, time horizon, and investment objectives systematically (Correct answer)
- Risk assessment is only needed for retirees
Correct answer: Evaluate risk tolerance, capacity, time horizon, and investment objectives systematically
Comprehensive risk assessment considers tolerance, capacity, time horizon, and objectives to create appropriate strategies.
Question 37: How should confidentiality be maintained in regulatory compliance?
- Protect all privileged information unless authorized disclosure applies (Correct answer)
- Confidentiality only applies in court
- Share information freely with colleagues
- Disclose information when it benefits the case
Correct answer: Protect all privileged information unless authorized disclosure applies
Confidentiality requires protecting all privileged information, with disclosure only when specifically authorized by law or the client.
Question 38: A company's code of conduct is primarily a governance tool that serves to:
- Satisfy tax reporting requirements to the IRS
- Communicate expected ethical standards and behavioral guidelines to all employees (Correct answer)
- Document the external auditor's responsibilities
- Replace the need for internal audit oversight
Correct answer: Communicate expected ethical standards and behavioral guidelines to all employees
A code of conduct is a governance document that communicates the organization's ethical standards and expected behavior, helping establish the ethical culture throughout the organization.
Question 39: In fraud investigations, what is a 'predicate' for initiating a formal investigation?
- A signed confession from the suspect
- A reasonable basis or indicators suggesting fraud may have occurred (Correct answer)
- A formal complaint filed with the SEC
- Documented material misstatement in financial statements
Correct answer: A reasonable basis or indicators suggesting fraud may have occurred
A predicate is the totality of circumstances that would lead a reasonable, professionally trained person to believe fraud has occurred, is occurring, or will occur.
Question 40: A CIA auditor is reviewing controls over a cloud-based accounting system. Which shared responsibility model principle is most important to understand?
- The cloud vendor is responsible for all security controls
- Cloud systems do not require IT general controls
- The auditor is responsible for cloud infrastructure testing
- The organization retains responsibility for data classification and user access (Correct answer)
Correct answer: The organization retains responsibility for data classification and user access
In a shared responsibility model, the organization always retains responsibility for its own data, user access management, and application-level controls.
Question 41: Under the Sarbanes-Oxley Act (SOX), which section requires management to assess and report on internal controls over financial reporting?
- Section 409
- Section 401
- Section 404 (Correct answer)
- Section 302
Correct answer: Section 404
SOX Section 404 requires management to assess internal control over financial reporting and requires auditors to attest to that assessment.
Question 42: What is considered a conflict of interest in accounting?
- Completing continuing education
- Accepting a gift from a client
- Auditing a company you own shares in (Correct answer)
- Using software to complete taxes
Correct answer: Auditing a company you own shares in
A conflict of interest arises when an accountant's personal interests or relationships could improperly influence their professional judgment or actions. Auditing a company in which the accountant owns shares creates such a conflict because their financial stake could compromise their objectivity and independence during the audit process. This situation undermines the credibility of the audit findings.
Question 43: What is a variance in standard costing?
- Difference between actual revenue and budgeted profit
- Difference between budgeted and actual costs (Correct answer)
- Difference between cash and accrual methods
- Difference between fixed and variable costs
Correct answer: Difference between budgeted and actual costs
In standard costing, a variance represents the difference between the actual cost incurred for an activity or product and the predetermined standard (budgeted) cost. Analyzing these variances is essential for management to identify inefficiencies, control costs, and evaluate performance. It highlights deviations from expected results, prompting investigation into their causes.
Question 44: What should an accountant do if asked to perform a task outside their competence?
- Attempt it anyway
- Assign it to a junior staff member
- Google the solution
- Consult or decline if outside professional ability (Correct answer)
Correct answer: Consult or decline if outside professional ability
If an accountant is asked to perform a task outside their professional competence, they have an ethical obligation to either decline the task or seek appropriate consultation and training to gain the necessary expertise. Attempting a task without the required skills could lead to errors, compromise professional standards, and potentially harm the client or organization. Professional integrity demands acknowledging limitations.
Question 45: Why is independence important in internal auditing?
- To increase office efficiency
- To ensure unbiased evaluations (Correct answer)
- To improve profits
- To reduce documentation
Correct answer: To ensure unbiased evaluations
Independence is paramount in internal auditing because it ensures that auditors can perform their work without undue influence or interference from management or other stakeholders. This objectivity is critical for providing unbiased evaluations, findings, and recommendations. Maintaining independence enhances the credibility and reliability of the audit function, thereby adding greater value to the organization.
Question 46: What continuing education requirement supports risk assessment competence?
- Ongoing education in regulatory changes, market developments, and best practices (Correct answer)
- Initial licensure is sufficient
- Education is only needed when seeking promotion
- Read financial news occasionally
Correct answer: Ongoing education in regulatory changes, market developments, and best practices
Financial markets, regulations, and best practices evolve constantly, requiring ongoing education for competent practice.
Question 47: Which financial statement reports revenues and expenses over a period?
- Statement of Cash Flows
- Statement of Retained Earnings
- Balance Sheet
- Income Statement (Correct answer)
Correct answer: Income Statement
The Income Statement, also known as the Profit and Loss (P&L) statement, reports a company's financial performance over a specific period, such as a quarter or a year. It details all revenues earned and expenses incurred during that period, ultimately calculating the net income or loss. This statement provides crucial insights into a company's profitability and operational efficiency.
Question 48: Which audit opinion indicates that the financial statements are presented fairly in all material respects?
- Qualified Opinion
- Adverse Opinion
- Unqualified Opinion (Correct answer)
- Disclaimer of Opinion
Correct answer: Unqualified Opinion
An unqualified opinion, also known as a clean opinion, is the most favorable type of audit opinion. It indicates that the auditor has concluded that the financial statements are presented fairly, in all material respects, in accordance with the applicable financial reporting framework. This opinion provides users with a high level of assurance regarding the reliability and credibility of the financial statements.
Question 49: What continuing education requirement supports tax strategies competence?
- Read financial news occasionally
- Ongoing education in regulatory changes, market developments, and best practices (Correct answer)
- Initial licensure is sufficient
- Education is only needed when seeking promotion
Correct answer: Ongoing education in regulatory changes, market developments, and best practices
Financial markets, regulations, and best practices evolve constantly, requiring ongoing education for competent practice.
Question 50: Which concept describes the process of verifying that a user is who they claim to be before granting system access?
- Authorization
- Accountability
- Authentication (Correct answer)
- Non-repudiation
Correct answer: Authentication
Authentication is the process of verifying identity (e.g., via password, biometrics, or multi-factor methods) before access is granted.
Question 51: Corporate governance is best described as:
- The internal audit methodology used to assess operational risks
- The regulatory filing requirements imposed by the SEC
- The process of preparing financial statements for shareholders
- The system of rules, practices, and processes by which a company is directed and controlled (Correct answer)
Correct answer: The system of rules, practices, and processes by which a company is directed and controlled
Corporate governance is the system of rules, practices, and processes by which a company is directed and controlled, balancing the interests of stakeholders.
Question 52: What is the professional obligation if an accountant identifies fraud?
- Confront the accused directly
- Ignore minor discrepancies
- Report it through the appropriate internal channels (Correct answer)
- Post anonymously online
Correct answer: Report it through the appropriate internal channels
Upon identifying fraud, an accountant has a professional and ethical obligation to report it through the appropriate internal channels within the organization. This typically involves informing senior management, the audit committee, or a designated compliance officer. Reporting internally ensures the issue is addressed properly and helps maintain the integrity of financial reporting and internal controls.
Question 53: How should conflicts of interest be managed in investment analysis?
- Conflicts are unavoidable and need not be disclosed
- Self-assessment of conflicts is sufficient
- Identify, disclose, and mitigate all actual and potential conflicts of interest (Correct answer)
- Conflicts only matter in large transactions
Correct answer: Identify, disclose, and mitigate all actual and potential conflicts of interest
All actual and potential conflicts of interest must be identified, disclosed to clients, and mitigated to maintain trust and compliance.
Question 54: What regulatory compliance requirement applies to risk assessment?
- Self-regulation is sufficient
- Full compliance with all applicable federal, state, and industry regulations (Correct answer)
- Compliance is only needed for publicly traded companies
- Regulations are optional for small practices
Correct answer: Full compliance with all applicable federal, state, and industry regulations
Full regulatory compliance is mandatory regardless of practice size, ensuring market integrity and client protection.
Question 55: What fiduciary duty applies to risk assessment?
- Maximize the advisor's commission
- Act in the client's best interest with loyalty, care, and full disclosure (Correct answer)
- Recommend the most expensive products
- Follow the firm's sales targets above all
Correct answer: Act in the client's best interest with loyalty, care, and full disclosure
Fiduciary duty requires acting in the client's best interest with loyalty, care, and full disclosure of all material facts.
Question 56: How should risk be assessed in tax strategies?
- Evaluate risk tolerance, capacity, time horizon, and investment objectives systematically (Correct answer)
- Ignore risk for aggressive growth
- Risk assessment is only needed for retirees
- Use a one-size-fits-all risk profile
Correct answer: Evaluate risk tolerance, capacity, time horizon, and investment objectives systematically
Comprehensive risk assessment considers tolerance, capacity, time horizon, and objectives to create appropriate strategies.
Question 57: Which of the following is the most common type of occupational fraud according to the ACFE Report to the Nations?
- Bribery and kickbacks
- Corruption schemes
- Financial statement fraud
- Asset misappropriation (Correct answer)
Correct answer: Asset misappropriation
Asset misappropriation is by far the most common category of occupational fraud, accounting for the majority of reported cases.
Question 58: Which audit procedure is most effective for testing that user access privileges are appropriate and follow least privilege principles?
- Inspecting software licensing agreements
- Reviewing IT project plans
- Performing a user access review (UAR) (Correct answer)
- Testing disaster recovery procedures
Correct answer: Performing a user access review (UAR)
A user access review compares granted system privileges against job responsibilities to identify excessive, inappropriate, or orphaned access rights.
Question 59: An internal auditor reviewing cloud computing arrangements should be most concerned with which risk?
- Increased hardware maintenance costs
- Reduced need for IT staff
- Loss of direct control over data and processes managed by the cloud provider (Correct answer)
- Slower processing speed compared to on-premise systems
Correct answer: Loss of direct control over data and processes managed by the cloud provider
Cloud arrangements shift operational control to a third party, creating risks around data security, availability, regulatory compliance, and the ability to audit the provider.
Question 60: Which type of fraud involves an employee creating fictitious vendors and submitting false invoices for payment?
- Ghost vendor scheme (Correct answer)
- Skimming
- Kiting
- Lapping
Correct answer: Ghost vendor scheme
A ghost vendor scheme involves setting up fictitious vendors in the accounts payable system to divert company funds to the fraudster.
Question 61: The concept of 'tone at the top' in corporate governance refers to:
- The ethical climate and commitment to integrity demonstrated by senior leadership (Correct answer)
- The first section of the annual report filed with regulators
- The highest salary band in the organization
- The top-tier risk categories identified during an audit
Correct answer: The ethical climate and commitment to integrity demonstrated by senior leadership
Tone at the top describes the ethical atmosphere that senior executives and the board create, which permeates the organization and influences employee behavior.
Question 62: What is the primary purpose of an anonymous fraud hotline in an organization?
- Encourage employees to report suspected fraud without fear of retaliation (Correct answer)
- Eliminate the need for segregation of duties
- Satisfy external auditor requirements only
- Replace the internal audit function
Correct answer: Encourage employees to report suspected fraud without fear of retaliation
An anonymous hotline provides a safe channel for employees to report suspected wrongdoing, significantly increasing the likelihood that fraud is detected through tips.
Question 63: Which control activity is specifically designed to prevent a single employee from both authorizing and recording transactions?
- Segregation of duties (Correct answer)
- Physical safeguards
- Documentation procedures
- Independent verification
Correct answer: Segregation of duties
Segregation of duties ensures that authorization, recording, and custody functions are divided among different employees to reduce fraud risk.
Question 64: How should client relations performance be reported to clients?
- Only report positive results
- Provide accurate, complete, and timely performance reporting with appropriate benchmarks (Correct answer)
- Let clients check their own accounts
- Reporting is only required annually
Correct answer: Provide accurate, complete, and timely performance reporting with appropriate benchmarks
Accurate, complete, and timely reporting with appropriate benchmarks enables informed decision-making by clients.
Question 65: What fiduciary duty applies to client relations?
- Maximize the advisor's commission
- Recommend the most expensive products
- Act in the client's best interest with loyalty, care, and full disclosure (Correct answer)
- Follow the firm's sales targets above all
Correct answer: Act in the client's best interest with loyalty, care, and full disclosure
Fiduciary duty requires acting in the client's best interest with loyalty, care, and full disclosure of all material facts.
Question 66: Which encryption concept ensures that a sender cannot later deny having sent a message?
- Public key infrastructure certificate revocation
- Hashing for data integrity
- Symmetric encryption
- Non-repudiation via digital signatures (Correct answer)
Correct answer: Non-repudiation via digital signatures
Non-repudiation, achieved through digital signatures, provides proof of origin so a sender cannot deny sending a message.
Question 67: Which data analytics technique is commonly used to detect potential payroll fraud such as ghost employees?
- Matching employee records to payroll disbursements (Correct answer)
- Regression analysis
- Benford's Law analysis
- Horizontal financial statement analysis
Correct answer: Matching employee records to payroll disbursements
Matching HR employee records against payroll disbursements identifies payments made to individuals who do not appear in the active employee database.
Question 68: Which financial statement manipulation technique involves recording revenue before it is earned?
- Capitalizing operating expenses
- Understating accounts payable
- Overstating the allowance for doubtful accounts
- Channel stuffing and premature revenue recognition (Correct answer)
Correct answer: Channel stuffing and premature revenue recognition
Channel stuffing involves pressuring distributors to accept excess inventory to record revenue prematurely before it is truly earned.
Question 69: What fiduciary duty applies to financial planning?
- Act in the client's best interest with loyalty, care, and full disclosure (Correct answer)
- Maximize the advisor's commission
- Follow the firm's sales targets above all
- Recommend the most expensive products
Correct answer: Act in the client's best interest with loyalty, care, and full disclosure
Fiduciary duty requires acting in the client's best interest with loyalty, care, and full disclosure of all material facts.
Question 70: Which organization publishes the Code of Ethics for internal auditors?
- AICPA
- SEC
- IIA (Correct answer)
- FASB
Correct answer: IIA
The Institute of Internal Auditors (IIA) is the global professional association for internal auditors. It is responsible for publishing the International Standards for the Professional Practice of Internal Auditing (Standards) and a comprehensive Code of Ethics that guides the conduct of internal auditors worldwide. These documents establish the principles and rules of conduct for the profession.
Question 71: An internal auditor reviewing IT application controls would examine which of the following?
- Firewall configurations
- Server room physical access logs
- Input validation and edit checks within a specific application (Correct answer)
- Network intrusion detection system alerts
Correct answer: Input validation and edit checks within a specific application
Application controls are embedded within specific systems and include input validation, processing controls, and output controls.
Question 72: A board of directors fulfills its governance responsibilities primarily through which of the following activities?
- Setting strategic direction, overseeing management, and ensuring accountability (Correct answer)
- Managing day-to-day operations and approving all expenditures
- Preparing financial statements for external reporting
- Performing operational audits of business units
Correct answer: Setting strategic direction, overseeing management, and ensuring accountability
The board fulfills governance responsibilities by setting strategic direction, hiring and overseeing senior management, and ensuring the organization is accountable to stakeholders.
Question 73: The concept of 'stewardship' in corporate governance refers to:
- The external auditor's duty to detect all fraud
- The board's authority to set employee salaries
- Management's responsibility to protect and grow assets on behalf of the organization's owners and stakeholders (Correct answer)
- The process of auditing third-party vendors
Correct answer: Management's responsibility to protect and grow assets on behalf of the organization's owners and stakeholders
Stewardship in governance means that management acts as a responsible caretaker of the organization's assets and interests on behalf of shareholders and other stakeholders.
Question 74: In a 'bill and hold' fraud scheme, a company records revenue for goods that:
- Were manufactured using substandard materials
- Have been invoiced but not yet shipped or delivered to the customer (Correct answer)
- Were sold below cost
- Have been returned by customers
Correct answer: Have been invoiced but not yet shipped or delivered to the customer
A bill and hold scheme records revenue when a sale is invoiced but the goods remain physically held at the seller's warehouse, violating revenue recognition standards.
Question 75: In IT auditing, what does 'segregation of duties' within the IT function typically require?
- Independent third-party reviews of all code
- All IT staff to rotate jobs annually
- Outsourcing IT operations to reduce conflict of interest
- Separation of system development, operations, and security roles (Correct answer)
Correct answer: Separation of system development, operations, and security roles
IT segregation of duties separates the development, operations, and security functions to prevent individuals from both creating and deploying unauthorized changes.
Question 76: When an internal auditor suspects fraud during an audit, the appropriate immediate action is to:
- Confront the suspected employee directly
- Report findings to appropriate levels of management and governance (Correct answer)
- Suspend the audit and wait for legal counsel
- Notify the board of directors without delay
Correct answer: Report findings to appropriate levels of management and governance
IIA standards require internal auditors to report suspected fraud to appropriate management levels and governance bodies, such as the audit committee.
Question 77: Which IT general control category is most directly concerned with ensuring that only authorized users can access financial systems?
- Change management controls
- System development controls
- Logical access controls (Correct answer)
- Computer operations controls
Correct answer: Logical access controls
Logical access controls restrict system access to authorized users through passwords, roles, and authentication mechanisms.
Question 78: How should portfolio management performance be reported to clients?
- Reporting is only required annually
- Let clients check their own accounts
- Only report positive results
- Provide accurate, complete, and timely performance reporting with appropriate benchmarks (Correct answer)
Correct answer: Provide accurate, complete, and timely performance reporting with appropriate benchmarks
Accurate, complete, and timely reporting with appropriate benchmarks enables informed decision-making by clients.
Question 79: What tool is used to analyze the impact of cost, volume, and price on profit?
- Cost–volume–profit analysis (Correct answer)
- Standard costing
- Variance analysis
- Activity-based costing
Correct answer: Cost–volume–profit analysis
Cost-volume-profit (CVP) analysis is a crucial management accounting tool used to examine the relationships between costs, sales volume, and profit. It helps businesses understand how changes in these three factors impact overall profitability. By analyzing these interdependencies, companies can make informed decisions regarding pricing strategies, production levels, and cost management.
Question 80: How should financial planning performance be reported to clients?
- Let clients check their own accounts
- Reporting is only required annually
- Provide accurate, complete, and timely performance reporting with appropriate benchmarks (Correct answer)
- Only report positive results
Correct answer: Provide accurate, complete, and timely performance reporting with appropriate benchmarks
Accurate, complete, and timely reporting with appropriate benchmarks enables informed decision-making by clients.
Question 81: Which governance principle emphasizes that those making decisions on behalf of the organization must be answerable for their actions and outcomes?
- Sustainability
- Transparency
- Accountability (Correct answer)
- Stewardship
Correct answer: Accountability
Accountability is the governance principle requiring individuals and entities to answer for their actions and decisions, and is fundamental to effective corporate governance.
Question 82: Benford's Law is used in fraud detection to analyze:
- Compliance with federal sentencing guidelines
- Employee background check results
- The expected frequency distribution of leading digits in naturally occurring numbers (Correct answer)
- The ratio of audit fees to company revenue
Correct answer: The expected frequency distribution of leading digits in naturally occurring numbers
Benford's Law predicts the frequency of leading digits in datasets; deviations from this distribution can indicate manipulated or fabricated numbers.
Question 83: Which inventory costing method assumes the first goods purchased are the first sold?
- LIFO
- Weighted Average
- FIFO (Correct answer)
- Specific Identification
Correct answer: FIFO
The FIFO (First-In, First-Out) inventory costing method assumes that the first goods purchased or produced are the first ones sold. This method aligns with the physical flow of most businesses, especially for perishable goods, and generally results in a higher net income and inventory value during periods of rising costs. It reflects the most recent costs in ending inventory, providing a current valuation.
Question 84: What is a closing entry?
- Recording an accrued expense
- Opening a new ledger account
- Adjusting an asset’s book value
- Transferring temporary account balances (Correct answer)
Correct answer: Transferring temporary account balances
Closing entries are made at the end of an accounting period to transfer the balances of temporary accounts (revenues, expenses, and dividends) to a permanent equity account, typically Retained Earnings. This process resets the temporary accounts to zero, preparing them for the next accounting period, and ensures that the income statement reflects only the current period's activity. It is a vital step in the accounting cycle.
Question 85: Which scheme involves an employee manipulating the books to conceal a cash theft by debiting a suspense or miscellaneous account?
- Skimming
- Forced balancing or plugging (Correct answer)
- Kiting
- Fictitious disbursements
Correct answer: Forced balancing or plugging
Forced balancing involves entering unsupported debit entries to suspense accounts to make the books balance after a theft.
Question 86: What is 'lapping' in the context of accounts receivable fraud?
- Recording fictitious sales to inflate revenue
- Writing off customer balances and pocketing cash
- Issuing duplicate payments to vendors
- Using one customer's payment to cover a stolen prior payment (Correct answer)
Correct answer: Using one customer's payment to cover a stolen prior payment
Lapping involves stealing a customer's payment and then covering it with a subsequent customer's payment, creating a rolling shortage.
Question 87: According to IIA Standards, organizational independence for the internal audit function is achieved when the CAE reports to a level that allows the function to:
- Fulfill its responsibilities without interference (Correct answer)
- Operate without a formal charter
- Report directly to the external auditors
- Maximize the number of audits completed per year
Correct answer: Fulfill its responsibilities without interference
Organizational independence requires the CAE to report to a sufficiently high level in the organization so the internal audit activity can fulfill its responsibilities free from undue influence.
Question 88: According to the fraud triangle, which of the following is NOT one of the three elements that contribute to fraudulent behavior?
- Greed (Correct answer)
- Rationalization
- Opportunity
- Pressure
Correct answer: Greed
The fraud triangle consists of pressure, rationalization, and opportunity — greed is not a recognized element of the model.
Question 89: Which of the following is the best example of a preventive IT control?
- Automated system alerts when anomalies are detected
- Input validation that rejects invalid data entry at the source (Correct answer)
- Post-processing exception reports reviewed by management
- Audit trails that log all user transactions
Correct answer: Input validation that rejects invalid data entry at the source
Input validation prevents invalid data from entering the system in the first place, making it a preventive rather than detective control.
Question 90: According to the IIA Standards, the Chief Audit Executive (CAE) should report functionally to which body to ensure organizational independence?
- The Chief Financial Officer
- The Chief Executive Officer
- The Board or Audit Committee (Correct answer)
- The External Auditor
Correct answer: The Board or Audit Committee
The IIA Standards require the CAE to have functional reporting to the board or audit committee to maintain independence from management.
Question 91: When auditing an ERP system, which procedure would best test the completeness of recorded transactions?
- Reviewing system configuration settings
- Vouching from system records back to source documents
- Interviewing IT personnel about data flows
- Tracing from source documents to the system (Correct answer)
Correct answer: Tracing from source documents to the system
Tracing from source documents to the system tests completeness by verifying that transactions originating outside the system were actually captured and recorded.
Question 92: Which framework is most commonly referenced for evaluating and improving IT governance and management within internal audit?
- ISO 9001
- COSO ERM
- COBIT (Correct answer)
- NIST SP 800-53
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is the leading framework for IT governance and management used in internal audit evaluations.
Question 93: What regulatory compliance requirement applies to tax strategies?
- Full compliance with all applicable federal, state, and industry regulations (Correct answer)
- Compliance is only needed for publicly traded companies
- Self-regulation is sufficient
- Regulations are optional for small practices
Correct answer: Full compliance with all applicable federal, state, and industry regulations
Full regulatory compliance is mandatory regardless of practice size, ensuring market integrity and client protection.
Question 94: According to the fraud triangle, which three elements must be present for fraud to occur?
- Greed, access, and collusion
- Motive, skill, and access
- Incentive, knowledge, and deception
- Pressure, opportunity, and rationalization (Correct answer)
Correct answer: Pressure, opportunity, and rationalization
The fraud triangle identifies pressure (incentive), opportunity (weak controls), and rationalization (justification) as the three conditions enabling fraud.
Question 95: What regulatory compliance requirement applies to estate planning?
- Self-regulation is sufficient
- Full compliance with all applicable federal, state, and industry regulations (Correct answer)
- Regulations are optional for small practices
- Compliance is only needed for publicly traded companies
Correct answer: Full compliance with all applicable federal, state, and industry regulations
Full regulatory compliance is mandatory regardless of practice size, ensuring market integrity and client protection.
Question 96: What regulatory compliance requirement applies to financial planning?
- Self-regulation is sufficient
- Full compliance with all applicable federal, state, and industry regulations (Correct answer)
- Compliance is only needed for publicly traded companies
- Regulations are optional for small practices
Correct answer: Full compliance with all applicable federal, state, and industry regulations
Full regulatory compliance is mandatory regardless of practice size, ensuring market integrity and client protection.
Question 97: Which budgeting approach starts from zero for each period?
- Incremental budgeting
- Flexible budgeting
- Static budgeting
- Zero-based budgeting (Correct answer)
Correct answer: Zero-based budgeting
Zero-based budgeting (ZBB) is a budgeting approach that requires all expenses to be justified for each new period, starting from a 'zero base.' Unlike incremental budgeting, it does not assume that past expenditures are necessary. This method forces managers to thoroughly evaluate every activity and cost, promoting efficiency and ensuring resources are allocated based on current needs and priorities.
Question 98: What regulatory compliance requirement applies to investment analysis?
- Self-regulation is sufficient
- Full compliance with all applicable federal, state, and industry regulations (Correct answer)
- Compliance is only needed for publicly traded companies
- Regulations are optional for small practices
Correct answer: Full compliance with all applicable federal, state, and industry regulations
Full regulatory compliance is mandatory regardless of practice size, ensuring market integrity and client protection.
Question 99: What is the role of an audit log (audit trail) in IT systems?
- Record a chronological history of user activities and system events for accountability (Correct answer)
- Speed up transaction processing
- Automatically correct data entry errors
- Compress data to reduce storage costs
Correct answer: Record a chronological history of user activities and system events for accountability
Audit logs create an immutable chronological record of system activities, enabling auditors and security teams to reconstruct events and establish accountability.
Question 100: A CIA examiner reviewing a company's IT controls finds that system administrators also perform end-user functions. This is an example of a failure in:
- Business continuity planning
- Patch management
- Data encryption standards
- Segregation of duties (Correct answer)
Correct answer: Segregation of duties
Allowing system administrators to also perform end-user functions violates segregation of duties by giving one person excessive control.
Question 101: Which COBIT framework domain is most focused on acquiring and implementing IT solutions?
- Deliver, Service and Support
- Build, Acquire and Implement (Correct answer)
- Monitor, Evaluate and Assess
- Align, Plan and Organize
Correct answer: Build, Acquire and Implement
The 'Build, Acquire and Implement' domain of COBIT covers how IT solutions are acquired, developed, and put into production.
Question 102: The King IV Report on Corporate Governance (South Africa) introduced the concept of 'integrated thinking,' which means:
- Combining financial and tax reporting into a single document
- Considering the interconnectedness of capital resources and their impact on value creation over time (Correct answer)
- Merging the roles of CEO and Chairman for efficiency
- Integrating internal and external audit teams
Correct answer: Considering the interconnectedness of capital resources and their impact on value creation over time
King IV's integrated thinking requires governing bodies to consider how financial, manufactured, intellectual, human, social, and natural capital interact and affect the organization's ability to create value.
Question 103: During a CIA audit, an auditor assesses whether backups are stored offsite. This control is primarily designed to support:
- Access control compliance
- Business continuity and disaster recovery (Correct answer)
- Change management procedures
- User authentication standards
Correct answer: Business continuity and disaster recovery
Offsite backup storage ensures that data can be recovered in the event of a disaster that destroys the primary site.
Question 104: Which type of financial statement fraud involves recognizing revenue before it has been earned or that is otherwise fictitious?
- Asset overstatement
- Related-party transaction abuse
- Liability concealment
- Revenue recognition manipulation (Correct answer)
Correct answer: Revenue recognition manipulation
Revenue recognition manipulation involves premature or fictitious revenue booking to inflate reported earnings and deceive financial statement users.
Question 105: Due care in accounting means:
- Only working within a company
- Acting with competence and diligence (Correct answer)
- Relying on assumptions
- Minimizing effort
Correct answer: Acting with competence and diligence
Due care in accounting means performing professional services with competence, diligence, and proper planning, applying professional judgment and skepticism. It requires accountants to act in the best interest of their clients or employers while adhering to professional standards and ethical principles. This ensures that work is performed thoroughly and accurately.
Question 106: What fiduciary duty applies to tax strategies?
- Act in the client's best interest with loyalty, care, and full disclosure (Correct answer)
- Follow the firm's sales targets above all
- Maximize the advisor's commission
- Recommend the most expensive products
Correct answer: Act in the client's best interest with loyalty, care, and full disclosure
Fiduciary duty requires acting in the client's best interest with loyalty, care, and full disclosure of all material facts.
Question 107: What continuing education requirement supports portfolio management competence?
- Initial licensure is sufficient
- Read financial news occasionally
- Ongoing education in regulatory changes, market developments, and best practices (Correct answer)
- Education is only needed when seeking promotion
Correct answer: Ongoing education in regulatory changes, market developments, and best practices
Financial markets, regulations, and best practices evolve constantly, requiring ongoing education for competent practice.
Question 108: What is the purpose of a business continuity plan (BCP) from an IT audit perspective?
- Manage software licensing compliance
- Test employee cybersecurity awareness
- Ensure daily data backups are performed
- Enable the organization to continue critical operations after a disruptive event (Correct answer)
Correct answer: Enable the organization to continue critical operations after a disruptive event
A BCP provides documented procedures to sustain essential business functions during and after major disruptions such as natural disasters or cyberattacks.
Question 109: Which COSO component focuses on the attitudes and actions of leadership that set the ethical tone for an organization?
- Risk Assessment
- Control Environment (Correct answer)
- Monitoring Activities
- Control Activities
Correct answer: Control Environment
The Control Environment is the COSO component that reflects 'tone at the top' — the integrity, ethical values, and management philosophy that establish the foundation for internal control.
Question 110: Which of the following best describes a 'shell company' scheme used in financial fraud?
- Inflating inventory counts
- Altering check amounts after approval
- Creating a fictitious entity to funnel unauthorized payments (Correct answer)
- Forging bank confirmations
Correct answer: Creating a fictitious entity to funnel unauthorized payments
A shell company scheme involves establishing a fictitious or controlled entity to receive fraudulent payments from the victim organization.
Question 111: What is the primary focus of managerial accounting?
- Supporting internal decision-making (Correct answer)
- Preparing external financial statements
- Allocating dividends to shareholders
- Auditing historical data
Correct answer: Supporting internal decision-making
The primary focus of managerial accounting is to provide financial and non-financial information to internal users, such as managers and employees, to aid in planning, controlling, and decision-making within the organization. Unlike financial accounting, it is not bound by GAAP and is tailored to meet specific internal needs. This information helps management optimize operations, allocate resources efficiently, and achieve strategic objectives.
Question 112: A whistleblower hotline is considered which type of anti-fraud control?
- Detective control (Correct answer)
- Corrective control
- Preventive control
- Directive control
Correct answer: Detective control
A whistleblower hotline is a detective control because it helps identify fraud that has already occurred by encouraging reporting.
Question 113: How should conflicts of interest be managed in risk assessment?
- Conflicts only matter in large transactions
- Conflicts are unavoidable and need not be disclosed
- Self-assessment of conflicts is sufficient
- Identify, disclose, and mitigate all actual and potential conflicts of interest (Correct answer)
Correct answer: Identify, disclose, and mitigate all actual and potential conflicts of interest
All actual and potential conflicts of interest must be identified, disclosed to clients, and mitigated to maintain trust and compliance.
Question 114: What is the main risk associated with 'shadow IT' (employees using unauthorized applications)?
- Uncontrolled data exposure and lack of IT governance (Correct answer)
- Increased paper usage
- Higher software licensing costs
- Slower internet speeds for the company
Correct answer: Uncontrolled data exposure and lack of IT governance
Shadow IT creates uncontrolled environments where data may be stored in unapproved tools without proper security or governance.
Question 115: How does due diligence apply to regulatory compliance?
- Thorough investigation and verification of all relevant facts and circumstances (Correct answer)
- A cursory review is sufficient
- Due diligence is optional
- Due diligence only applies to corporate transactions
Correct answer: Thorough investigation and verification of all relevant facts and circumstances
Due diligence requires thorough investigation and verification of all relevant facts to ensure competent and ethical practice.
Question 116: What regulatory compliance requirement applies to client relations?
- Full compliance with all applicable federal, state, and industry regulations (Correct answer)
- Regulations are optional for small practices
- Compliance is only needed for publicly traded companies
- Self-regulation is sufficient
Correct answer: Full compliance with all applicable federal, state, and industry regulations
Full regulatory compliance is mandatory regardless of practice size, ensuring market integrity and client protection.
Question 117: How should conflicts of interest be managed in portfolio management?
- Conflicts are unavoidable and need not be disclosed
- Identify, disclose, and mitigate all actual and potential conflicts of interest (Correct answer)
- Self-assessment of conflicts is sufficient
- Conflicts only matter in large transactions
Correct answer: Identify, disclose, and mitigate all actual and potential conflicts of interest
All actual and potential conflicts of interest must be identified, disclosed to clients, and mitigated to maintain trust and compliance.
Question 118: How should risk be assessed in estate planning?
- Use a one-size-fits-all risk profile
- Ignore risk for aggressive growth
- Risk assessment is only needed for retirees
- Evaluate risk tolerance, capacity, time horizon, and investment objectives systematically (Correct answer)
Correct answer: Evaluate risk tolerance, capacity, time horizon, and investment objectives systematically
Comprehensive risk assessment considers tolerance, capacity, time horizon, and objectives to create appropriate strategies.
Question 119: In IT audit, what does 'change management control' primarily prevent?
- Unauthorized or untested changes to production systems (Correct answer)
- Hardware failures in data centers
- Budget overruns on IT projects
- Phishing attacks on end users
Correct answer: Unauthorized or untested changes to production systems
Change management controls ensure all modifications to production systems are authorized, tested, and documented before deployment to prevent errors and unauthorized alterations.
Question 120: Which committee of the board of directors bears primary responsibility for overseeing the internal audit function?
- Audit Committee (Correct answer)
- Nominating Committee
- Compensation Committee
- Risk Committee
Correct answer: Audit Committee
The audit committee has primary board-level responsibility for overseeing financial reporting, internal controls, and the internal audit function.
Question 121: Which account type has a normal credit balance?
- Dividend
- Liability (Correct answer)
- Expense
- Asset
Correct answer: Liability
In accounting, a liability account has a normal credit balance because liabilities represent obligations owed to external parties, and they typically increase with a credit entry. Conversely, assets and expenses normally have debit balances, while equity and revenue also normally have credit balances. Understanding normal balances is fundamental to correctly recording transactions in the double-entry system.
Question 122: Which of the following best describes a 'data integrity' control in an accounting information system?
- Encrypting all transmitted data
- Ensuring data is accurate, complete, and unaltered throughout its lifecycle (Correct answer)
- Ensuring data is backed up daily
- Restricting user access to sensitive tables
Correct answer: Ensuring data is accurate, complete, and unaltered throughout its lifecycle
Data integrity controls ensure that information remains accurate, consistent, and unaltered from creation through storage and reporting.
Question 123: Which of the following best describes a 'data dictionary' in the context of IT general controls?
- A glossary of IT audit terms
- A list of approved software vendors
- A log of all database transactions
- A repository defining the structure, format, and relationships of data elements (Correct answer)
Correct answer: A repository defining the structure, format, and relationships of data elements
A data dictionary documents the definitions, formats, and relationships of data elements used across an organization's systems.
Question 124: Which fraud detection method relies on the statistical principle that in naturally occurring datasets, leading digits follow a predictable distribution?
- Regression testing
- Parallel simulation
- Stratified sampling
- Benford's Law (Correct answer)
Correct answer: Benford's Law
Benford's Law states that the digit 1 appears as the leading digit roughly 30% of the time in natural datasets, and deviations may indicate manipulation.
Question 125: What fiduciary duty applies to investment analysis?
- Follow the firm's sales targets above all
- Act in the client's best interest with loyalty, care, and full disclosure (Correct answer)
- Recommend the most expensive products
- Maximize the advisor's commission
Correct answer: Act in the client's best interest with loyalty, care, and full disclosure
Fiduciary duty requires acting in the client's best interest with loyalty, care, and full disclosure of all material facts.
Question 126: Confidentiality in accounting requires that professionals:
- Publish all data for internal transparency
- Discuss client details with peers
- Protect sensitive information unless required by law (Correct answer)
- Disclose all information for transparency
Correct answer: Protect sensitive information unless required by law
Confidentiality in accounting mandates that professionals protect sensitive client or employer information acquired during their work. This ethical obligation ensures trust and safeguards proprietary data, preventing unauthorized disclosure. Information should only be revealed when legally required or with proper authorization from the client or employer.
Question 127: Under IIA Standards, when an internal auditor discovers fraud during an audit, the auditor should first:
- Report findings to the audit committee or appropriate level of management (Correct answer)
- Close the audit and issue a clean opinion
- Terminate the engagement until legal counsel is retained
- Immediately confront the employee suspected of fraud
Correct answer: Report findings to the audit committee or appropriate level of management
When fraud is discovered, the internal auditor must escalate findings to senior management or the audit committee as required by IIA Standards.
Certified Internal Auditor (CIA) Exam
The CIA certification is the only globally recognized certification for internal auditors, demonstrating proficiency in internal audit principles and practices.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds