According to IIA guidance, which of the following is accurate regarding the chief audit executive's (CAE's) requirement to report the results of quality assessments? 1. The CAE must report the results of external assessments at least annually. 2. The CAE must report the results of ongoing monitoring at least annually. 3. The CAE must report the results of quality assessments to senior management. 4. The CAE must report the results of quality assessments to the board.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
According to IIA guidance, a new internal auditor is expected to possess which of the following competencies?
-
A
Technical industry-specific expertise.
-
B
Expertise in cybersecurity, an area of increasing risk.
-
C
Knowledge of IT risks and controls.
-
D
Knowledge of forensic accounting.
Reveal answer details
Close answer details
Which of the following is an example of a transaction-level control?
-
A
-
B
-
C
Reconciliations of primary accounts.
-
D
Reveal answer details
Close answer details
According to IIA guidance, which of the following corporate social responsibility (CSR) evaluation activities may be performed by the internal audit activity? 1. Consult on CSR program design and implementation. 2. Serve as an advisor on CSR governance and risk management. 3. Review third parties for contractual compliance with CSR terms. 4. Identify and mitigate risks to help meet the CSR program objectives.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which of the following engagements would be considered an appropriate consulting service?
-
A
The internal audit activity of a commercial bank routinely performs branch audits for compliance with regulations.
-
B
The internal audit activity participates in a cosourcing arrangement with an IT audit firm to test information systems security.
-
C
The internal audit activity facilitates biannual training of the risk management team in risk identification methodologies.
-
D
The internal audit activity partners with external auditors annually to complete fieldwork required as a part of the external audit exercise.
Reveal answer details
Close answer details
Which of the following controls would most likely prevent the input of an unreasonable number of labor hours into a costing system?
-
A
Recalculation tests during processing.
-
B
Programmed limit tests of input fields.
-
C
Reconciliation of input control totals.
-
D
Consistency checks of data in input fields.
Reveal answer details
Close answer details
An internal auditor pays to participate in the company's annual golf tournament, which is held outside of normal business hours. The auditor wins the putting contest and is awarded an all-expense-paid weekend vacation. According to the IIA Code of Ethics regarding objectivity, the auditor's best course of action would be to:
-
A
Refuse the prize because the amount is significant.
-
B
Accept the prize because the event was held outside of normal business hours.
-
C
Refuse the prize because it represents an impairment to objectivity.
-
D
Accept the prize because the auditor received no special treatment.
Reveal answer details
Close answer details
The results of an internal control questionnaire revealed that all investment activity exceeding $10,000 must be approved by the assistant treasurer. A sample of these transactions with a ve-percent acceptable error rate found that 98 of the 100 items tested included the assistant treasurer's approval. Based on this data, the auditor should:
-
A
Con rm all investment activity with the rm's broker since errors in approval had occurred.
-
B
Decide not to perform further testing of investment authorizations.
-
C
Contact the corporate finance department to verify all of the investments held.
-
D
Perform an analytical review of investment transactions in comparison with prior years to identify significant uctuations.
Reveal answer details
Close answer details
When planning an audit engagement, what should an internal auditor first consider when assessing the risk of fraud in the area to be audited?
-
A
Impact of and exposure to fraud.
-
B
Existence of evidence of fraud.
-
C
Organizational structure.
-
D
Management's risk appetite.
Reveal answer details
Close answer details
Question 10
Single choice
To identify those components of a telecommunications system that present the greatest risk, an internal auditor should first:
-
A
Review the open systems interconnect network model.
-
B
Identify the network operating costs.
-
C
Determine the business purpose of the network.
-
D
Map the network software and hardware products into their respective layers.
Reveal answer details
Close answer details
Question 11
Single choice
Which of the following must be included when reporting results of a quality assurance and improvement program?
-
A
The designated objectives of both internal and external assessments.
-
B
The risk acceptance for areas not in conformance with the Standards.
-
C
The qualifications and independence of the assessment team.
-
D
The methodological approach of conducting external assessments.
Reveal answer details
Close answer details
Question 12
Single choice
Which data analytics competency is critical for new internal auditors to possess in order to plan and perform internal audit engagements in conformance with the Standards?
-
A
Describe data analytics and the application of data analytics methods in internal auditing.
-
B
Apply data analytics methods in internal auditing.
-
C
Evaluate the use of data analytics in an internal audit.
-
D
Understand the definition of data analytics only.
Reveal answer details
Close answer details
Question 13
Single choice
The chief audit executive (CAE) wants to ensure that there are suficient resources available to fulfill the responsibilities of the internal audit activity in the coming year. Which statement describes the most logical sequence of events for the CAE to undertake in order to achieve this objective?
-
A
Con rm audit plan; confirm budget; review existing resources; identify outstanding resource requirements.
-
B
Review prior year audit plan; review existing resources; confirm new audit plan; confirm budget.
-
C
Con rm budget; review existing resources; obtain any new resources required; confirm new audit plan.
-
D
Review results of prior year audit plan; adjust current plan accordingly; hire required resources; confirm budget.
Reveal answer details
Close answer details
Question 14
Single choice
Which of the following best defines the role of internal auditing in risk management?
-
A
To own and manage all identified risks.
-
B
To provide assurance on the effectiveness of risk management processes.
-
C
To eliminate all operational risks.
-
D
To approve management's risk appetite.
Reveal answer details
Close answer details
Question 15
Single choice
An internal auditor is researching the laws and regulations related to a city's grant program. Which of the following procedures is least relevant to this task?
-
A
Making inquiries of the audit committee about the nature of the grants.
-
B
Reviewing prior-year workpapers and asking officials if there have been any changes.
-
C
Reviewing applicable grant agreements.
-
D
Discussing the matter with the city's chief financial officer, legal counsel, or grant administrators.
Reveal answer details
Close answer details
Question 16
Single choice
According to IIA guidance, which of the following must internal auditors consider to conform with the requirements for due professional care during a consulting engagement? 1. The cost of the engagement, as it pertains to audit time and expenses in relation to the potential benefits. 2. The needs and expectation of clients, including the nature, timing, and communication of engagement results. 3. The application of technology-based audit and other data analysis techniques, where appropriate. 4. The relative complexity and extent of work needed to achieve the engagement's objectives.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 17
Single choice
Senior management at a financial institution has received allegations of fraud at its derivatives trading desk and has asked the internal audit activity to investigate and issue a report concerning the allegations. The internal audit activity has not yet developed suficient proficiency regarding derivatives trading to conduct a thorough fraud investigation in this area. Which of the following courses of action should the chief audit executive (CAE) take to comply with the Standards?
-
A
Engage the former head of the institution's derivatives trading desk to perform the investigation and submit a report with supporting documentation to the CAE.
-
B
Request that senior management allow a delay of the fraud investigation until the internal audit activity's on-staff certified fraud examiner is able to obtain the appropriate training regarding the analysis of derivatives trading.
-
C
Request that senior management exclude the internal audit activity from the investigation completely and instead contract with an external certified fraud examiner with derivatives experience to perform all aspects of the investigation and subsequent reporting.
-
D
Contract with an external certified fraud examiner with derivatives experience to perform the investigation and subsequent reporting, with the chief audit
Reveal answer details
Close answer details
Question 18
Single choice
Which of the following is the primary concern of an internal auditor in a comprehensive audit of an organization?
-
A
Accuracy of reports on the source and use of funds.
-
B
Extent of achievement of the organization's mission.
-
C
Con rmation of compliance with policies and procedures.
-
D
Appropriateness of procedures related to the budgeting process.
Reveal answer details
Close answer details
Question 19
Single choice
Which of the following statements is true with regard to governance?
-
A
Governance activities support the organization's risk management framework.
-
B
Cultural risk factors can impede the operation of governance activities.
-
C
Internal control within an organization is supported by governance activities.
-
D
Governance activities are uniform for organizations in the same industry.
Reveal answer details
Close answer details
Question 20
Single choice
When can an internal audit activity use the statement, "Conforms with the International Standards for the Professional Practice of Internal Auditing"?
-
A
The internal audit activity has been in existence for four years; the results of the last three consecutive internal assessments have demonstrated general conformance with the Standards and Code of Ethics.
-
B
The internal audit activity has been in existence for 11 years; the results of the last external assessment, performed six years ago, demonstrated general conformance with the Standards and Code of Ethics.
-
C
The internal audit activity has been in existence for six years; although an external assessment has not yet been performed, the results of the last four consecutive internal assessments have demonstrated general conformance with the Standards and Code of Ethics.
-
D
The internal audit activity has been in existence for seven years; the results of the external assessment performed seven years ago and the last six consecutive internal assessments have demonstrated general conformance with the Standards and Code of Ethics.
Reveal answer details
Close answer details
Question 21
Single choice
Performing a monthly analysis of potential duplicate invoices paid to suppliers is an example of which type of fraud control?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 22
Single choice
The results of an assessment of the adequacy of controls would be considered incomplete or misleading unless the internal auditor considers which of the following?
-
A
Number of mitigating controls.
-
B
Effectiveness of the control environment.
-
C
Use of computer-assisted auditing techniques.
-
D
Reveal answer details
Close answer details
Question 23
Single choice
Which of the following topics would a chief audit executive most likely include with their report to the board?
-
A
The status of labor contract negotiations at the largest manufacturing plant.
-
B
A significant level of senior management turnover throughout the organization.
-
C
A recent management hire to oversee labor concerns.
-
D
Analyses of recent increases in overtime.
Reveal answer details
Close answer details
Question 24
Single choice
Which of the following are appropriate ways to obtain continuous professional education? 1. Instructing at a local IIA training event. 2. Attending internal audit conferences and seminars. 3. Practicing specialized audit and consulting work. 4. Participating in research projects in internal auditing.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 25
Single choice
An internal auditor found that his organization did not make a disclosure that is required by law. However, the auditor decided not to raise an audit finding. Which of the following Code of Ethics principles was violated?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 26
Single choice
An internal auditor conducted a surprise inventory count at a warehouse of a small subsidiary. By the end of the count, it became apparent that a few items from several categories were missing. The warehouse manager explained that he took those items for personal needs, and he said that he would provide information about other employees' wrongdoings to avoid being reported. The auditor agreed not to report the issue, which ultimately enabled her to uncover more significant losses. Which of the following statements is true regarding this situation?
-
A
This scenario demonstrates an impairment to audit independence.
-
B
The auditor acted in accordance with the definition of Internal Auditing, adding value to the organization.
-
C
The auditor demonstrated due professional care and cost-benefit considerations.
-
D
The auditor appears to lack personal integrity.
Reveal answer details
Close answer details
Question 27
Single choice
In its five years of existence, an internal audit activity conducted a single internal assessment of its quality assurance and improvement program (QAIP). The results of that assessment showed that the internal audit activity did not conform with the Standards. Prior to this, an external assessment of the internal audit activity's QAIP was conducted, which reported that the internal audit activity was in conformance with the Standards. Considering the two assessments, what would be the internal audit activity's current state of conformance with the Standards?
-
A
Conformance with the Standards.
-
B
Nonconformance with the Standards.
-
C
Unable to determine conformance with the Standards.
-
D
Partial conformance with the Standards.
Reveal answer details
Close answer details
Question 28
Single choice
A large trucking organization wants to reduce traffic accidents by improving its system of internal controls. Which of the following controls is correctly classified? 1. Review of speeding violations to identify repetitive locations and drivers is an example of a preventive control. 2. Defensive driver training is an example of a directive control. 3. The installation of tracking devices in delivery vehicles is an example of a corrective control. 4. Providing a vehicle driver handbook is an example of a detective control.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 29
Single choice
The main reason to establish internal controls in an organization is to:
-
A
Encourage compliance with policies and procedures.
-
B
Safeguard the resources of the organization.
-
C
Ensure the accuracy, reliability, and timeliness of information.
-
D
Provide reasonable assurance on the achievement of objectives.
Reveal answer details
Close answer details
Question 30
Single choice
Which of the following methods is not valid for completing continuing professional education hours?
-
A
Attending technical session meetings held by state auditing organizations.
-
B
Completing all audit engagements in accordance with the Standards.
-
C
Publishing an article on the organization's internal audit department.
-
D
Participating in a formal in-house training program.
Reveal answer details
Close answer details
Question 31
Single choice
Which of the following statements pertaining to the relationship between independence and objectivity is accurate?
-
A
Independence and objectivity are directly related, and they essentially mean the same thing.
-
B
If the internal audit activity is not independent, the internal auditor cannot be objective.
-
C
It is easier to measure and implement safeguards to ensure objectivity than it is to ensure independence.
-
D
Independence generally relates to conditions that limit the internal auditor's performance, and objectivity relates to a state of mind.
Reveal answer details
Close answer details
Question 32
Single choice
With regard to governance, which of the following is a board-level responsibility rather than a management responsibility?
-
A
Obtaining assurance on external nancial, regulatory, and internal audits.
-
B
Complying with laws, regulations, and codes.
-
C
Assigning authority and responsibilities organizationwide.
-
D
Monitoring and measuring performance.
Reveal answer details
Close answer details
Question 33
Single choice
Which of the following is a second line of defense in effective risk management and control?
-
A
-
B
-
C
-
D
Internal audit department.
Reveal answer details
Close answer details
Question 34
Single choice
Which of the following describes a control weakness?
-
A
Purchasing procedures are well designed and are followed unless otherwise directed by the purchasing supervisor.
-
B
Pre-numbered blank purchase orders are secured within the purchasing department.
-
C
Normal operational purchases fall in the range from $500 to $1,000 with two signatures required for purchases over $1,000.
-
D
The purchasing agent invests in a publicly traded mutual fund that lists the stock of one of the company's suppliers in its portfolio.
Reveal answer details
Close answer details
Question 35
Single choice
During a monthly internal audit staff meeting, the chief audit executive (CAE) decided to reinforce the importance of internal audit staff being objective in their work. Which of the following examples would be most appropriate for the CAE to include as part of the meeting presentation?
-
A
Statistical sampling techniques should always be used to pull unbiased sampling for testing.
-
B
Fieldwork completed by internal auditors should be appropriately reviewed.
-
C
Internal auditors should avoid using the lunch room simultaneously with audit clients.
-
D
During the audit review period, there should be no nonaudit dialogues with the audit client.
Reveal answer details
Close answer details
Question 36
Single choice
Which of the following would be a violation of the IIA Code of Ethics?
-
A
Reporting information that could be damaging to the organization, at the request of a court of law.
-
B
Including an issue in the final audit report after management has resolved the issue.
-
C
Participating in an audit engagement for which the auditor does not have the necessary experience or training.
-
D
Accepting a gift that is a commercial advertisement available to the public.
Reveal answer details
Close answer details
Question 37
Single choice
Which of the following is a limitation of internal controls?
-
A
Controls can prevent all human error.
-
B
Controls are designed to detect every instance of fraud.
-
C
Controls may be overridden by management.
-
D
Controls eliminate the need for external audits.
Reveal answer details
Close answer details
Question 38
Single choice
An employee is more likely to commit fraud if which of the following red flags are present? 1. The employee believes that he is being underpaid and deserves a higher salary. 2. The employee is close to retirement and has expressed a desire to take an expensive trip around the world. 3. The employee has personal financial problems and seems very unhappy. 4. The employee is spending much more time at the office than usual and has been asking about opportunities for professional advancement.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 39
Single choice
The chief audit executive (CAE) is drafting the annual internal audit plan and seeks input from senior management and the external auditor prior to submitting it for approval to the board. According to IIA guidance, which of the following statements is true regarding this scenario?
-
A
The CAE's actions are likely to impair the independence of the internal audit activity.
-
B
The CAE acted appropriately, and the independence of the internal audit activity was not impaired.
-
C
The CAE should have developed the audit plan without outside influence to maintain objectivity.
-
D
The CAE acted appropriately, as he has authority to determine who reviews and approves the audit plan.
Reveal answer details
Close answer details
Question 40
Single choice
Which of the following is the primary advantage of using a computer assisted audit technique (CAAT) to provide a higher level of assurance?
-
A
CAATs can select an appropriate sample size for testing and thus provide higher level of assurance.
-
B
CAATs are more objective than the traditional methods in interpreting the results.
-
C
CAATs can examine the whole of population of transactions, rather than a sample, in order to identify exceptions and trends.
-
D
CAATs can process the results faster and thus give a higher level of assurance.
Reveal answer details
Close answer details
Question 41
Single choice
According to IIA guidance, which of the following components must be included in the annual report to the board on the quality assurance and improvement program?
-
A
Results from the assessment and the current status of resulting action plans.
-
B
Disclosure of nonconformance that impacts the overall operation of the internal audit activity.
-
C
Audit clients' feedback and recommendations for quality improvement.
-
D
A statement of compliance with the Code of Ethics, Standards, and definition of Internal Auditing.
Reveal answer details
Close answer details
Question 42
Single choice
Which of the following is an appropriate role for the board in governance?
-
A
Preparing written organizational policies that relate to compliance with laws, regulations, ethics, and conflicts of interest.
-
B
Ensuring that financial statements are understandable, transparent, and reliable.
-
C
Assisting the internal audit activity in performing annual reviews of governance.
-
D
Working with the organization's attorneys to develop a strategy regarding current litigation, pending litigation, or regulatory proceedings governance.
Reveal answer details
Close answer details
Question 43
Single choice
Which of the following organizations has an impairment to internal audit independence?
-
A
An organization where the chief audit executive (CAE) reports administratively to the CEO, who is the highest officer within the organization.
-
B
An organization in which the CAE reports functionally to the board, which is the governing body for the organization.
-
C
An organization where the chief financial officer, who is a high-ranking executive, is responsible for approving the internal audit budget.
-
D
An organization where the CAE is a member of the executive management team.
Reveal answer details
Close answer details
Question 44
Single choice
A senior executive at a government-owned organization received an invitation to attend a public exhibition where he can learn about new trucks relevant to the organization's business. As a special perk, the executive is offered an opportunity to drive a luxury vehicle manufactured by one of the exhibiting companies. Prior to the event, the executive asked for the chief audit executive's (CAE's) advice. What should the CAE recommend as the most appropriate course of action for the executive?
-
A
Attend the event, but decline the offer to use the luxury vehicle.
-
B
Decline the invitation to the exhibition.
-
C
Ask the board to decide on the issue.
-
D
Select a lower-level employee to enjoy the luxury vehicle instead.
Reveal answer details
Close answer details
Question 45
Single choice
Which of the following best supports the internal audit activity's role in evaluating governance?
-
A
Assessing whether the board promotes appropriate ethics and values.
-
B
Preparing the organization's code of conduct.
-
C
Managing all enterprise risk activities.
-
D
Conducting all investigations of employee misconduct.
Reveal answer details
Close answer details
Question 46
Single choice
In order to provide the most useful information for an organization's risk management decisions, which of the following should be assessed?
-
A
Risk levels for future events based on the degree of uncertainty of those events and their cost of mitigation.
-
B
Inherent and control risks and their impact on the extent of financial misstatements.
-
C
Risk levels of current and future events, their effect on the achievement of the organization's objectives, and their underlying causes.
-
D
Risk levels of current and future events, their impact on the organization's mission, and the potential for the elimination of existing risk factors.
Reveal answer details
Close answer details
Question 47
Single choice
Which of the following should be incorporated in a risk management policy? I- Boundaries and limit structures. II-. Requirements for reporting risk. III-. Risk authorities.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 48
Single choice
Which of the following most accurately describes corporate social responsibility at an organization?
-
A
An organizational focus on improving the overall environment, even if it is to the detriment of the local community.
-
B
A philosophy driven by employees that flows up to senior management and the board of directors.
-
C
An overall commitment of the organization to improve the quality of life for not only the employees but the community at large.
-
D
A policy of ensuring that the organization is socially responsible, even if it leads to unprofitability due to increased costs.
Reveal answer details
Close answer details
Question 49
Single choice
An auditor identifies three errors in the sample of 25 entries selected for review (a 12 percent error rate). Based on this result, the auditor assumes that approximately 59 of the total population of 492 entries are incorrect. To reach this assumption, the auditor has used a technique known as which of the following?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 50
Single choice
If earnings on financial statements for internal use only have been manipulated in the past, an internal auditor is likely to focus on which of the following?
-
A
The proper accrual of payables at the end of the interim period.
-
B
The timing of revenue recognition and the valuation of inventories.
-
C
Whether accounting estimates are reasonable given past actual results.
-
D
Whether there have been changes in accounting principles that materially affect the financial statements.
Reveal answer details
Close answer details
Question 51
Single choice
An organization's chief audit executive (CAE) has been asked to conduct an assurance engagement for an information technology system that was subject to a consulting engagement in the prior year. How should the CAE respond?
-
A
Decline the engagement because independence and objectivity would be impaired.
-
B
Delay the assurance engagement to ensure that there is a two-year period between the engagements.
-
C
Accept the engagement and assign different auditors to conduct the assurance services.
-
D
Facilitate a control self-assessment workshop instead of performing an assurance engagement.
Reveal answer details
Close answer details
Question 52
Single choice
An organization's project managers regularly travel to various destinations. Although plane tickets and accommodations are booked and paid for by the organization, project managers can still submit for reimbursement any travel-related receipts for transportation, dining, and other miscellaneous costs. Which of the following fraud schemes should the auditor test for?
-
A
Multiple and overstated expenses.
-
B
Unauthorized expenditures.
-
C
Improper period recognition of expenses.
-
D
Concealed liabilities and expenses.
Reveal answer details
Close answer details
Question 53
Single choice
Which of the following is not an appropriate type of coordination between the internal audit activity and regulatory auditors?
-
A
Regulatory auditors share their perspective on risk management, control, and governance with the internal auditors.
-
B
Internal auditors perform fieldwork at the direction of the regulatory auditors.
-
C
Internal auditors review copies of regulatory reports in planning related internal engagements.
-
D
Regulatory and internal auditors exchange information about planned activities.
Reveal answer details
Close answer details
Question 54
Single choice
Prior to commencing a financial compliance engagement, the engagement supervisor reads the business plan for the finance department and meets informally with the director to learn more about any key issues. Which of the following competencies is the engagement supervisor demonstrating?
-
A
The ability to inspire trust.
-
B
The ability to communicate effectively.
-
C
The ability to display courage.
-
D
The ability to understand the needs of stakeholders.
Reveal answer details
Close answer details
Question 55
Single choice
Which of the following best describes the expectation for internal auditors to demonstrate due professional care when performing their work?
-
A
Internal auditors consider the possibility of fraud during all assurance engagements.
-
B
Internal auditors ensure that any risks within the engagement scope are identified.
-
C
Internal auditors provide absolute assurance to senior management and the board.
-
D
Internal auditors mitigate risks to a level deemed acceptable by the organization.
Reveal answer details
Close answer details
Question 56
Single choice
Which of the following decisions made during the testing phase of a compliance audit requires the most judgment by an internal auditor?
-
A
Which sampling methodology to select for testing.
-
B
Which fields to examine on each invoice.
-
C
Whether an individual expenditure is allowable.
-
D
What level of noncompliance is acceptable.
Reveal answer details
Close answer details
Question 57
Single choice
According to IIA guidance, the chief audit executive, board, and senior management must mutually agree on which of the following?
-
A
Internal audit activity objectives and responsibilities.
-
B
Audit engagements to be performed during the year.
-
C
The items selected for detailed audit testing.
-
D
staffing of the internal audit activity.
Reveal answer details
Close answer details
Question 58
Single choice
Under which of the following circumstances should the final audit report include a disclosure of nonconformance with the Standards?
-
A
An external quality assessment of the internal audit activity is performed only once every five years.
-
B
The internal auditor provided negative assurance, because he found no evidence of misconduct.
-
C
The annual internal audit plan includes some consulting engagements that are based on opportunities rather than risks to the organization.
-
D
A new internal auditor moved into the internal audit activity from the payroll department and was immediately assigned to the payroll audit.
Reveal answer details
Close answer details
Question 59
Single choice
During an account receivables audit, an internal auditor found a significant number of input errors resulting in a $500,000 balance understatement. Which of the following is the most important question the internal auditor should ask to develop an appropriate recommendation for this finding?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 60
Single choice
When performing an audit of the risk management process an auditor makes the observations listed below. Which poses the greatest risk to the organization?
-
A
The identified risks have not undergone a detailed review to ensure completeness in the past two years.
-
B
The controls in place to mitigate the risks are not tested on an annual basis to confirm operating effectiveness.
-
C
The process in place to identify and evaluate new risks to the organization is informal and poorly documented.
-
D
The identified risks have not been ranked to establish their importance and risk management priority.
Reveal answer details
Close answer details
Question 61
Single choice
An organization is considering purchasing a new banking software system and has asked the internal audit activity to evaluate the system. An internal auditor assigned to perform the engagement worked at the software company two years ago and is familiar with the system's design strengths and weaknesses. Which of the following is true regarding impairment to the auditor's objectivity?
-
A
This situation does not necessitate any action related to the auditor's objectivity.
-
B
The auditor should decline to perform the audit because personal conflicts of interest are likely.
-
C
The auditor must disclose to the chief audit executive that this situation may impair her objectivity.
-
D
The auditor can provide only consulting services, not assurance.
Reveal answer details
Close answer details
Question 62
Single choice
A manufacturer uses a materials requirements planning (MRP) system to track inventory, orders, and raw materials requirements. What condition should an auditor search for in the MRP database if a preliminary assessment indicated that inventory is understated? I- Item cost set at zero. II-. Negative quantities on hand. III-. Order quantity exceeding requirements. IV-. Inventory lead times exceeding delivery schedule.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 63
Single choice
What is the primary purpose of a risk management program?
-
A
Reduce risk to a tolerable level.
-
B
Reduce all risks regardless of costs.
-
C
Transfer all risks to external third parties.
-
D
Identify every significant risk to avoid it.
Reveal answer details
Close answer details
Question 64
Single choice
Which of the following best demonstrates organizational independence of the internal audit activity?
-
A
The chief audit executive (CAE) reports functionally to the CEO.
-
B
The CAE's compensation is approved by the chief financial officer.
-
C
The CAE's appointment is determined by the CEO.
-
D
The CAE reports administratively to the chief operating officer.
Reveal answer details
Close answer details
Question 65
Single choice
During a review of data center physical security and environmental controls, an auditor should ensure that: I- Visitors are accompanied by authorized personnel at all times. II-. Only developers and operators have access to the data center. III-. Fire suppression equipment is tested periodically. IV-. Fire and water detectors have been installed.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 66
Single choice
The internal auditor of a small manufacturer noted that the accounting department has insufficient staff to achieve proper segregation of duties. What type of controls would the auditor likely recommend to management to specifically address this problem?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 67
Single choice
An internal auditor must determine which components of an organization's telecommunications may introduce the greatest risk. Which of the following tasks should the internal auditor complete first?
-
A
Review the open systems interconnect network model.
-
B
Identify the network operating costs.
-
C
Map the network software and hardware products into their respective layers.
-
D
Ascertain the business purpose of the network.
Reveal answer details
Close answer details
Question 68
Single choice
A newly hired internal auditor is most likely to need further education in the area of business acumen in which of the following situations?
-
A
She was transferred from the managerial accounting department of the same organization.
-
B
She was recruited from the internal audit activity of another organization that operates in a different industry.
-
C
She was offered a permanent position after she had worked with the organization for two years in a temporary auditor-in-training position.
-
D
She previously served on the organization's external audit team and was recruited to the internal audit activity following the current year's financial audit.
Reveal answer details
Close answer details
Question 69
Single choice
Which of the following circumstances would most likely be considered a potential red flag for fraud by the internal audit activity?
-
A
The monthly payroll reports are not vetted to ensure terminated employees have been removed from the payroll system.
-
B
The volume of nonroutine journal entries has steadily increased over time.
-
C
The database of approved suppliers has not been reviewed in the last year.
-
D
The recent employee survey indicates that some employees remain unaware of the organization's whistleblower hotline.
Reveal answer details
Close answer details
Question 70
Single choice
An organization purchases an insurance policy against re. Which of the following risk management techniques does this exemplify?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 71
Single choice
Which of the following statements, if true, could justify an auditor's decision not to report governance-related control defficiencies to the audit committee?
-
A
Management plans to initiate corrective action.
-
B
The board of directors has a separate corporate governance committee.
-
C
The amounts and the potential risks associated with the defficiencies are not material to the overall organization.
-
D
Governance issues are complex and the auditor should rely on management's analysis of the extent of the problem.
Reveal answer details
Close answer details
Question 72
Single choice
In which of the following ways can a whistleblower hotline serve as a preventative control?
-
A
Third parties who operate the hotline ensure anonymity for whistleblowers.
-
B
Whistleblower tips help discover wrongdoings and violations of the code of conduct.
-
C
Potential perpetrators of fraud know that their actions can be reported easily.
-
D
Better investigation protocols are triggered by the whistleblower hotline.
Reveal answer details
Close answer details
Question 73
Single choice
An internal audit charter should do which of the following?
-
A
Outline the schedule of future audits.
-
B
Define the scope of internal audit activities.
-
C
Establish the size of the internal audit activity.
-
D
Communicate the internal audit activity's goals.
Reveal answer details
Close answer details
Question 74
Single choice
According to IIA guidance, which of the following is not a responsibility of the chief audit executive pertaining to documenting information to support internal audit engagement results and conclusions?
-
A
Rating each engagement record to assess its relevance and accessibility for the organization's board.
-
B
Controlling access to engagement records, including access by senior management.
-
C
Developing retention requirements for engagement records that are consistent with organizational guidelines.
-
D
Forming policies governing the custody and retention of consulting engagement records before their release to other parties.
Reveal answer details
Close answer details
Question 75
Single choice
A daily log of treasury dealers who exceeded their authorized limits serves as a:
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 76
Single choice
In preparing for an audit of the footwear division of a major retail organization, an internal auditor gathered the following information about the organization's stores:  In addition to labor costs, the other costs associated with each store are leasing and maintenance expenses. Which of the following is a valid conclusion?
-
A
Sales per store are directly related to the size of the store.
-
B
Employees are less productive in larger stores.
-
C
Gross margin is directly related to the size of the store.
-
D
Cost of goods sold is directly related to the size of the store.
Reveal answer details
Close answer details
Question 77
Single choice
A manufacturing organization receives all direct materials for nished goods production. Which of the following is the strongest preventive control for lapses in quality assurance?
-
A
Identifying and rejecting completed products that are not up to quality and standard specifications.
-
B
Electronically measuring the materials and components according to specifications prior to manufacturing.
-
C
Examining partially assembled nished products to ensure that the manufacturing process is working correctly.
-
D
Manually inspecting received supplier materials to ensure appropriate quantities and quality.
Reveal answer details
Close answer details
Question 78
Single choice
Which of the following is not a benefit of using information technology in solving audit problems?
-
A
It helps reduce audit risk.
-
B
It improves the timeliness of the audit engagement.
-
C
It increases audit opportunities.
-
D
It improves the auditor's judgment.
Reveal answer details
Close answer details
Question 79
Single choice
Which of the following risk assessment tools would best facilitate the matching of controls to risks?
-
A
-
B
Internal control questionnaire.
-
C
-
D
Program evaluation and review technique (PERT) analysis.
Reveal answer details
Close answer details
Question 80
Single choice
Once the cause of a problem has been identified, the next step is to:
-
A
-
B
Generate alternative solutions.
-
C
-
D
Consider the reaction of competitors to various courses of action.
Reveal answer details
Close answer details
Question 81
Single choice
An internal auditor assessed the controls within his organization's payroll process and suspects that erroneous payments may have been made to a fraudulent bank account. What is the best course of action for the auditor to take?
-
A
Speak to the payroll manager so he may investigate the auditor's observations.
-
B
Continue to investigate the payments to confirm the accuracy of the observations, and determine whether further fraudulent payments have been made.
-
C
Stop the audit and report the findings to senior management immediately.
-
D
Escalate the concern to the engagement supervisor.
Reveal answer details
Close answer details
Question 82
Single choice
During an audit of the purchasing department, an internal auditor identifies significant issues that could affect the organization's financial reporting. Management disagrees with the audit results. Which of the following responses best demonstrates the internal auditor has the necessary competencies related to professional judgement and conflict management?
-
A
The auditor maintains his convictions and continues to proceed with the review process despite management's concerns related to the results.
-
B
The auditor bypasses management, discusses the results with the board, and seeks the board's input on how best to address the recommendations.
-
C
The auditor consults with other members of the audit team, and together they develop alternative recommendations that management may be more likely to accept.
-
D
The auditor meets with management to discuss the results and obtain a better understanding of the specific concerns.
Reveal answer details
Close answer details
Question 83
Single choice
A high-volume retailer of consumer goods has used point-of-sale data to record sales and update inventory records for several years. When price changes are scheduled, corporate headquarters downloads a price change file to a computer server system at each store. Each store's assistant manager is responsible for checking the server for downloads and running the program that updates the store's price file at the authorized price update time. In comparison with having headquarters initiate the price update centrally, this approach to price updating will most likely:
-
A
Decrease the risk that customers will be undercharged consistently for sales items.
-
B
Decrease the risk that item prices will sometimes be inaccurate.
-
C
Increase the risk that customers will be undercharged consistently for sales items.
-
D
Increase the risk that item prices will sometimes be inaccurate.
Reveal answer details
Close answer details
Question 84
Single choice
A chief audit executive (CAE) identifies that the internal audit activity lacks a necessary skill to perform a management request for a consulting engagement. According to IIA guidance, which of the following is the most appropriate action the CAE should take regarding the request?
-
A
Assign the engagement to a more senior internal auditor.
-
B
Decline the engagement request.
-
C
Allow the internal auditors to acquire the needed skills while performing the engagement.
-
D
Supervise the assigned internal auditors throughout the engagement.
Reveal answer details
Close answer details
Question 85
Single choice
The internal audit activity conducted an organizationwide risk assessment. One of the most significant risks identified is associated with the oil price market. The chief audit executive (CAE) is considering including in the annual audit plan an assessment of the effectiveness of oil price risk management. The manager responsible commented that the assessment was not needed, as market risks were regularly addressed by the financial risk committee. If the CAE decides to include this activity in the annual audit plan anyway, how should it be recorded?
-
A
A consulting engagement independent of the financial risk committee's review.
-
B
-
C
-
D
A joint consulting engagement with input from the financial risk committee.
Reveal answer details
Close answer details
Question 86
Single choice
According to the IIA Code of Ethics, the deliberate omission of relevant information from an audit report would violate which principle?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 87
Single choice
Which of the following would constitute an effort of an organization's corporate social responsibility initiative?
-
A
Implementing a procurement policy requiring all new vehicle purchases to meet fuel efficiency requirements.
-
B
Requiring administrators to use dual-factor authentication to access the organization's social media accounts.
-
C
Hosting an annual conference for employees, customers, and other industry stakeholders to receive continuing professional education and network.
-
D
Upgrading employee laptops to increase processing speed and data storage.
Reveal answer details
Close answer details
Question 88
Single choice
The chief audit executive for an organization has just completed a risk assessment process, identified the areas with the highest risk, and assigned an audit priority to each. Which of the following statements is true and consistent with the International Professional Practices Framework? I- Items should be ranked in the order of quanti able dollar exposure to the organization. II-. The audit priorities should be in order of major control defficiencies. III-. The risk assessment, though quanti ed, is the result of professional judgments about both exposures and probability of occurrences.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 89
Single choice
Which of the following factors is not likely to affect the level of inherent risk associated with an application system?
-
A
-
B
Controls over the system appear reliable.
-
C
The system is not a critical operating system.
-
D
The system uses complex technology.
Reveal answer details
Close answer details
Question 90
Single choice
Which of the following is a valid statement about the use of visual observations during an audit engagement? 1. Visual observations can be used to detect ineffective controls, idle resources, and safety hazards. 2. Visual observations can be used during both preliminary survey and fieldwork stages of the audit engagement. 3. Visual observations can provide unsubstantiated facts to management if the internal auditor believes the information is useful. 4. Visual observations can assist an auditor in determining if a material observation should be communicated through informal means to the organizations senior management.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 91
Single choice
An internal audit of an organization's disbursement department revealed that multiple payments were made to legitimate vendors bearing fraudulent banking information belonging to employees in the department. These vendors were initially set up with accurate banking information but were subsequently modified by disbursement officers with access to the vendor management system. Which of the following controls would have likely prevented the fraudulent modi cation of vendors' banking information?
-
A
Management periodically reviews and veri es the information in the vendor master file.
-
B
Management's approval is required for update to vendors' banking information.
-
C
Management randomly audits a sample of payments to verify the accuracy of vendors' banking information.
-
D
Management's approval is required before payments can be processed.
Reveal answer details
Close answer details
Question 92
Single choice
The organization implements several controls to address the risk that employees might submit false claims for travelling expenses. The controls include requiring claims to be approved by a direct supervisor, providing clear guidance regarding which expenses can be included, automatic calculations of daily allowance, and notifying employees that the submission of false claims will be investigated. Which of the described controls is irrelevant to the risk?
-
A
The requirement of a supervisor's approval.
-
B
The availability of clear guidance.
-
C
The investigations into false claims.
-
D
The automatic calculations of daily allowance.
Reveal answer details
Close answer details
Question 93
Single choice
Once an organization's risks are identified, what would be the next step to ensure resources are properly allocated to manage those risks?
-
A
Risk responses must be selected.
-
B
-
C
The risk universe must be established.
-
D
Risk responses must be aligned.
Reveal answer details
Close answer details
Question 94
Single choice
Which of the following would not be a factor for senior management to consider when determining the internal audit activity's role in an organization's risk management process?
-
A
The extent to which the internal audit activity is outsourced.
-
B
The maturity level of risk management practices in the organization.
-
C
The competency of the internal auditors in risk management.
-
D
The nature of the business and the environment in which the organization operates.
Reveal answer details
Close answer details
Question 95
Single choice
A chief audit executive (CAE) has been asked by the board to evaluate the effectiveness of ethical programs created by management. Which of the following would be the most appropriate action for the CAE to take?
-
A
Compare the design of the organization's ethical programs with best practices.
-
B
Verify that a code of conduct and related policies exist and are communicated.
-
C
Use employee surveys to assess whether ethical programs are achieving desired outcomes.
-
D
Compare the cost of the ethical programs with the achieved outcomes.
Reveal answer details
Close answer details
Question 96
Single choice
According to IIA guidance, which of the following is an area in which the internal auditor should be proficient?
-
A
-
B
Computerized information systems.
-
C
Internal audit standards, procedures, and techniques.
-
D
Fundamentals of accounting, economics, and nance.
Reveal answer details
Close answer details
Question 97
Single choice
Internal auditors are preparing for an engagement to evaluate an organization's plan to accept cryptocurrency as a form of payment. Which of the following would demonstrate the internal auditors' business acumen in this scenario?
-
A
Auditors attended a seminar on mitigating risks related to blockchain.
-
B
Auditors coordinated their engagement work with department managers.
-
C
Auditors are available to provide consulting services to departments.
-
D
Auditors attended critical thinking seminars.
Reveal answer details
Close answer details
Question 98
Single choice
A chief audit executive (CAE) was asked by senior management to establish and manage a risk management function. A new chief risk officer was hired a year later to assume these responsibilities. As this function was included in the current annual audit plan, the CAE engaged an external resource for a risk management engagement. Which of the following potential threats to objectivity was the CAE likely addressing?
-
A
-
B
-
C
-
D
Personal relationship threat.
Reveal answer details
Close answer details
Question 99
Single choice
What type of risk management strategy is being employed when an organization installs two rewalls to provide protection from unauthorized access to the network?
-
A
Diversifying the risk that network access will not be available to legitimate, authorized users.
-
B
Accepting the risk that there may be attempts at unauthorized access to the network.
-
C
Avoiding the risk of having a direct network connection to un-trusted networks.
-
D
Sharing the risk that either rewall could be compromised by hackers.
Reveal answer details
Close answer details
Question 100
Single choice
Which of the following statements is true regarding globally recognized internal control frameworks?
-
A
Responsibility for internal control lies with each individual in the organization.
-
B
Responsibility for internal control lies only with the risk manager of the organization.
-
C
Responsibility for internal control lies only with the internal auditors of the organization.
-
D
Responsibility for internal control lies only with the board of the organization.
Reveal answer details
Close answer details
|