Which of the following is an indicator of liquidity that is more dependable than working capital?
A. Acid-test (quick) ratio
B. Average collection period
C. Current ratio.
D. Inventory turnover.
Explanation:
Working capital (current assets minus current liabilities) is an absolute dollar amount that does not account for the composition of current assets. It can be misleading because it includes inventory and prepaid expenses, which may not be quickly convertible to cash. The acid-test (quick) ratio is a more dependable indicator of liquidity because it excludes inventory and prepaids, focusing only on cash, marketable securities, and accounts receivable—the most liquid assets that can be used to meet short-term obligations immediately. This ratio provides a stricter, more conservative measure of an organization's ability to pay its current liabilities without relying on the sale of inventory.
Why the other options are incorrect:
B. Average collection period. This measures how quickly receivables are collected. While useful for cash flow analysis, it does not provide a comprehensive liquidity snapshot like the acid-test ratio.
C. Current ratio. The current ratio (current assets ÷ current liabilities) is similar to working capital but is a ratio rather than a dollar amount. However, it still includes inventory and prepaids, making it less dependable than the quick ratio for immediate liquidity assessment.
D. Inventory turnover. This measures how efficiently inventory is sold and replaced. It is an operational efficiency metric, not a direct measure of liquidity.
References:
CIA Part 3 Syllabus – Financial Management / Liquidity Ratios: Tests the candidate's understanding that the acid-test (quick) ratio is a more conservative liquidity measure than the current ratio because it excludes inventory.
Financial Analysis Textbooks (Ross, Brigham): The quick ratio is a more dependable indicator of short-term liquidity as it focuses on the most liquid assets.
An internal auditor found the following information while reviewing the monthly financial
siatements for a wholesaler of safety

The cost of goods sold was reported at $8,500. Which of the following inventory methods
was used to derive this value?
A. Average cost method
B. First-in, first-out (FIFO) method
C. Specific identification method
D. Activity-based costing method
Explanation:
To determine which inventory method was used, we calculate the Cost of Goods Sold (COGS) under each method and compare it to the reported $8,500.
Given Data:
Opening Inventory: 1,000 units @ $2 = $2,000
Purchases: 5,000 units @ $3 = $15,000
Total Available: 6,000 units @ Total Cost = $17,000
Units Sold: 3,000 units
Average Cost Method:
Weighted Average Cost = $17,000 ÷ 6,000 = $2.8333 per unit
COGS = 3,000 × $2.8333 = **$8,500** ✅
FIFO (First-In, First-Out):
COGS = (1,000 × $2) + (2,000 × $3) = $2,000 + $6,000 = $8,000 ❌
LIFO (Last-In, First-Out):
COGS = 3,000 × $3 = **$9,000** ❌
Since the reported COGS of $8,500 exactly matches the Average Cost method calculation, the wholesaler used the average cost method.
Why the other options are incorrect:
B. FIFO method. FIFO yields $8,000, not $8,500.
C. Specific identification method.
This requires tracking the actual cost of each individual item sold, which cannot be determined from the aggregate data provided.
D. Activity-based costing method.
ABC is a method for allocating overhead costs to products or services, not an inventory costing method for determining COGS.
References:
GAAP – ASC 330 (Inventory): Recognizes average cost, FIFO, LIFO, and specific identification as acceptable inventory costing methods.
CIA Part 3 Syllabus – Financial Management / Inventory Valuation: Tests the candidate's ability to calculate COGS using different inventory methods and identify the method used based on reported figures.
A retail organization mistakenly did have include $10,000 of Inventory in the physical count at the end of the year. What was the impact to the organization's financial statements?
A. Cost of sales and net income are understated.
B. Cost of sales and net income are overstated.
C. Cost of sales is understated and not income is overstated.
D. Cost of sales is overstated and net Income is understated.
Explanation:
When ending inventory is understated (i.e., $10,000 of inventory is not included in the physical count), the Cost of Goods Sold (COGS) is overstated. This is because COGS is calculated as:
COGS = Beginning Inventory + Purchases – Ending Inventory
If Ending Inventory is too low, the subtraction is smaller, making COGS higher (overstated). Higher COGS directly reduces gross profit, which in turn reduces net income. Therefore, net income becomes understated.
This is a classic accounting error with a direct and inverse relationship: understated ending inventory → overstated COGS → understated net income.
Why the other options are incorrect:
A. Cost of sales and net income are understated. This would occur if ending inventory were overstated, not understated.
B. Cost of sales and net income are overstated. This is the opposite of the correct effect. Overstated ending inventory would overstate net income and understate COGS.
C. Cost of sales is understated and net income is overstated. This also describes the effect of an overstated ending inventory, not an understated one.
References:
GAAP – ASC 330 (Inventory): Inventory errors have a direct impact on COGS and net income. An understatement of ending inventory causes COGS to be overstated and net income to be understated.
CIA Part 3 Syllabus – Financial Management / Inventory Errors: Tests the candidate's understanding of the ripple effect of inventory misstatements on financial statements.
Which of the following statements. Is most accurate concerning the management and audit of a web server?
A. The file transfer protocol (FTP) should always be enabled.
B. The simple mail transfer protocol (SMTP) should be operating under the most privileged accounts.
C. The number of ports and protocols allowed to access the web server should be maximized.
D. Secure protocols for confidential pages should be used instead of dear-text protocols such as HTTP or FTP.
Explanation:
When managing and auditing a web server, the most critical security principle is to protect sensitive data during transmission. This is achieved by using secure protocols—such as HTTPS (HTTP over SSL/TLS) for web traffic and SFTP/FTPS for file transfers—instead of clear-text protocols like HTTP or FTP. Clear-text protocols transmit data, including credentials and confidential information, in an unencrypted format, making them vulnerable to interception, eavesdropping, and man-in-the-middle attacks. Secure protocols encrypt the data in transit, ensuring confidentiality and integrity, which is a fundamental control for any web server handling sensitive information.
Why the other options are incorrect:
A. The file transfer protocol (FTP) should always be enabled.
This is false. FTP is a clear-text protocol and should generally be disabled in favor of secure alternatives like SFTP or FTPS. Enabling FTP introduces unnecessary security risks.
B. The simple mail transfer protocol (SMTP) should be operating under the most privileged accounts. This is incorrect and dangerous. Services like SMTP should run under least-privilege accounts, not privileged ones, to minimize the impact if the service is compromised.
C. The number of ports and protocols allowed to access the web server should be maximized. This is the opposite of good security practice. The principle of least functionality dictates that only necessary ports and protocols should be open, reducing the attack surface.
References:
IIA GTAG – Information Security Governance: Emphasizes the use of encrypted protocols (HTTPS, SFTP) to protect data in transit and recommends disabling insecure protocols like HTTP and FTP.
NIST SP 800-53 – SC-8 (Transmission Confidentiality and Integrity): Requires that organizations protect the confidentiality and integrity of transmitted information, typically through encryption.
Which of the following is improved by the use of smart devices?
A. Version control
B. Privacy
C. Portability
D. Secure authentication
Explanation:
Smart devices such as smartphones, tablets, and wearables are characterized primarily by their ability to provide computing functionality while being mobile, that is, their portability. Users can carry them anywhere and still access data, applications, and networks. This is the defining improvement smart devices provide compared with traditional desktop computing.
❌ Why the Other Options Are Incorrect:
A. Version control
– Version control is a function of software tools such as Git and SVN and document management systems. Smart devices do not inherently improve version control. In some cases, editing files across multiple mobile devices can make version management more complex.
B. Privacy
– Smart devices can reduce privacy rather than improve it. They may collect location data, usage patterns, and personal information and can introduce additional privacy concerns. Therefore, privacy is not a defining benefit of smart devices.
D. Secure authentication
– Smart devices can support authentication methods such as biometrics and security tokens, but they also introduce additional attack surfaces and risks. Secure authentication depends on proper implementation and is not an inherent benefit of smart devices.
📚 References:
* IIA-CIA-Part3 – Information Technology – Covers the benefits and risks of emerging technologies, including mobile and smart devices.
* GTAG – Auditing Mobile Computing – Discusses portability as a primary benefit of mobile computing while highlighting associated privacy and security risks.
Which of the following organization structures would most likely be able to cope with rapid changes and uncertainties?
A. Decentralized
B. Centralized
C. Departmentalized
D. Tall structure
Explanation:
A decentralized organizational structure distributes decision-making authority throughout the organization, pushing it down to lower levels of management and closer to where the work occurs. This provides several advantages when facing rapid changes and uncertainties:
Faster decision-making – Decisions do not have to travel through a long chain of command. Local managers can respond quickly to changing conditions.
Greater flexibility and adaptability – Individual units can adjust their operations to local circumstances without waiting for top-level approval.
Empowered employees – Lower-level managers have the authority and autonomy to solve problems as they arise.
Better responsiveness – Those closest to the customer, market, or operational issue can react quickly.
In volatile, complex, or fast-moving environments, this responsiveness provides a decisive advantage.
❌ Why the Other Options Are Incorrect:
B. Centralized – Decision-making authority is concentrated at the top. This can create slower response times because information must flow upward and decisions downward. Centralized structures are better suited to stable, predictable environments where consistency and tight control are more important than speed.
C. Departmentalized – This refers to grouping activities by function, product, geography, or customer. It describes how work is divided, not how authority is distributed. Departmentalization can exist in either centralized or decentralized structures, so it does not directly answer the question about coping with rapid change.
D. Tall structure – A tall hierarchical structure has many layers of management. This lengthens communication channels, slows decision-making, and can create rigidity, which is the opposite of what is needed to cope with rapid changes and uncertainty.
📚 References:
IIA-CIA-Part3 – Business Acumen / Organizational Behavior – Covers organizational structures and their impact on operations, decision-making, and governance.
An organization has an agreement with a third-party vendor to have a fully operational facility, duplicate of the original site and configured to the organization's needs, in order to quickly recover operational capability in the event of a disaster, Which of the following best describes this approach to disaster recovery planning?
A. Cold recovery plan,
B. Outsourced recovery plan.
C. Storage area network recovery plan.
D. Hot recovery plan
Explanation:
A hot site is a fully operational duplicate facility configured to the organization's requirements and capable of being brought online almost immediately in the event of a disaster. It typically includes duplicate hardware, software, network infrastructure, pre-installed applications, replicated or synchronized data, and the resources needed to resume operations. Because it is ready to operate with minimal setup, a hot site provides the fastest recovery time of the recovery-site options, but it is also the most expensive to maintain.
❌ Why the Other Options Are Incorrect:
A. Cold recovery plan – A cold site is an empty or minimally equipped facility with basic infrastructure such as power, HVAC, and cabling, but with no configured hardware or software. It is generally the least expensive option but takes the longest time to become operational, often days or weeks. This is the opposite of the scenario described.
B. Outsourced recovery plan – This describes who manages the recovery capability, typically a third-party provider, rather than the type of recovery facility. Although the scenario involves a third-party vendor, the defining characteristic is the fully operational duplicate facility, which makes it a hot site.
C. Storage area network recovery plan – A SAN is a data storage technology that provides dedicated network access to block-level storage. It can support data replication or recovery operations, but it is not an alternate recovery facility. Therefore, it does not describe the recovery approach in the scenario.
📚 References:
IIA-CIA-Part3 – Business Continuity Management (BCM) and Disaster Recovery Planning – Covers alternate recovery-site strategies, including hot, warm, and cold sites.
Which of the following statements is true regarding the term "flexible budgets" as it is used in accounting?
A. The term describes budgets that exclude fixed costs.
B. Flexible budgets exclude outcome projections, which are hard to determine, and instead rely on the most recent actual outcomes.
C. The term is a red flag for weak budgetary control activities.
D. Flexible budgets project data for different levels of activity.
Explanation:
A flexible budget is a budget that adjusts, or flexes, based on the actual level of activity achieved. Rather than projecting costs and revenues at a single, fixed level of activity, as a static budget does, a flexible budget presents figures for multiple levels of activity, such as different production or sales volumes. This allows management to compare actual results against the budgeted amounts that should have occurred at the actual activity level, making performance evaluation more meaningful.
For example, if a company budgeted for 10,000 units but actually produced 12,000 units, a static budget comparison could be misleading. A flexible budget recalculates expected costs for 12,000 units, allowing variances to reflect actual performance rather than differences in activity levels.
❌ Why the Other Options Are Incorrect:
A. The term describes budgets that exclude fixed costs – This is incorrect. Flexible budgets nclude both fixed and variable costs. Fixed costs remain constant across activity levels, while variable costs change proportionally. The flexible budget accounts for both types of costs when showing how total costs behave at different activity levels.
B. Flexible budgets exclude outcome projections, which are hard to determine, and instead rely on the most recent actual outcomes – This is incorrect. Flexible budgets are still projections or plans. They are prepared using expected cost behavior, such as fixed costs plus variable cost per unit multiplied by the activity level. They do not simply rely on past actual outcomes. Using only recent actuals would represent a different budgeting approach.
C. The term is a red flag for weak budgetary control activities – This is incorrect. Flexible budgets are actually a strength in budgetary control, not a weakness. They enhance control by enabling fair and accurate variance analysis at the actual activity level. The absence of flexible budgeting or consistently unexplained large variances may indicate weaknesses in budgetary control.
📚 Reference:
* IIA-CIA-Part3 – Financial Management / Managerial Accounting – Covers budgeting concepts and techniques, including static and flexible budgets.
An organization selected a differentiation strategy to compete at the business level. Which of the following structures best fits this strategic choice?
A. Functional structure
B. Divisional structure
C. Divisional structure
D. Functional structure with cross-functional teams
Explanation:
When an organization pursues a differentiation strategy, it seeks to compete by offering products or services that are perceived as unique, superior, or distinctive in ways that customers value — for example, through brand image, quality, innovation, customer service, or features. This strategy requires the organization to be innovative, responsive to customer needs, and coordinated across functions to deliver a differentiated offering. A functional structure with cross-functional teams best supports this because the functional structure provides the specialized expertise needed to develop superior products and capabilities (e.g., R&D, marketing, engineering), while cross-functional teams break down silos between functions, enabling the coordination, integration, and speed required to innovate and respond to customer preferences — critical for differentiation. This combination balances efficiency (specialization) with flexibility and responsiveness (integration).
Why the other options are incorrect:
A. Functional structure
– A pure functional structure groups employees by specialty (marketing, finance, operations). While it builds deep expertise, it tends to be slow, siloed, and inward-focused, making it harder to coordinate across functions for innovation. It is generally better suited to a cost leadership strategy, where efficiency and economies of scale matter most.
B. Divisional structure
– A divisional structure organizes the company by product, geography, or customer. While it can support differentiation by allowing each division to tailor offerings to its market, it often duplicates resources, increases costs, and can fragment overall strategy. On its own, it is less clearly aligned with a business-level differentiation strategy than a structure explicitly built for cross-functional integration.
C. Divisional structure
– This is the same option as B (appears to be a duplication/typo in the question). Either way, the reasoning in B applies.
Reference:
IIA-CIA-Part3 content area on Business Acumen / Strategic Management — business-level strategies (Porter's generic strategies) and their alignment with organizational structures.
According to lIA guidance on IT, which of the following plans would pair the identification of critical business processes with recovery time objectives?
A. The business continuity management charter.
B. The business continuity risk assessment plan
C. The business Impact analysis plan
D. The business case for business continuity planning
Explanation:
According to IIA guidance on IT, the Business Impact Analysis (BIA) is the process that identifies critical business processes and pairs them with Recovery Time Objectives (RTOs). The BIA determines which business functions are essential to the organization's survival and how quickly they must be restored after a disruption. It establishes the RTO, which represents the maximum acceptable time before a process must be restored, and the Recovery Point Objective (RPO) for each critical process. This provides the foundation for prioritizing recovery efforts and allocating resources in the business continuity plan.
❌ Why the Other Options Are Incorrect:
A. The business continuity management charter – The charter is a high-level document that establishes the authority, scope, objectives, and governance structure for the business continuity management program. It does not identify critical business processes or set recovery time objectives. That is the role of the BIA.
B. The business continuity risk assessment plan – The risk assessment plan focuses on identifying and evaluating threats, vulnerabilities, and potential impacts that could disrupt operations. While it informs the business continuity management program, it does not specifically pair critical business processes with RTOs. That linkage is established through the BIA.
D. The business case for business continuity planning – The business case is a justification document that outlines the costs, benefits, and rationale for investing in business continuity planning. It is used to obtain management approval and resources, not to identify critical processes or determine recovery time objectives.
📚 Reference:
* IIA-CIA-Part3 – Business Continuity Management (BCM) – Covers business impact analysis and its role in identifying critical processes and establishing recovery objectives.
A company records income from an investment in common stock when it does which of the following?
A. Purchases bonds
B. Receives interest
C. Receives dividends
D. Sells bonds
Explanation:
When a company invests in common stock, it earns income in the form of dividends declared and paid by the investee company. Under accounting principles, dividend income is recognized when the right to receive the dividend is established. The key point is that income from an investment in common stock arises from dividends, not from interest, which applies to debt securities such as bonds, or from the purchase or sale of the securities themselves.
Why the other options are incorrect:
A. Purchases bonds
– Purchasing bonds is an investment activity, not a source of income. Buying a bond does not generate income at the time of purchase; it creates an investment asset. Any income from bonds comes later in the form of interest.
B. Receives interest
– Interest income is associated with debt securities such as bonds, not common stock. Common stockholders are owners, not creditors, so they receive dividends rather than interest. This option describes income from bond investments.
D. Sells bonds
– Selling bonds is a disposal of an investment, which may generate a gain or loss, but it is not the way a company records income from an investment in common stock. This option relates to debt securities and realized gains or losses, not dividend income.
📚 Reference:
IIA-CIA-Part3 content area on Financial Management / Accounting – Covers investment accounting and the recognition of income from equity versus debt securities.
Which of the following is true regarding the use of remote wipe for smart devices?
A. It can restore default settings and lock encrypted data when necessary
B. It enables the erasure and reformatting of secure digital (SD) cards
C. It can delete data backed up to a desktop for complete protection if required
D. It can wipe data that is backed up via cloud computing
Explanation:
Remote wipe is a security feature that allows an organization to remotely erase data and restore a smart device to its default (factory) settings when the device is lost, stolen, or compromised. It is a key control in mobile device management (MDM) policies. When remote wipe is initiated, it can remove sensitive organizational data from the device, reset it to its original factory configuration, and lock encrypted data so that unauthorized users cannot access it. This capability is essential for protecting confidential information and preventing data breaches when a device is no longer under the organization's physical control.
Why the other options are incorrect:
B. It enables the erasure and reformatting of secure digital (SD) cards – While some remote wipe tools may extend to removable storage, this is not a universal or defining capability of remote wipe. The standard function focuses on the device's internal storage and settings, not specifically the reformatting of SD cards, which may be encrypted separately or not manageable remotely.
C. It can delete data backed up to a desktop for complete protection if required – Remote wipe targets the smart device itself, not backups stored on a separate desktop or computer. Backups on other devices are outside the scope of a remote wipe command and would require separate deletion procedures, so this statement overstates the capability.
D. It can wipe data that is backed up via cloud computing – Remote wipe does not typically erase data stored in cloud backups. Cloud backup data resides on external servers managed by the cloud provider, and remote wipe generally affects only the local device. Wiping cloud backups would require separate administrative action through the cloud service, so this statement is inaccurate.
📚 Reference:
IIA-CIA-Part3 content area on Information Technology – Covers mobile device security, mobile device management (MDM), and data protection controls for smart devices.
| Page 12 out of 58 Pages |
| 34567891011121314151617181920 |
| IIA-CIA-Part3 Practice Test Home |
Real-World Scenario Mastery: Our IIA-CIA-Part3 practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before Certified Internal Auditor Part 3 - Internal Audit Function exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive IIA-CIA-Part3 practice exam questions pool covering all topics, the real exam feels like just another practice session.