Which of the following is considered a physical security control?
A. Transaction logs are maintained to capture a history of system processing.
B. System security settings require the use of strong passwords and access controls.
C. Failed system login attempts are recorded and analyzed to identify potential security incidents.
D. System servers are secured by locking mechanisms with access granted to specific individuals.
Explanation
Physical security controls are measures designed to protect the physical assets of an organization, such as servers, network equipment, facilities, and other hardware, from unauthorized access, theft, damage, or environmental threats. Securing system servers with locking mechanisms and restricting access to specific individuals is a classic example of a physical security control. It ensures that only authorized personnel can physically access the servers, reducing the risk of tampering, theft, or sabotage. Locking mechanisms, such as locked server racks, cages, or rooms, and controlled physical access are fundamental physical safeguards for protecting IT infrastructure.
Why the other options are incorrect:
A. Transaction logs are maintained to capture a history of system processing
– Transaction logs are logical controls, specifically detective and audit trail controls, that record system activity for review and accountability. They are not physical security controls because they protect data through logical means, not physical barriers.
B. System security settings require the use of strong passwords and access controls
– Strong passwords and access controls are logical access controls, or technical controls. They govern access to systems and data through logical means such as authentication and authorization, not through physical barriers.
C. Failed system login attempts are recorded and analyzed to identify potential security incidents
– Recording and analyzing failed login attempts is a logical detective control. It monitors system access activity to identify potential security incidents, but it does not involve physical protection of assets.
Reference:
IIA-CIA-Part3 content area on Information Technology — Specifically physical security controls versus logical (technical) controls, and the protection of IT assets.
Which of the following information security controls has the primary function of preventing unauthorized outside users from accessing an organization's data through the organization's network?
A. Firewall.
B. Encryption.
C. Antivirus.
D. Biometrics.
Explanation
A firewall is a network security control whose primary function is to prevent unauthorized outside users from accessing an organization's data through the organization's network. It acts as a barrier between the organization's internal network and external networks such as the internet, inspecting incoming and outgoing traffic and allowing or blocking it based on predefined security rules. By filtering traffic at the network perimeter, a firewall blocks unauthorized access attempts, malicious traffic, and other external threats, thereby protecting the organization's data and systems from outside intrusion. This makes the firewall the control specifically designed for the purpose described in the question.
Why the other options are incorrect:
B. Encryption
– Encryption protects the confidentiality of data by converting it into an unreadable form that can only be decrypted with the proper key. While it protects data from being understood if intercepted or accessed, it does not prevent unauthorized outside users from accessing the network in the first place. Encryption is a data protection control, not a network perimeter access control.
C. Antivirus
– Antivirus software detects, prevents, and removes malicious software, such as viruses, worms, and trojans, on computers and devices. It protects against malware infections but does not control or prevent unauthorized network access from outside users. Its function is malware detection and removal, not network perimeter defense.
D. Biometrics
– Biometrics is an authentication method that verifies identity using physical or behavioral characteristics such as fingerprints, iris patterns, or facial recognition. It controls access to systems or physical facilities based on who the user is, but it is not designed to prevent unauthorized outside users from accessing the organization's network. It is an authentication control, not a network perimeter control.
Reference:
IIA-CIA-Part3 content area on Information Technology — Specifically network security, perimeter controls, and information security controls.
Which of the following is true of matrix organizations?
A. A unity-of-command concept requires employees to report technically, functionally, and administratively to the same manager.
B. A combination of product and functional departments allows management to utilize personnel from various Junctions.
C. Authority, responsibility and accountability of the units Involved may vary based on the project's life, or the organization's culture
D. It is best suited for firms with scattered locations or for multi-line, Large-scale firms.
Explanation
A matrix organization is a structure that combines two or more lines of authority, typically a functional structure, such as marketing, finance, or engineering, and a project or product structure. Employees in a matrix organization often report to both a functional manager and a project or product manager. This dual-reporting arrangement allows management to utilize personnel from various functions across projects or products, drawing on specialized expertise from different functional areas while focusing on specific projects or product lines. This combination of product and functional departments is the defining characteristic of a matrix organization, making option B the correct statement.
Why the other options are incorrect:
A. A unity-of-command concept requires employees to report technically, functionally, and administratively to the same manager
– The unity-of-command concept holds that each employee should report to only one manager, which is the opposite of how a matrix organization operates. In a matrix, employees typically report to two managers, such as a functional manager and a project manager, which violates the traditional unity-of-command principle. This statement describes a traditional hierarchical structure, not a matrix organization.
C. Authority, responsibility and accountability of the units involved may vary based on the project's life, or the organization's culture
– While it is true that authority and responsibility in matrix organizations can be complex and may shift over time or vary by culture, this statement is too vague and general to be the defining or most accurate characteristic of matrix organizations. Option B more precisely captures what a matrix organization is: a combination of product and functional departments that allows flexible use of personnel.
D. It is best suited for firms with scattered locations or for multi-line, large-scale firms
– This statement describes conditions under which a divisional or geographic structure might be appropriate, not specifically a matrix organization. While matrix structures can be used by large, complex organizations, the statement does not accurately capture the essence of what a matrix organization is or its primary characteristic.
Reference:
IIA-CIA-Part3 content area on Business Acumen / Organizational Behavior — Specifically organizational structures, including matrix organizations.
Which of the following biometric access controls uses the most unique human recognition characteristic?
A. Facial comparison using photo identification.
B. Signature comparison.
C. Voice comparison.
D. Retinal print comparison.
Explanation:
Biometric access controls verify identity using unique physical or behavioral characteristics of an individual. Among the biometric methods listed, retinal print comparison uses the most unique human recognition characteristic. The retina — the layer of tissue at the back of the eye containing blood vessels — has a highly complex and distinctive pattern of blood vessels that is unique to each individual, even among identical twins. Retinal patterns are extremely stable over a person's lifetime and are very difficult to replicate or forge, making retinal scanning one of the most accurate and secure biometric authentication methods available. This high degree of uniqueness and stability is why retinal print comparison is considered to use the most unique human recognition characteristic among the options.
Why the other options are incorrect:
A. Facial comparison using photo identification
– Facial recognition compares facial features (e.g., distance between eyes, nose shape, jawline) to verify identity. While facial features are distinctive, they can change with age, weight, facial hair, or expression, and photo identification is relatively easy to forge or spoof. Facial characteristics are less unique and less reliable than retinal patterns.
B. Signature comparison
– Signature comparison is a behavioral biometric that analyzes the way a person signs their name, including speed, pressure, and stroke pattern. Signatures can vary from one signing to another and can be forged or imitated with practice, making them less unique and less reliable than retinal patterns.
C. Voice comparison
– Voice comparison is a behavioral/biometric method that analyzes vocal characteristics such as pitch, tone, and cadence. Voices can change due to illness, emotion, or aging, and can be imitated or recorded and replayed, making voice recognition less unique and less secure than retinal scanning.
Reference:
IIA-CIA-Part3 content area on Information Technology — specifically biometric authentication methods and access controls.
Which of the following types of accounts must be closed at the end of the period?
A. Income statement accounts.
B. Balance sheet accounts.
C. Permanent accounts
D. Real accounts
Explanation:
Income statement accounts (also called temporary or nominal accounts) must be closed at the end of each accounting period. These accounts include revenues, expenses, gains, and losses. At the end of the period, their balances are transferred to a summary account (such as Income Summary) and ultimately to retained earnings (or owner's equity). Closing these accounts resets their balances to zero so they can accumulate activity for the next period. This process is known as the closing process, and it applies specifically to income statement accounts because they measure activity for a period rather than a point in time.
Why the other options are incorrect:
B. Balance sheet accounts
– Balance sheet accounts (assets, liabilities, and equity) are permanent accounts and are not closed at the end of the period. Their balances carry forward from one period to the next because they represent the organization's financial position at a point in time, which is cumulative.
C. Permanent accounts
– Permanent accounts (also called real accounts) are balance sheet accounts whose balances are carried forward indefinitely. They are not closed at the end of the period; only temporary (income statement) accounts are closed.
D. Real accounts
– Real accounts are another term for permanent accounts (balance sheet accounts). Like permanent accounts, they are not closed at the end of the period. Their balances continue into the next period, so this option is incorrect.
Reference:
IIA-CIA-Part3 content area on Financial Management / Accounting — specifically the accounting cycle, closing process, and the distinction between temporary and permanent accounts.
Which of the following storage options would give the organization the best chance of recovering data?
A. Encrypted physical copies of the data, and their encryption keys are stored together at the organization and are readily available upon request.
B. Encrypted physical copies of the data are stored separately from their encryption keys, and both are held in secure locations a few hours away from the organization.
C. Encrypted reports on usage and database structure changes are stored on a cloudbased, secured database that is readily accessible.
D. Encrypted copies of the data are stored in a separate secure location a few hours away, while the encryption keys are stored at the organization and are readily available.
Explanation:
To give the organization the best chance of recovering data, backups must be both secure and available in the event of a disaster. This option achieves that by (1) storing encrypted physical copies of the data, which protects confidentiality; (2) storing the encryption keys separately from the data, so that if the data is compromised or the storage location is breached, the data cannot be decrypted without the separately held keys; and (3) keeping both the data and the keys in secure offsite locations a few hours away, so that a disaster at the primary site (e.g., fire, flood, or physical destruction) does not destroy both the data and the keys. Separating the data from the keys and placing both offsite balances security and recoverability, making this the best option for ensuring data can be recovered.
Why the other options are incorrect:
A. Encrypted physical copies of the data, and their encryption keys are stored together at the organization and are readily available upon request
– Storing the encryption keys together with the encrypted data defeats much of the purpose of encryption, because anyone who gains access to the storage location can also access the keys and decrypt the data. In addition, keeping both at the organization means a disaster at the primary site could destroy both the data and the keys, making recovery impossible.
C. Encrypted reports on usage and database structure changes are stored on a cloud-based, secured database that is readily accessible
– This option only stores reports on usage and database structure changes, not the actual data itself. Without the full data, the organization cannot fully recover its operations. Storing only reports and metadata does not provide the best chance of recovering data.
D. Encrypted copies of the data are stored in a separate secure location a few hours away, while the encryption keys are stored at the organization and are readily available
– While the encrypted data is stored offsite, the encryption keys remain at the organization. If a disaster destroys the organization's primary site, the keys could be lost along with it, making the offsite encrypted data undecryptable and therefore useless for recovery. The keys must be protected and available separately from the primary site.
Reference:
IIA-CIA-Part3 content area on Information Technology — specifically backup and recovery, data protection, encryption key management, and offsite storage.
According to IIA guidance on IT, which of the following strategies would provide the most effective access control over an automated point-of-sale system?
A. Install and update anti-virus software.
B. Implement data encryption techniques
C. Set data availability by user need.
D. Upgrade firewall configuration
Explanation:
According to IIA guidance on IT, access control is about ensuring that users can access only the data and functions they need to perform their job responsibilities, based on the principle of least privilege and need-to-know. Setting data availability by user need means defining and restricting access rights so that each user can only reach the data and system functions required for their role. This is the essence of effective access control. In an automated point-of-sale (POS) system, this would mean, for example, that cashiers can process sales but cannot access pricing configuration, refund authorization, or management reports, while supervisors and managers have broader access appropriate to their duties. This approach directly controls who can access what within the POS system, making it the most effective access control strategy among the options.
Why the other options are incorrect:
A. Install and update anti-virus software
– Anti-virus software protects systems from malware infections. While important for overall security, it is not an access control strategy; it does not govern who can access the POS system or what data they can use. It addresses a different risk (malicious software) rather than controlling access.
B. Implement data encryption techniques
– Encryption protects the confidentiality of data by making it unreadable to unauthorized parties, both in storage and in transmission. While encryption is a valuable security control, it does not control who is authorized to access the system or what they can do once inside. It protects data from being understood if intercepted, not from being accessed by unauthorized users.
D. Upgrade firewall configuration
– A firewall controls network traffic entering and leaving the organization's network. While it helps prevent unauthorized external access, it does not govern internal user access rights within the POS system. It is a perimeter control, not an access control over the application and its data.
Reference:
IIA-CIA-Part3 content area on Information Technology — specifically access controls, the principle of least privilege, and need-to-know access in application systems.
Which of the following types of date analytics would be used by a hospital to determine which patients are likely to require remittance for additional treatment?
A. Predictive analytics
B. Prescriptive analytics.
C. Descriptive analytics
D. Diagnostic analytics
Explanation:
Predictive analytics uses historical data, statistical models, and machine learning techniques to forecast future outcomes or identify the likelihood of future events. In this scenario, the hospital wants to determine which patients are likely to require readmission for additional treatment — that is, it wants to predict a future event based on patterns in existing data (such as patient history, diagnoses, treatment records, and demographics). This is a classic application of predictive analytics, which estimates the probability of future occurrences and helps organizations anticipate needs and allocate resources accordingly.
Why the other options are incorrect:
B. Prescriptive analytics
– Prescriptive analytics goes beyond prediction to recommend specific actions or decisions to achieve a desired outcome. It answers the question "What should we do about it?" While prescriptive analytics may build on predictive models, the question asks about determining which patients are likely to require readmission, which is a prediction of likelihood, not a recommendation for action. Therefore, predictive analytics is the more accurate answer.
C. Descriptive analytics
– Descriptive analytics summarizes and describes what has already happened, using historical data to provide insights into past performance or trends (e.g., how many patients were readmitted last year). It does not forecast future events or identify which patients are likely to require readmission, so it is not the correct technique here.
D. Diagnostic analytics
– Diagnostic analytics examines past data to understand why something happened — it focuses on identifying causes and relationships (e.g., why readmission rates increased). It is explanatory rather than predictive, so it does not determine which patients are likely to require additional treatment in the future.
Reference:
IIA-CIA-Part3 content area on Information Technology / Data Analytics— specifically types of data analytics, including descriptive, diagnostic, predictive, and prescriptive analytics.
An employee was promoted within the organization and relocated to a new office in a different building. A few months later, security personnel discovered that the employee's smart card was being used to access the building where she previously worked. Which of the following security controls could prevent such an incident from occurring?
A. Regular review of logs.
B. Two-level authentication.
C. Photos on smart cards
D. Restriction of access hours
Explanation
In this scenario, the employee's smart card continued to be used to access her former building after she was promoted and relocated. This indicates that her old access rights were not removed or updated when her role changed. A regular review of access logs would help detect this type of issue because it would reveal that the smart card was still being used at the previous building, prompting corrective action such as deactivating the old access rights. Log reviews are a detective control that identifies unauthorized or inappropriate access, enabling security personnel to investigate and remediate the situation. While log review alone does not automatically prevent the access, it is the control that would most directly detect and lead to prevention of this incident.
Why the other options are incorrect:
B. Two-level authentication
– Two-level authentication, such as something you have plus something you know, strengthens authentication at the point of entry, but in this scenario, the smart card was legitimately issued to the employee. If the employee, or someone else using her card, also had the second authentication factor, two-level authentication would not prevent access. The problem is not weak authentication at the door; it is that the employee's access rights to the old building were never updated or revoked.
C. Photos on smart cards
– Photos on smart cards help security personnel visually verify that the person using the card is the legitimate cardholder. However, this control depends on someone physically inspecting the card and the person at the point of entry. If the card is used at an unattended reader or if no one checks the photo, it would not prevent the access. It also does not address the underlying issue of outdated access rights.
D. Restriction of access hours
– Restricting access hours limits when a card can be used, but it does not prevent a former occupant from using the card during allowed hours. Since the access occurred at the previous building during presumably normal hours, access-hour restrictions would not have prevented this incident.
Reference:
IIA-CIA-Part3 content area on Information Technology — Specifically physical access controls, access rights management, and monitoring controls.
Which of the following techniques would best detect an inventory fraud scheme?
A. Analyze Invoice payments just under individual authorization limits.
B. Analyze stratification of inventory adjustments by warehouse location.
C. Analyze inventory invoice amounts and compare with approved contract amounts.
D. Analyze differences discovered during duplicate payment testing
Explanation
Inventory fraud schemes typically involve manipulating inventory records to conceal theft, misappropriation, or false reporting. Common inventory frauds include stealing inventory and covering it up with fictitious adjustments, write-offs, or shrinkages recorded against inventory records. Analyzing the stratification of inventory adjustments by warehouse location is an effective detection technique because it breaks down inventory adjustments, such as write-offs, shrinkage, and count variances, by location and value ranges, allowing the auditor to identify unusual patterns or concentrations. For example, if one warehouse consistently shows disproportionately large or frequent adjustments compared to others, this could indicate that inventory is being stolen and masked through adjustments at that location. This technique helps isolate anomalies that might signal fraud.
Why the other options are incorrect:
A. Analyze invoice payments just under individual authorization limits
– This technique is designed to detect fraud in the procurement or accounts payable process, where an employee splits invoices or keeps amounts just below approval thresholds to avoid scrutiny. It relates to payment authorization fraud, not inventory fraud. It would not effectively detect manipulation of inventory records or physical inventory theft.
C. Analyze inventory invoice amounts and compare with approved contract amounts
– This technique compares invoice amounts to contract terms to detect overbilling or pricing discrepancies in purchases. While useful for detecting procurement fraud or billing errors, it focuses on the purchasing and invoicing process rather than on inventory adjustments or physical inventory discrepancies. It would not be the best technique for detecting an inventory fraud scheme.
D. Analyze differences discovered during duplicate payment testing
– Duplicate payment testing identifies instances where the same invoice has been paid more than once. This is a technique for detecting accounts payable fraud or errors, not inventory fraud. It does not address inventory records, adjustments, or physical inventory counts, so it would not effectively detect an inventory fraud scheme.
Reference:
IIA-CIA-Part3 content area on Information Technology / Data Analytics and Fraud Detection — Specifically inventory fraud schemes and analytical techniques used to detect them.
Which of the following actions would senior management need to consider as part of new IT guidelines regarding the organization's cybersecurity policies?
A. Assigning new roles and responsibilities for senior IT management.
B. Growing use of bring your own devices for organizational matters.
C. Expansion of operations into new markets with limited IT access
D. Hiring new personnel within the IT department for security purposes
Explanation
When senior management establishes new IT guidelines and cybersecurity policies, it must consider emerging trends and changes in how technology is used across the organization. The growing use of bring-your-own-device (BYOD) arrangements, where employees use personally owned devices for organizational matters, is a significant cybersecurity concern that directly affects policy design. BYOD introduces risks related to data leakage, unsecured devices, mixing of personal and organizational data, loss or theft of devices, and difficulty enforcing security controls on devices the organization does not own. As BYOD use grows, senior management must update cybersecurity policies to address device approval, mobile device management, encryption, access controls, acceptable use, and incident response for personally owned devices. This makes the growing use of BYOD a key consideration for new IT guidelines and cybersecurity policies.
Why the other options are incorrect:
A. Assigning new roles and responsibilities for senior IT management – While assigning roles and responsibilities is an important governance activity, it is an internal organizational decision rather than an external or emerging trend that would drive the need for new cybersecurity guidelines. It is a consequence of policy decisions, not a trigger for reconsidering cybersecurity policies.
C. Expansion of operations into new markets with limited IT access – Expanding into new markets may raise IT and security considerations, but this is a strategic business decision that may or may not occur. It is not a general trend that senior management would necessarily need to address as part of new IT guidelines for cybersecurity policy, and it is phrased conditionally, "with limited IT access," making it less directly relevant than BYOD.
D. Hiring new personnel within the IT department for security purposes – Hiring additional IT security personnel is a resource and staffing decision, not a policy consideration that would shape new cybersecurity guidelines. It addresses capacity rather than the content and scope of the policies themselves, so it is not the best answer.
Reference:
IIA-CIA-Part3 content area on Information Technology — Specifically cybersecurity governance, IT policy development, and emerging technology risks including BYOD.
Which of the following statements is true regarding data backup?
A. System backups should always be performed real time.
B. Backups should be stored in a secured location onsite for easy access.
C. The tape rotation schedule affects how long data is retained
D. Backup media should be restored only m case of a hardware or software failure
Explanation
In data backup procedures, the tape rotation schedule determines how backup media are cycled through use and how long each backup is retained before being overwritten or retired. For example, a rotation schedule may specify daily, weekly, monthly, and annual backups, with media being reused according to a defined cycle. The rotation schedule therefore directly affects the retention period of backed-up data, meaning how far back the organization can restore data if needed. This makes option C a true statement about data backup.
Why the other options are incorrect:
A. System backups should always be performed real time
– Not all backups need to be performed in real time. The frequency of backups depends on the criticality of the data, the cost of backup, and the acceptable recovery point objective (RPO). Some systems may use real-time replication, while others may use daily, weekly, or monthly backups. Stating that backups should "always" be performed in real time is inaccurate and impractical for many organizations.
B. Backups should be stored in a secured location onsite for easy access
– Storing backups only onsite is not recommended because a disaster at the primary site, such as fire, flood, or theft, could destroy both the original data and the onsite backups. Best practice requires that backups be stored offsite in a secure location, and often a copy is retained onsite for operational convenience. Therefore, this statement is not true as written.
D. Backup media should be restored only in case of a hardware or software failure
– Backups are used for many purposes beyond hardware or software failure, including recovering from data corruption, accidental deletion, cyberattacks such as ransomware, human error, and disaster recovery. Restricting restoration to hardware or software failure only is incorrect and understates the purpose of backups.
Reference:
IIA-CIA-Part3 content area on Information Technology — Specifically data backup, backup rotation schedules, retention, and disaster recovery planning.
GTAG (Global Technology Audit Guide) — Business Continuity Management and IT Essentials for Internal Auditors (IIA), which discusses backup procedures, rotation schedules and their effect on data retention, the importance of offsite storage, and the varied purposes for which backups are restored.
| Page 19 out of 58 Pages |
| 101112131415161718192021222324252627 |
| IIA-CIA-Part3 Practice Test Home |
Real-World Scenario Mastery: Our IIA-CIA-Part3 practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before Certified Internal Auditor Part 3 - Internal Audit Function exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive IIA-CIA-Part3 practice exam questions pool covering all topics, the real exam feels like just another practice session.