Which of the following application controls, implemented by management, monitors data being processed to ensure the data remains consistent and accurate?
A. Management trail controls
B. Output controls.
C. Integrity controls
D. input controls
Explanation
Integrity controls are application controls designed to monitor data being processed to ensure that it remains consistent, accurate, and complete throughout processing. They help detect and prevent errors, unauthorized changes, or corruption of data during processing. Examples include control totals, hash totals, record counts, check digits, and reconciliation routines that verify data integrity as it moves through the system. Because their purpose is to ensure data remains consistent and accurate during processing, integrity controls are the correct answer.
Why the other options are incorrect:
A. Management trail controls
– Management trail controls, also called audit trail controls, are designed to provide a record of transactions and activities so that processing can be traced and reviewed. While they support accountability and oversight, their primary purpose is to create a traceable history of activity, not to monitor data processing for consistency and accuracy in real time.
B. Output controls
– Output controls are designed to ensure the accuracy, completeness, and validity of the results produced by the system, such as reports and output files. They focus on the final results of processing rather than monitoring data during processing to maintain its consistency and accuracy.
D. Input controls
– Input controls are designed to ensure that data entered into the system is accurate, complete, authorized, and valid at the point of entry. They govern the quality of data going into the system, not the monitoring of data during processing to ensure it remains consistent and accurate.
Reference:
IIA-CIA-Part3 content area on Information Technology — Specifically application controls, including input, processing (integrity), and output controls.
GTAG (Global Technology Audit Guide) — Auditing IT Controls and IT Essentials for Internal Auditors (IIA), which categorizes application controls into input controls (data entry accuracy), processing/integrity controls (ensuring data remains consistent and accurate during processing), and output controls (validating results), and describes integrity controls as those that monitor data during processing to ensure consistency and accuracy.
A new clerk in the managerial accounting department applied the high-low method and computed the difference between the high and low levels of maintenance costs. Which type of maintenance costs did the clerk determine?
A. Fixed maintenance costs.
B. Variable maintenance costs.
C. Mixed maintenance costs.
D. Indirect maintenance costs.
Explanation
The high-low method is a cost estimation technique used to separate mixed costs into their fixed and variable components. The method involves taking the highest and lowest activity levels and their associated total costs, then computing the difference between the high and low total costs and dividing by the difference in activity levels. The resulting amount represents the variable cost per unit of activity , that is, the variable cost component of the mixed cost. By computing the difference between the high and low levels of maintenance costs, the clerk determined the variable maintenance cost per unit of activity, making variable maintenance costs the correct answer.
Why the other options are incorrect:
A. Fixed maintenance costs
– Under the high-low method, fixed costs are determined after the variable cost per unit is calculated. Fixed costs are found by subtracting the total variable cost at either the high or low activity level from the total cost at that level. The difference between the high and low total costs does not directly yield fixed costs; it yields the variable costs.
C. Mixed maintenance costs
– Mixed, or semivariable, costs contain both a fixed and a variable component. The high-low method is used to separate a mixed cost into its fixed and variable elements, but the specific computation described, the difference between high and low total costs, determines the variable portion, not the mixed cost as a whole.
D. Indirect maintenance costs
– Indirect costs are costs that cannot be traced directly to a cost object. The high-low method is concerned with cost behavior, specifically fixed versus variable, not with whether costs are direct or indirect. Therefore, indirect maintenance costs are not what the clerk determined by applying the high-low method.
Reference:
IIA-CIA-Part3 content area on Financial Management / Managerial Accounting — Specifically cost behavior, mixed costs, and the high-low method of cost estimation.
Standard managerial accounting theory — The high-low method separates mixed costs into fixed and variable components, where the difference between total costs at high and low activity levels divided by the difference in activity levels yields the variable cost per unit.
Which of the following purchasing scenarios would gain the greatest benefit from implementing electronic cate interchange?
A. A just-in-time purchasing environment
B. A Large volume of custom purchases
C. A variable volume sensitive to material cost
D. A currently inefficient purchasing process
Explanation
Electronic data interchange (EDI) is the electronic exchange of business documents, such as purchase orders, invoices, and shipping notices, between organizations in a standardized format. EDI's greatest benefit is realized in environments that require speed, accuracy, and tight coordination between trading partners. A just-in-time (JIT) purchasing environment depends on frequent, timely, and highly accurate communication of purchase orders and delivery schedules to ensure that materials arrive exactly when needed and inventory levels remain low. EDI directly supports JIT by enabling rapid, error-free transmission of purchasing documents, reducing lead times, minimizing manual processing, and synchronizing supplier deliveries with production schedules. This makes JIT the scenario that gains the greatest benefit from EDI.
Why the other options are incorrect:
B. A large volume of custom purchases
– Custom purchases often involve unique specifications, negotiations, and nonstandard terms, which may not lend themselves to standardized EDI transactions. While EDI can still be used, the benefit is reduced because custom purchases are less repetitive and standardized, requiring more manual handling and customization.
C. A variable volume sensitive to material cost
– Purchasing volume that varies with material cost sensitivity is primarily a pricing and cost management issue. While EDI can improve efficiency, the greatest benefit of EDI is not specifically tied to cost-sensitive volume variability. EDI's core advantage is speed, accuracy, and coordination of standardized transactions, which is most critical in JIT environments.
D. A currently inefficient purchasing process
– While EDI can improve an inefficient purchasing process, the greatest benefit of EDI is realized where timing and coordination are critical, such as in JIT environments. An inefficient process may benefit from many types of improvements, such as process reengineering or automation, but EDI's specific strengths, rapid, standardized, error-free document exchange, are most valuable in JIT purchasing, where timing and accuracy are essential.
Reference:
IIA-CIA-Part3 content area on Information Technology — Specifically electronic data interchange (EDI), e-commerce, and supply chain management.
GTAG (Global Technology Audit Guide) — IT Essentials for Internal Auditors and related IIA guidance, which describes EDI as a technology that enables fast, accurate, standardized exchange of business documents between trading partners and notes that EDI provides significant benefits in environments requiring tight coordination and timely delivery, such as just-in-time purchasing.
Which of the following application controls is the most dependent on the password owner?
A. Password selection
B. Password aging
C. Password lockout
D. Password rotation
Explanation
Among the application controls listed, password selection is the most dependent on the password owner. Password selection refers to the process by which the user chooses their own password. Because the user creates and controls the password, its strength, uniqueness, and confidentiality depend heavily on the user's choices and behavior, for example, whether they choose a strong password, avoid using personal information, and refrain from sharing it. Other password controls, such as password aging, lockout, and rotation, are enforced by the system regardless of the user's choices. Password selection, however, relies directly on the password owner to make appropriate decisions, making it the control most dependent on the password owner.
Why the other options are incorrect:
B. Password aging
– Password aging is a system-enforced control that requires users to change their passwords after a specified period. It is applied automatically by the system, so it does not depend on the password owner's decisions; the system enforces the requirement regardless of user preferences.
C. Password lockout
– Password lockout is a system-enforced control that disables an account after a specified number of failed login attempts. It is implemented and enforced by the system, not by the password owner, so it does not depend on the user's actions beyond entering incorrect passwords.
D. Password rotation
– Password rotation is the practice of periodically changing passwords, often enforced by system policy. Like password aging, it is system-enforced and does not rely on the password owner's discretion. The system mandates the rotation regardless of the user's preferences.
Reference:
IIA-CIA-Part3 content area on Information Technology — Specifically authentication controls, password management, and access controls.
GTAG (Global Technology Audit Guide) — Identity and Access Management (IIA), which discusses password controls including password selection, which is user-chosen and dependent on user behavior, and password aging, password lockout, and password rotation, which are primarily system-enforced controls. Password selection is therefore the control most dependent on the password owner's choices and behavior.
Which of the following best describes the type of control provided by a firewall?
A. Corrective
B. Detective
C. Preventive
D. Discretionary
Explanation
A firewall is a preventive control. It is designed to stop unauthorized access, malicious traffic, and other security threats before they reach the organization's internal network or systems. By filtering incoming and outgoing data packets based on predefined security rules, a firewall prevents unauthorized users and harmful traffic from entering the network in the first place. Because its primary function is to block or deny unwanted activity before it occurs, a firewall provides preventive control, making option C the correct answer.
Why the other options are incorrect:
A. Corrective – Corrective controls are designed to restore systems, data, or operations after a security incident or problem has occurred (e.g., backups, disaster recovery, patch management). A firewall does not correct or remediate incidents after they happen; it prevents them from occurring, so it is not a corrective control.
B. Detective – Detective controls are designed to identify or discover security incidents, errors, or irregularities after they have occurred or while they are occurring (e.g., log monitoring, intrusion detection systems, variance analysis). A firewall primarily blocks traffic rather than detecting and reporting incidents, so it is not classified as a detective control.
D. Discretionary – "Discretionary" describes a type of access control (discretionary access control, or DAC) where the owner of a resource decides who may access it, rather than a category of control function (preventive, detective, corrective). A firewall is not described as a discretionary control in terms of its control function; it is a preventive control.
Reference:
IIA-CIA-Part3 content area on Information Technology — Specifically information security controls, including preventive, detective, and corrective controls, and network perimeter protection.
GTAG (Global Technology Audit Guide) — Information Security Governance and IT Essentials for Internal Auditors (IIA), which categorizes controls by function (preventive, detective, corrective) and identifies firewalls as preventive controls that block unauthorized traffic before it reaches the internal network.
Which of the following statements is true regarding user developed applications (UDAs) and traditional IT applications?
A. UDAs arid traditional JT applications typically follow a similar development life cycle
B. A UDA usually includes system documentation to illustrate its functions, and ITdeveloped applications typically do not require such documentation.
C. Unlike traditional IT applications. UDAs typically are developed with little consideration of controls.
D. IT testing personnel usually review both types of applications thoroughly to ensure they were developed properly.
Explanation
User-developed applications (UDAs), such as spreadsheets, small databases, and ad hoc query tools created by end users, are typically developed by users outside the formal IT development process. As a result, UDAs are often built with little consideration of controls, documentation, testing, or security. Users focus on getting the immediate task done rather than on establishing proper change control, access controls, input validation, error handling, or segregation of duties. In contrast, traditional IT applications are developed through a formal systems development life cycle (SDLC) that includes requirements analysis, design, testing, controls, and documentation. This difference, that UDAs are typically developed with little consideration of controls, makes option C the true statement.
Why the other options are incorrect:
A. UDAs and traditional IT applications typically follow a similar development life cycle – This is incorrect. UDAs are generally developed quickly and informally by users, without following a formal SDLC. Traditional IT applications, by contrast, follow a structured development life cycle with defined phases, approvals, testing, and documentation. Their development approaches are fundamentally different.
B. A UDA usually includes system documentation to illustrate its functions, and IT-developed applications typically do not require such documentation – This is incorrect and reverses the reality. Traditional IT-developed applications typically include extensive system documentation, such as design documents, user manuals, and technical specifications, while UDAs often lack formal documentation because they are developed informally by users for their own use.
D. IT testing personnel usually review both types of applications thoroughly to ensure they were developed properly – This is incorrect. Traditional IT applications are typically reviewed and tested by IT testing personnel and quality assurance teams. UDAs, however, are usually not subject to the same rigorous IT testing and review; they are often used without independent testing or review, which is a significant risk associated with UDAs.
Reference:
IIA-CIA-Part3 content area on Information Technology — Specifically user-developed applications (UDAs), application controls, and the systems development life cycle.
GTAG (Global Technology Audit Guide) — Auditing User-Developed Applications (IIA), which describes UDAs as applications developed by end users outside the formal IT development process, often with little consideration of controls, documentation, or testing, in contrast to traditional IT applications developed under a formal SDLC.
An organization created a formalized plan for a large project. Which of the following should be the first step in the project management plan?
A. Estimate time required to complete the whole project.
B. Determine the responses to expected project risks.
C. Break the project into manageable components.
D. Identify resources needed to complete the project
Explanation
In project management, once a project is authorized and a formalized project management plan is being developed, one of the first steps is to define and break down the project scope into manageable components. This is accomplished through scope definition and the creation of a work breakdown structure (WBS), which decomposes the total project into smaller, more manageable deliverables and work packages. Breaking the project into manageable components is essential because it provides the foundation for all subsequent planning activities, including estimating time and cost, identifying resources, assigning responsibilities, identifying risks, and developing schedules. Without this decomposition, it is difficult to accurately estimate time, resources, or risks. Therefore, breaking the project into manageable components should be the first step in the project management plan.
Why the other options are incorrect:
A. Estimate time required to complete the whole project
– Estimating the time required for the entire project is a subsequent planning activity. Accurate time estimates depend on knowing the individual tasks and work packages, which come from breaking the project into manageable components. Time estimation cannot be done effectively before the project is decomposed.
B. Determine the responses to expected project risks
– Risk response planning comes after risk identification and analysis, which in turn depend on understanding the project scope and its components. Risk response planning is a later step in the project management plan, not the first.
D. Identify resources needed to complete the project
– Identifying resources is also a subsequent activity that depends on knowing what work needs to be done. Resource identification follows the decomposition of the project into manageable components, because you must first know the tasks before you can determine the resources required to perform them.
Reference:
IIA-CIA-Part3 content area on Business Acumen / Project Management — Specifically project planning, scope definition, and the work breakdown structure.
Which of the following IT layers would require the organization to maintain communication with a vendor in a tightly controlled and monitored manner?
A. Applications
B. Technical infrastructure.
C. External connections.
D. IT management
Explanation
External connections are the IT layer through which an organization's systems and networks communicate with outside parties, such as vendors, customers, business partners, and other external networks. Because external connections link the organization's internal environment to outside entities, they represent a significant security and operational risk. Maintaining communication with a vendor over an external connection requires a tightly controlled and monitored manner to ensure that access is authorized, data is protected, and any activity is logged and reviewed. This includes controls such as secure protocols, firewalls, encryption, authentication, monitoring, and clearly defined interface agreements. This makes external connections the IT layer where tightly controlled and monitored communication with a vendor is required.
Why the other options are incorrect:
A. Applications
– Applications are software programs that process data and support business functions. While applications may communicate with vendors (e.g., through APIs or interfaces), the control and monitoring of vendor communication is primarily a function of the external connection layer, not the application layer itself. Applications operate within the environment; external connections govern how data moves between the organization and outside parties.
B. Technical infrastructure
– Technical infrastructure includes hardware, networks, operating systems, and other foundational components that support IT services. While infrastructure supports external connections, the specific layer requiring tightly controlled and monitored communication with a vendor is the external connection layer, which governs interaction with outside parties.
D. IT management
– IT management refers to the governance, planning, and oversight of IT resources and activities. While IT management sets policies and controls over vendor communication, it is not itself the IT layer through which the communication occurs. The external connections layer is the technical point where vendor communication takes place and must be controlled and monitored.
Reference:
IIA-CIA-Part3 content area on Information Technology — Specifically IT layers, external connections, third-party access, and network security controls.
A large retail customer made an offer to buy 10.000 units at a special price of $7 per unit. The manufacturer usually sells each unit for §10, Variable Manufacturing costs are 55 per unit and fixed manufacturing costs are $3 per unit. For the manufacturer to accept the offer, which of the following assumptions needs to be true?
A. Fixed and Variable manufacturing costs are less than the special offer selling price.
B. The manufacturer can fulfill the order without expanding the capacities of the production facilities.
C. Costs related to accepting this offer can be absorbed through the sale of other products.
D. The manufacturer’s production facilities are currently operating at full capacity.
Explanation
When evaluating a special order at a reduced price, the manufacturer must consider whether it has sufficient available (idle) production capacity to fulfill the order without disrupting normal sales or incurring additional fixed costs. If the manufacturer must expand capacity, for example, by purchasing new equipment, renting additional space, or paying overtime, then additional fixed costs or incremental costs would be incurred, potentially making the special order unprofitable. However, if the manufacturer can fulfill the order using existing capacity, the only relevant costs are the variable manufacturing costs ($5 per unit), and the special order price of $7 per unit would contribute $2 per unit toward covering fixed costs and increasing profit. Therefore, the key assumption for the manufacturer to accept the offer is that it can fulfill the order without expanding its production capacity, making option B the correct answer.
Why the other options are incorrect:
A. Fixed and variable manufacturing costs are less than the special offer selling price
– This is not the correct criterion. Fixed manufacturing costs are typically irrelevant to a special order decision when there is available capacity because they do not change with the order. The relevant comparison is between the special offer price and the variable (incremental) costs, not total fixed plus variable costs. Since fixed costs ($3 per unit) plus variable costs ($5 per unit) equal $8 per unit, which exceeds the $7 special price, this assumption would actually suggest rejecting the order, which is not the correct basis for the decision.
C. Costs related to accepting this offer can be absorbed through the sale of other products
– This statement is vague and does not represent a valid assumption for accepting a special order. Special order decisions should be based on the incremental costs and benefits of the order itself, not on absorbing costs through other products. Absorbing costs through other sales is an allocation concept, not a decision criterion for a special order.
D. The manufacturer's production facilities are currently operating at full capacity
– If the manufacturer is operating at full capacity, accepting the special order would require either displacing regular sales, which are more profitable at $10 per unit, or expanding capacity, which would incur additional costs. In either case, accepting the special order at $7 would likely not be beneficial. The correct assumption is the opposite: the manufacturer must have available capacity, not be operating at full capacity.
Reference:
IIA-CIA-Part3 content area on Financial Management / Managerial Accounting — Specifically relevant costing, special order decisions, and the treatment of fixed versus variable costs.
While conducting' audit procedures at the organization's data center an internal auditor
noticed the following:
- Backup media was located on data center shelves.
- Backup media was organized by date.
- Backup schedule was one week in duration.
The system administrator was able to present restore logs.
Which of the following is reasonable for the internal auditor to conclude?
A. Backup media is not properly stored, as the storage facility should be off-site.
B. Backup procedures are adequate and appropriate according to best practices.
C. Backup media is not properly indexed, as backup media should be indexed by system, not date.
D. Backup schedule is not sufficient, as full backup should be conducted daily.
Explanation
When backup media is located on shelves within the data center itself, it is stored at the same physical location as the systems it is meant to protect. This defeats a key purpose of backup storage: if a disaster (fire, flood, theft, or other physical destruction) occurs at the data center, both the original data and the onsite backups could be destroyed simultaneously, making recovery impossible. Best practice requires that backup media be stored off-site in a secure location, with at least one copy maintained at a remote site. Because the auditor observed backup media stored on data center shelves, it is reasonable to conclude that the backup media is not properly stored, the storage facility should be off-site, making option A the correct conclusion.
Why the other options are incorrect:
B. Backup procedures are adequate and appropriate according to best practices
– This conclusion is not reasonable because the auditor observed a significant control weakness: backup media stored onsite rather than offsite. Best practices require offsite storage of backups, so the procedures are not fully adequate. The presence of restore logs and an organized backup schedule does not offset the failure to store backups offsite.
C. Backup media is not properly indexed, as backup media should be indexed by system, not date
– Organizing backup media by date is a common and generally acceptable practice because it allows the organization to locate the most recent backups quickly and manage retention. There is no requirement that backups be indexed by system rather than date. The auditor's concern should be the location of storage, not the indexing method, so this conclusion is not reasonable.
D. Backup schedule is not sufficient, as full backup should be conducted daily
– The auditor observed that the backup schedule was one week in duration. Whether a weekly full backup (with incremental or differential backups in between) is sufficient depends on the organization's recovery point objective (RPO) and the criticality of the data. There is no universal rule that a full backup must be conducted daily; many organizations use a weekly full backup supplemented by daily incremental or differential backups. This conclusion is not supported by the facts as stated.
Reference:
IIA-CIA-Part3 content area on Information Technology — Specifically backup procedures, offsite storage, and disaster recovery controls.
The management of working capital is most crucial for which of the following aspects of business?
A. Liquidity
B. Profitability
C. Solvency
D. Efficiency
Explanation
Working capital is the difference between current assets and current liabilities, and its management focuses on ensuring that the organization has sufficient short-term resources to meet its short-term obligations as they come due. Managing working capital, including cash, accounts receivable, inventory, and accounts payable, is most crucial for maintaining liquidity. Liquidity refers to the organization's ability to pay its short-term debts and obligations without disruption. If working capital is poorly managed (e.g., too much cash tied up in inventory or slow collections), the organization may struggle to meet its immediate obligations, even if it is profitable. Therefore, working capital management is most crucial for liquidity.
Why the other options are incorrect:
B. Profitability
– Profitability refers to the organization's ability to generate earnings relative to revenues, assets, and equity. While working capital management can affect profitability (e.g., by reducing holding costs or avoiding excessive financing costs), its primary focus is on short-term liquidity, not on generating profits. An organization can be profitable and still have liquidity problems if working capital is poorly managed.
C. Solvency
– Solvency refers to the organization's ability to meet its long-term obligations and remain financially viable over the long term. It is assessed using measures such as debt-to-equity and interest coverage. Working capital management primarily addresses short-term financial health (liquidity), not long-term solvency, so solvency is not the aspect most crucial to working capital management.
D. Efficiency
– Efficiency refers to how well the organization uses its assets to generate revenue (e.g., asset turnover, inventory turnover). While working capital management involves efficiency considerations (such as inventory turnover and collection periods), the fundamental purpose of managing working capital is to maintain liquidity, ensuring the organization can meet its short-term obligations. Efficiency is a related but secondary consideration.
Reference:
IIA-CIA-Part3 content area on Financial Management — Specifically working capital management, liquidity, and short-term financial management.
Which of the following best describes a transformational leader, as opposed to a transactional leader?
A. The leader searches for deviations from the rules and standards and intervenes when deviations exist.
B. The leader intervenes only when performance standards are not met.
C. The leader intervenes to communicate high expectations.
D. The leader does not intervene to promote problem-solving
Explanation
Transformational leadership is a leadership style in which the leader inspires and motivates employees to exceed expectations, embrace a shared vision, and achieve higher levels of performance and personal development. Transformational leaders intervene by communicating high expectations, articulating a compelling vision, providing intellectual stimulation, and offering individualized consideration. By setting high expectations and inspiring employees to reach beyond their normal performance levels, transformational leaders create change and drive improvement. This contrasts with transactional leadership, which focuses on exchanges (rewards for performance), monitoring deviations, and intervening only when standards are not met. This makes communicating high expectations the best description of a transformational leader.
Why the other options are incorrect:
A. The leader searches for deviations from the rules and standards and intervenes when deviations exist
– This describes transactional leadership (specifically management by exception-active), where the leader monitors for deviations from rules and standards and takes corrective action when they occur. This is a transactional, not transformational, behavior.
B. The leader intervenes only when performance standards are not met
– This describes transactional leadership (management by exception-passive), where the leader takes action only when problems become serious or standards are not met. It is a reactive, transactional approach rather than a transformational one.
D. The leader does not intervene to promote problem-solving
– This does not accurately describe either transformational or transactional leadership. Transformational leaders actively intervene to inspire, motivate, and develop employees, including promoting problem-solving through intellectual stimulation. A leader who does not intervene at all would be more accurately described as laissez-faire, not transformational.
Reference:
IIA-CIA-Part3 content area on Business Acumen / Organizational Behavior — Specifically leadership styles, including transformational versus transactional leadership.
| Page 22 out of 58 Pages |
| 131415161718192021222324252627282930 |
| IIA-CIA-Part3 Practice Test Home |
Real-World Scenario Mastery: Our IIA-CIA-Part3 practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before Certified Internal Auditor Part 3 - Internal Audit Function exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive IIA-CIA-Part3 practice exam questions pool covering all topics, the real exam feels like just another practice session.