Which of the following is most appropriately placed in the financing section of an organization's cash budget?
A. Collections from customers
B. Sale of securities.
C. Purchase of trucks.
D. Payment of debt, including interest
Explanation:
A cash budget is divided into three main sections:
Operating (Receipts and Disbursements) – day-to-day cash inflows and outflows.
Investing – cash flows from buying/selling long-term assets.
Financing – cash flows related to borrowing, repaying debt, and equity transactions.
The financing section includes cash flows from obtaining or repaying capital, such as loan repayments, interest payments, dividend payments, and proceeds from issuing stock or bonds. Therefore, payment of debt, including interest, is the most appropriate item to place in the financing section, as it directly relates to the organization's capital structure and debt obligations.
Why the other options are incorrect:
A. Collections from customers. This is an operating cash receipt from the organization's core business activities (sales), not a financing activity.
B. Sale of securities. This is ambiguous. If "securities" refers to equity or debt securities issued by the organization, it would be financing. However, in standard financial terminology, "sale of securities" typically means trading securities (investments) held by the organization, which falls under investing activities. The question uses "sale of securities" in the context of marketable securities, making it an investing activity.
C. Purchase of trucks. This is an investing cash outflow, as trucks are long-term productive assets (property, plant, and equipment), not a financing transaction.
References:
CIA Part 3 Syllabus – Financial Management / Cash Budgeting: Tests the candidate's understanding of the three sections of a cash budget: operating, investing, and financing.
Corporate Finance / Managerial Accounting: The financing section includes debt-related cash flows (borrowing, repayments, interest), equity transactions, and dividend payments.
According to The IIA's Three Lines Model, which of the following IT security activities is commonly shared by all three lines?
A. Assessments of third parties and suppliers.
B. Recruitment and retention of certified IT talent.
C. Classification of data and design of access privileges.
D. Creation and maintenance of secure network and device configuration.
Explanation:
According to The IIA's Three Lines Model, the three lines work together to achieve effective risk management and governance. Data classification and access privilege design is a core security activity that requires collaboration across all three lines:
First line (operational management) implements and maintains access controls, applying least privilege principles to ensure employees have only the access needed for their roles.
Second line (risk, compliance, InfoSec) provides oversight, establishes policies, monitors compliance, and challenges the design of access privileges to ensure alignment with risk appetite.
Third line (internal audit) provides independent assurance that data classification and access controls are designed effectively and operating as intended.
This shared responsibility—from implementation to oversight to assurance—makes it the most appropriate choice for an activity commonly shared by all three lines.
Why the other options are incorrect:
A. Assessments of third parties and suppliers. This is primarily a second-line function (e.g., Third-Party Risk Management). While internal audit (third line) may review this process, the first line does not typically perform supplier assessments.
B. Recruitment and retention of certified IT talent. This is a first-line HR/operational activity. The second line may set policy, and the third line may assess staffing adequacy, but it is not a security control actively executed or shared by all three lines.
D. Creation and maintenance of secure network and device configuration. This is a hands-on first-line technical activity performed by network/system administrators. While the second line provides oversight and the third line provides assurance, the actual creation and maintenance are not shared activities—they are executed by the first line.
References:
The IIA's Three Lines Model (2017/2020): Defines the roles: first line (operational management) owns risks and controls; second line (risk/compliance/security) provides oversight and challenge; third line (internal audit) provides independent assurance. Data classification and access control require coordination across all lines to ensure effective governance.
An organization that soils products to a foreign subsidiary wants to charge a price that wilt decrease import tariffs. Which of the following is the best course of action for the organization?
A. Decrease the transfer price
B. Increase the transfer price
C. Charge at the arm's length price
D. Charge at the optimal transfer price
Explanation:
To decrease import tariffs on goods sold to a foreign subsidiary, the organization should decrease the transfer price. The customs value—the basis upon which import tariffs are calculated—is typically derived from the invoice price of the goods. By lowering this intercompany price, the organization directly reduces the dutiable value, thereby decreasing the tariff liability .
This creates a direct trade-off: a lower transfer price minimizes tariffs but increases the taxable profit of the importing entity, while a higher transfer price inflates tariffs but reduces taxable profit in the import country . Organizations must weigh the cost of cross-border duties against their income tax exposure.
Why the other options are incorrect:
B. Increase the transfer price. This would increase the customs value and therefore increase import tariffs—the opposite of the desired outcome .
C. Charge at the arm's length price. While the arm's length principle is the internationally accepted standard for transfer pricing, it is not a tactical tool for decreasing tariffs . Charging the arm's length price simply satisfies tax compliance; it does not inherently minimize tariff exposure . Moreover, tax authorities and customs have different valuation criteria, and a price accepted for tax purposes may not be acceptable for customs .
D. Charge at the optimal transfer price. This is vague. While "optimal" could theoretically include tariff minimization, the specific tactic for reducing tariffs is to lower the transfer price—making option A the precise, actionable answer .
References:
Customs Valuation: Under the WTO Valuation Agreement, the transaction value (typically the invoice price) is the primary basis for customs value and tariff calculation .
Transfer Pricing & Tariffs: Lower transfer prices directly reduce customs value and tariff costs, though this must be balanced against income tax consequences .
What is the primary purpose of data and systems backup?
A. To restore all data and systems immediately after the occurrence of an incident.
B. To set the maximum allowable downtime to restore systems and data after the occurrence of an incident.
C. To set the point in time to which systems and data must be recovered after the occurrence of an incident.
D. To restore data and systems to a previous point in time after the occurrence of an incident
Explanation:
The primary purpose of data and systems backup is to create recoverable copies of information and system configurations that can be used to restore operations to a previous point in time following an incident—such as hardware failure, cyberattack (e.g., ransomware), human error, or natural disaster. Backups are the fundamental mechanism for recovery, enabling the organization to retrieve lost or corrupted data and resume business functions. Without backups, restoration is impossible; with them, the organization can roll back to a known good state (defined by the Recovery Point Objective – RPO) and recover from the disruption.
Why the other options are incorrect:
A. To restore all data and systems immediately after the occurrence of an incident.
This describes the Recovery Time Objective (RTO) and near-instantaneous recovery, which is the goal of hot sites or real-time replication, not the purpose of backups themselves. Backups enable recovery, but not necessarily immediate recovery.
B. To set the maximum allowable downtime to restore systems and data after the occurrence of an incident.
This defines the Recovery Time Objective (RTO)—a business continuity metric, not the purpose of backups. Backups are the means; RTO is the target.
C. To set the point in time to which systems and data must be recovered after the occurrence of an incident.
This defines the Recovery Point Objective (RPO)—a metric that specifies the maximum acceptable data loss. Backups help achieve the RPO, but the purpose of backups is restoration, not setting the metric.
References:
IIA GTAG – Business Continuity Management: Defines backups as the foundational recovery mechanism used to restore data and systems to a prior state after an incident.
IIA CIA Part 3 Syllabus – IT / Business Continuity & Disaster Recovery: Tests the candidate's understanding that backups enable restoration to a previous point, distinct from RTO and RPO, which are performance metrics.
In accounting, which of the following statements is true regarding the terms debit and credit?
A. Debit indicates the right side of an account and credit the left side
B. Debit means an increase in an account and credit means a decrease.
C. Credit indicates the right side of an account and debit the left side.
D. Credit means an increase in an account and debit means a decrease
Explanation:
In double-entry accounting, debit and credit are directional terms that indicate the side of an account where a transaction is recorded:
Debit (Dr.) always refers to the left side of an account.
Credit (Cr.) always refers to the right side of an account.
This is a fixed, universal rule in accounting, regardless of whether the account is an asset, liability, equity, revenue, or expense. The effect of a debit or credit (increase or decrease) depends on the type of account—not on the term itself. For example, a debit increases asset and expense accounts but decreases liability, equity, and revenue accounts. However, the side of the T-account is always consistent: debit = left, credit = right.
Why the other options are incorrect:
A. Debit indicates the right side of an account and credit the left side.
This is the exact opposite of the correct rule. Debit is left; credit is right.
B. Debit means an increase in an account and credit means a decrease.
This is false because the effect depends on the account type. For example, a debit increases an asset but decreases a liability. This statement is an oversimplification that ignores the account classification.
D. Credit means an increase in an account and debit means a decrease.
This is also false for the same reason. A credit increases liabilities and revenues but decreases assets and expenses. The effect is not fixed.
References:
GAAP / Double-Entry Accounting: The foundational rule is that debits are recorded on the left side of an account, and credits on the right side. The effect on account balances depends on the account type (asset, liability, equity, revenue, expense).
CIA Part 3 Syllabus – Financial Management / Accounting: Tests the candidate's understanding of the fundamental accounting equation and the mechanics of debits and credits.
Which of the following describes a third-party network that connects an organization specifically with its trading partners?
A. Value-added network (VAN).
B. Local area network (LAN).
C. Metropolitan area network (MAN).
D. Wide area network (WAN).
Explanation:
A Value-Added Network (VAN) is a private, third-party managed network that is specifically designed to facilitate secure, reliable, and standardized electronic data interchange (EDI) between an organization and its trading partners (e.g., suppliers, customers, logistics providers). VANs provide value-added services beyond basic data transmission, such as protocol translation, message validation, data encryption, audit trails, and store-and-forward capabilities. They are the traditional backbone for B2B e-commerce and supply chain communication, ensuring that business documents (e.g., purchase orders, invoices, shipping notices) are exchanged accurately and securely between external partners.
Why the other options are incorrect:
B. Local area network (LAN).
A LAN is a network confined to a small geographic area (e.g., a single office or building) that connects internal devices. It does not connect an organization to external trading partners.
C. Metropolitan area network (MAN).
A MAN spans a larger geographic area than a LAN, typically a city or metropolitan region. While it may connect multiple buildings, it is not specifically designed for trading partner communication.
D. Wide area network (WAN).
A WAN spans large geographic distances (e.g., countries or continents) and connects multiple LANs. While a VAN can operate over a WAN infrastructure, a WAN itself is a general-purpose network, not specifically a third-party network for trading partner EDI.
References:
IIA GTAG – Auditing Electronic Data Interchange (EDI) and VANs: Defines VANs as third-party networks that provide secure, managed EDI services for trading partner communication, including data translation and audit trails.
Which of the following physical access control is most likely to be based on ’’something you have" concept?
A. A retina characteristics reader
B. A P3M code reader
C. A card-key scanner
D. A fingerprint scanner
Explanation:
Physical access controls are categorized based on the three authentication factors:
Something you know (e.g., PIN, password)
Something you have (e.g., card-key, token, smart card, key fob)
Something you are (e.g., fingerprint, retina, voice)
A card-key scanner reads a physical credential (an access card or proximity card) that the user must possess to gain entry. This is the classic example of a "something you have" factor, as the user presents a tangible item that contains encoded identification data. The scanner validates the card's credentials and grants access if authorized.
Why the other options are incorrect:
A. A retina characteristics reader. This is a biometric control based on "something you are"—the unique pattern of blood vessels in the retina. It does not rely on possession.
B. A PIN code reader. This is based on "something you know"—a numeric secret that the user must memorize and enter. It is a knowledge-based factor, not possession-based.
D. A fingerprint scanner. This is another biometric control based on "something you are"—the unique ridge pattern of a fingerprint. It is not based on possession.
References:
IIA GTAG – Information Security Governance: Defines the three authentication factors—knowledge, possession, and inherence—and categorizes card-key readers as possession-based controls.
What is the primary purpose of an Integrity control?
A. To ensure data processing is complete, accurate, and authorized.
B. To ensure data being processed remains consistent and intact.
C. To ensure data being processed remains consistent and intact.
D. To ensure the output aligns with the intended result.
Explanation:
An integrity control is designed to protect data from unauthorized modification, corruption, or loss during processing, storage, or transmission. Its primary purpose is to ensure that data remains consistent, accurate, and intact throughout its lifecycle. Integrity controls include mechanisms such as checksums, hashing, parity checks, reconciliation, and edit checks to detect and prevent data alteration or errors. In the context of the CIA Triad (Confidentiality, Integrity, Availability), integrity is specifically about preserving the trustworthiness and completeness of data.
Why the other options are incorrect:
A. To ensure data processing is complete, accurate, and authorized. This is a broader description of application controls in general (encompassing completeness, accuracy, and authorization), not specifically the primary purpose of integrity controls. Integrity controls focus on maintaining data consistency, not all three objectives.
C. To ensure data being processed remains consistent and intact. (This is identical to B.) Since B is the correct answer, C is a duplicate and not a separate valid option.
D. To ensure the output aligns with the intended result. This describes validation or output controls (verifying that outputs are correct), not the specific purpose of integrity controls. Integrity focuses on the data itself during processing, not just final outputs.
References:
IIA GTAG – Information Security Governance: Defines integrity controls as mechanisms to ensure data is not altered or destroyed and remains complete and accurate throughout processing.
IIA CIA Part 3 Syllabus – IT / Security Controls: Tests the candidate's understanding of the CIA Triad, where integrity is specifically about maintaining data consistency and intactness.
Which of the following situations best illustrates a "false positive" in the performance of a spam filter?
A. The spam filter removed Incoming communication that included certain keywords and domains.
B. The spam filter deleted commercial ads automatically, as they were recognized as unwanted.
C. The spam filter routed to the "junk|r folder a newsletter that appeared to include links to fake websites.
D. The spam filter blocked a fitness club gift card that coworkers sent to an employee for her birthday.
Explanation:
A "false positive" occurs when a security control (like a spam filter) incorrectly identifies a legitimate item as malicious or unwanted and takes action against it (e.g., blocks it or routes it to junk). In this scenario, the spam filter blocked a legitimate email—a gift card sent by coworkers for a birthday—mistakenly classifying it as spam. This is a classic false positive because the email was genuine and desired, yet it was incorrectly flagged and blocked.
Why the other options are incorrect:
A. The spam filter removed incoming communication that included certain keywords and domains.
This is a correct action based on predefined rules. If the keywords/domains are known spam indicators, this is a true positive (correctly identified spam), not a false positive.
B. The spam filter deleted commercial ads automatically, as they were recognized as unwanted.
This is also a true positive—commercial ads are typically unwanted and correctly classified as spam. The filter performed as intended.
C. The spam filter routed to the 'junk' folder a newsletter that appeared to include links to fake websites.
If the links were indeed suspicious or fake, this is a true positive—the filter correctly identified a potentially harmful newsletter. Even if the newsletter was legitimate but contained compromised links, the filter acted correctly.
References:
IIA GTAG – Information Security Governance: Defines false positives as instances where a security control incorrectly flags legitimate activity as a threat, leading to unnecessary disruptions and reduced user trust.
Which of the following risks would Involve individuals attacking an oil company's IT system as a sign of solidarity against drilling in a local area?
A. Tampering
B. Hacking
C. Phishing
D. Piracy
Explanation:
Hacking refers to unauthorized access, intrusion, or attacks on computer systems, networks, or digital infrastructure with the intent to disrupt, damage, steal information, or make a political or ideological statement. In this scenario, individuals attack the oil company's IT system as a sign of solidarity against drilling—this is a classic example of hacktivism (a form of hacking driven by political, social, or environmental motives). The attackers are deliberately breaching or disrupting the company's systems to advance their cause, which falls squarely under the definition of hacking.
Why the other options are incorrect:
A. Tampering. This involves unauthorized alteration or manipulation of data, systems, or physical assets (e.g., modifying records, damaging equipment). While hacking may include tampering, the scenario describes the act of attacking the IT system itself as a political statement, which is hacking—not specifically tampering.
C. Phishing. This is a social engineering attack where attackers deceive individuals into revealing sensitive information (e.g., passwords, credit card numbers) via fraudulent emails or messages. The scenario does not involve deception or credential theft; it involves a direct attack on the IT system as an act of solidarity.
D. Piracy. This typically refers to unauthorized copying, distribution, or use of copyrighted software, media, or intellectual property. It does not involve attacking IT systems for political or environmental protest.
References:
IIA GTAG – Information Security Governance: Defines hacking as unauthorized access or intrusion into systems, often motivated by financial gain, espionage, or activism (hacktivism).
CIA Part 3 Syllabus – IT / Cybersecurity Threats: Tests the candidate's understanding of different threat types, including hacking, phishing, malware, and social engineering, and their distinguishing characteristics.
How do data analysis technologies affect internal audit testing?
A. They improve the effectiveness of spot check testing techniques.
B. They allow greater insight into high risk areas.
C. They reduce the overall scope of the audit engagement,
D. They increase the internal auditor's objectivity.
Explanation:
Data analysis technologies (e.g., data mining, continuous monitoring, visualization, and predictive analytics) enable internal auditors to analyze entire populations of data rather than relying solely on small samples. This provides greater insight into high-risk areas by identifying anomalies, patterns, outliers, and correlations that may not be visible through traditional sampling techniques. Auditors can stratify data, perform trend analysis, and focus their testing on the transactions or processes that pose the highest risk, thereby enhancing both the effectiveness and efficiency of the audit. The primary value of data analytics is its ability to uncover deeper, risk-relevant insights that drive audit focus and improve assurance quality.
Why the other options are incorrect:
A. They improve the effectiveness of spot check testing techniques.
Data analytics reduces reliance on spot checks and sampling by allowing full-population testing. Spot checks are a traditional, less effective technique that analytics often supplements or replaces.
C. They reduce the overall scope of the audit engagement.
Data analytics does not reduce the audit scope; rather, it may expand or refocus the scope by identifying new risk areas that warrant investigation. It improves coverage, not scope reduction.
D. They increase the internal auditor's objectivity.
Objectivity is a matter of auditor independence and mindset, not a direct result of using data analysis tools. While analytics may reduce bias in sample selection, objectivity is governed by professional standards and personal conduct, not technology.
References:
IIA GTAG – Data Analysis Technologies: Emphasizes that data analytics enables auditors to analyze entire datasets, identify high-risk transactions, and focus audit procedures on areas with the greatest risk exposure.
IIA Standard 1220.A2 – Due Professional Care: Auditors are expected to use analytical techniques to improve audit effectiveness and efficiency. Data analytics provides deeper risk insights.
Which of the following is a likely result of outsourcing?
A. Increased dependence on suppliers.
B. Increased importance of market strategy.
C. Decreased sensitivity to government regulation
D. Decreased focus on costs
Explanation:
Outsourcing involves transferring specific business functions, processes, or services to external third-party providers. A primary and direct consequence of outsourcing is that the organization becomes more dependent on its suppliers for the delivery of critical goods, services, or capabilities. This dependence introduces risks such as loss of internal expertise, reduced control over quality and timelines, potential vendor lock-in, and supply chain vulnerabilities. The organization must rely on the supplier's performance, security, and financial stability, which creates a strategic dependency that requires robust vendor management and oversight.
Why the other options are incorrect:
B. Increased importance of market strategy.
Outsourcing may affect operations, but it does not inherently increase the importance of market strategy (i.e., product positioning, branding, customer segmentation). Market strategy remains important regardless of outsourcing decisions.
C. Decreased sensitivity to government regulation.
Outsourcing increases sensitivity to regulations—especially data privacy (GDPR, CCPA), labor laws, and industry-specific compliance—because the organization remains accountable for the supplier's actions. It does not decrease regulatory exposure.
D. Decreased focus on costs.
Outsourcing is often driven by a desire to reduce or control costs (e.g., labor arbitrage, economies of scale). Therefore, it typically increases focus on costs, not decreases it.
References:
IIA GTAG – Auditing Outsourced Services and Third-Party Relationships: Identifies increased dependency on third parties as a key risk of outsourcing, requiring enhanced vendor oversight, contract management, and contingency planning.
IIA CIA Part 3 Syllabus – Operations / Outsourcing: Tests the candidate's understanding of the strategic and operational implications of outsourcing, including the risks of supplier dependency.
| Page 8 out of 58 Pages |
| 123456789101112131415161718 |
| IIA-CIA-Part3 Practice Test Home |
Real-World Scenario Mastery: Our IIA-CIA-Part3 practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before Certified Internal Auditor Part 3 - Internal Audit Function exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive IIA-CIA-Part3 practice exam questions pool covering all topics, the real exam feels like just another practice session.