IIA-CIA-Part3-CN Exam Question 46
以下哪一项是对企业的产品导向型定义,而不是对企业的市场导向型定义?
Correct Answer: C
A product-oriented definition describes the business by what it makes or sells. A market-oriented definition describes the customer need being satisfied. "We make movies" focuses on the product itself, so it is product- oriented. By contrast, "we are a people-and-goods mover" defines the customer need for transportation. "We supply energy" describes a broader market need rather than a single product. "We provide climate control in the home" focuses on the customer benefit, not merely the product. Internal auditors involved in strategy, planning, or operational reviews should understand this distinction because product-oriented thinking can create strategic risk if management ignores changing customer needs, substitute products, or market disruption. A market-oriented definition is usually more flexible and customer-focused. Therefore, Option C is correct.
IIA-CIA-Part3-CN Exam Question 47
組織網路安全風險評估架構的哪個元件允許管理階層根據使用者角色實施使用者控制?
Correct Answer: C
Information access management is the component of an organization's cybersecurity risk assessment framework that allows management to implement user controls based on a user's role. This principle, often referred to as Role-Based Access Control (RBAC), ensures that individuals have access only to the data and systems necessary for their job responsibilities.
Definition of Role-Based Access Control (RBAC):
RBAC assigns permissions based on an individual ' s role within the organization.
For example, a finance employee may access financial records, but not HR data.
Minimization of Insider Threats:
By limiting access to sensitive data, information access management helps reduce the risk of fraud, data breaches, and unauthorized modifications.
Regulatory Compliance:
Many regulations (e.g., GDPR, SOX, HIPAA) require companies to implement access control measures to protect sensitive information.
Internal auditors assess whether access management policies are enforced properly.
Alignment with Cybersecurity Risk Frameworks:
NIST Cybersecurity Framework - Access Control (AC) Family: Establishes guidelines for restricting access based on user identity and role.
ISO/IEC 27001 - Information Security Management System (ISMS): Requires organizations to implement access control policies to protect data integrity.
A). Prompt response and remediation policy: Focuses on incident response rather than proactive access control.
B). Inventory of information assets: Important for tracking IT assets but does not define access privileges.
D). Standard security configurations: Enforce security settings but do not manage access based on user roles.
IIA GTAG (Global Technology Audit Guide) on Information Security: Recommends implementing access control policies to restrict unauthorized access.
IIA Standard 2110 - Governance: Emphasizes the importance of cybersecurity governance, including role- based access management.
COBIT Framework - DSS05.04 (Manage User Identity and Access): Defines best practices for controlling user access based on organizational roles.
Step-by-Step Justification:Why Not the Other Options?IIA References:
Definition of Role-Based Access Control (RBAC):
RBAC assigns permissions based on an individual ' s role within the organization.
For example, a finance employee may access financial records, but not HR data.
Minimization of Insider Threats:
By limiting access to sensitive data, information access management helps reduce the risk of fraud, data breaches, and unauthorized modifications.
Regulatory Compliance:
Many regulations (e.g., GDPR, SOX, HIPAA) require companies to implement access control measures to protect sensitive information.
Internal auditors assess whether access management policies are enforced properly.
Alignment with Cybersecurity Risk Frameworks:
NIST Cybersecurity Framework - Access Control (AC) Family: Establishes guidelines for restricting access based on user identity and role.
ISO/IEC 27001 - Information Security Management System (ISMS): Requires organizations to implement access control policies to protect data integrity.
A). Prompt response and remediation policy: Focuses on incident response rather than proactive access control.
B). Inventory of information assets: Important for tracking IT assets but does not define access privileges.
D). Standard security configurations: Enforce security settings but do not manage access based on user roles.
IIA GTAG (Global Technology Audit Guide) on Information Security: Recommends implementing access control policies to restrict unauthorized access.
IIA Standard 2110 - Governance: Emphasizes the importance of cybersecurity governance, including role- based access management.
COBIT Framework - DSS05.04 (Manage User Identity and Access): Defines best practices for controlling user access based on organizational roles.
Step-by-Step Justification:Why Not the Other Options?IIA References:
IIA-CIA-Part3-CN Exam Question 48
某组织的内部审计部门正在开展人力资源审计。作为审计的一部分,他们进行了一项员工调查。调查显示,员工在办公室外工作时对信息安全感到担忧。信息技术部门建议部署一个网络,使员工能够像连接到专用网络一样发送和接收数据。
IT部门推荐以下哪种网络?
IT部门推荐以下哪种网络?
Correct Answer: C
A virtual private network allows users outside the office to securely send and receive data as though they were connected to the organization's private internal network. VPNs commonly use encryption, tunneling, and authentication to protect remote access over public networks. A local area network is limited to a specific location such as an office or building. A wide area network links multiple locations over a broader geographic area, but it does not specifically describe secure remote access for employees. A global area network is broader and not the best fit for the described control. Internal auditors reviewing remote work should evaluate VPN configuration, encryption, authentication, logging, endpoint security, and access rights. Therefore, Option C is correct.
IIA-CIA-Part3-CN Exam Question 49
下列哪一項代表了管理階層可以操縱的庫存成本計算技術,透過出售以低成本購買的單位來增加淨利潤?
Correct Answer: A
The FIFO (First-In, First-Out) method values inventory based on the assumption that older, lower-cost inventory is sold first, leaving newer, higher-cost inventory in stock. During periods of rising prices, FIFO results in lower cost of goods sold (COGS) and higher net income, making it susceptible to manipulation by management.
(A) Correct - First-in, first-out method (FIFO).
FIFO lowers COGS when older, cheaper inventory is sold first, inflating net income.
Management can manipulate earnings by selectively selling older, lower-cost inventory.
(B) Incorrect - Last-in, first-out method (LIFO).
LIFO assumes newer, higher-cost inventory is sold first, resulting in higher COGS and lower net income.
LIFO is typically used to reduce taxable income, not to inflate net income.
(C) Incorrect - Specific identification method.
This method tracks the exact cost of each unit, eliminating the ability to manipulate costs easily.
(D) Incorrect - Average-cost method.
The average-cost method smooths out fluctuations in inventory costs, preventing significant income manipulation.
IIA's Global Internal Audit Standards - Financial Reporting and Inventory Valuation Risks Discusses inventory accounting methods and their impact on financial statements.
IFRS and GAAP Accounting Standards - Inventory Valuation
Defines how FIFO can be used to influence financial performance.
COSO's ERM Framework - Financial Manipulation Risks
Identifies inventory valuation as an area where earnings management can occur.
Analysis of Answer Choices:IIA References and Internal Auditing Standards:
(A) Correct - First-in, first-out method (FIFO).
FIFO lowers COGS when older, cheaper inventory is sold first, inflating net income.
Management can manipulate earnings by selectively selling older, lower-cost inventory.
(B) Incorrect - Last-in, first-out method (LIFO).
LIFO assumes newer, higher-cost inventory is sold first, resulting in higher COGS and lower net income.
LIFO is typically used to reduce taxable income, not to inflate net income.
(C) Incorrect - Specific identification method.
This method tracks the exact cost of each unit, eliminating the ability to manipulate costs easily.
(D) Incorrect - Average-cost method.
The average-cost method smooths out fluctuations in inventory costs, preventing significant income manipulation.
IIA's Global Internal Audit Standards - Financial Reporting and Inventory Valuation Risks Discusses inventory accounting methods and their impact on financial statements.
IFRS and GAAP Accounting Standards - Inventory Valuation
Defines how FIFO can be used to influence financial performance.
COSO's ERM Framework - Financial Manipulation Risks
Identifies inventory valuation as an area where earnings management can occur.
Analysis of Answer Choices:IIA References and Internal Auditing Standards:
IIA-CIA-Part3-CN Exam Question 50
某組織第一年和第二年的毛利率均為 40%。第一年淨利率為 18%,第二年淨利率為 13%。下列哪一項可能是第二年淨利率下降的原因?
Correct Answer: D
The net profit margin is calculated as:
Net Profit Margin=Net ProfitTotal Sales×100\text{Net Profit Margin} = \frac{\text{Net Profit}}{\text{Total Sales}} \times 100Net Profit Margin=Total SalesNet Profit×100 The given data shows:
Gross profit margin (Revenue - Cost of Goods Sold) remained constant at 40% in both years.
Net profit margin declined from 18% in Year 1 to 13% in Year 2.
Since the gross profit margin remained unchanged, the cost of sales did not increase relative to sales. This eliminates Option A as a possible cause.
A decline in net profit margin while gross profit remains the same suggests an increase in operating expenses, interest, or taxes.
If the government increased the corporate tax rate, net income after taxes would be lower, leading to a reduced net profit margin.
The IIA's GTAG 14 - Auditing Governance, Risk, and Compliance recommends analyzing external factors like tax rate changes when evaluating financial performance.
A). Cost of sales increased relative to sales # Incorrect. If this were true, gross profit margin would have declined, but it remained stable.
B). Total sales increased relative to expenses # Incorrect. If sales increased while expenses stayed constant, net profit margin would have increased, not decreased.
C). The organization had a higher dividend payout rate in year two # Incorrect. Dividends do not affect net profit margin, as they are paid out from net income after it is calculated.
IIA Standard 2120 - Risk Management states that auditors should analyze changes in financial performance due to external economic factors.
COSO ERM Framework highlights tax rate changes as a key risk factor in financial analysis.
IFRS (International Financial Reporting Standards) require companies to disclose changes in tax rates and their impact on profitability.
Why Option D is Correct?Explanation of the Other Options:IIA References & Best Practices:Thus, the correct answer is D. The government increased the corporate tax rate.
Net Profit Margin=Net ProfitTotal Sales×100\text{Net Profit Margin} = \frac{\text{Net Profit}}{\text{Total Sales}} \times 100Net Profit Margin=Total SalesNet Profit×100 The given data shows:
Gross profit margin (Revenue - Cost of Goods Sold) remained constant at 40% in both years.
Net profit margin declined from 18% in Year 1 to 13% in Year 2.
Since the gross profit margin remained unchanged, the cost of sales did not increase relative to sales. This eliminates Option A as a possible cause.
A decline in net profit margin while gross profit remains the same suggests an increase in operating expenses, interest, or taxes.
If the government increased the corporate tax rate, net income after taxes would be lower, leading to a reduced net profit margin.
The IIA's GTAG 14 - Auditing Governance, Risk, and Compliance recommends analyzing external factors like tax rate changes when evaluating financial performance.
A). Cost of sales increased relative to sales # Incorrect. If this were true, gross profit margin would have declined, but it remained stable.
B). Total sales increased relative to expenses # Incorrect. If sales increased while expenses stayed constant, net profit margin would have increased, not decreased.
C). The organization had a higher dividend payout rate in year two # Incorrect. Dividends do not affect net profit margin, as they are paid out from net income after it is calculated.
IIA Standard 2120 - Risk Management states that auditors should analyze changes in financial performance due to external economic factors.
COSO ERM Framework highlights tax rate changes as a key risk factor in financial analysis.
IFRS (International Financial Reporting Standards) require companies to disclose changes in tax rates and their impact on profitability.
Why Option D is Correct?Explanation of the Other Options:IIA References & Best Practices:Thus, the correct answer is D. The government increased the corporate tax rate.
- Latest Upload
- 129PECB.ISO-14001-Lead-Auditor.v2026-08-14.q31
- 256CompTIA.SY0-701.v2026-08-14.q385
- 163CompTIA.XK0-006.v2026-08-14.q82
- 129Cisco.700-250.v2026-08-14.q34
- 246Cisco.300-420.v2026-08-13.q190
- 266IIA.IIA-CIA-Part3-CN.v2026-08-13.q328
- 174Fortinet.NSE7_SSE_AD-25.v2026-08-12.q38
- 237CyberAB.CMMC-CCP.v2026-08-12.q96
- 175SAP.C_ARCON.v2026-08-12.q39
- 165SAP.C_CR125.v2026-08-12.q33
[×]
Download PDF File
Enter your email address to download IIA.IIA-CIA-Part3-CN.v2026-08-13.q328 Practice Test
