IIA-CIA-Part3-CN Exam Question 66
下列哪一項最恰當地描述了組織面臨透過惡意資料加密所建立的拒絕服務威脅的網路攻擊?
Correct Answer: B
Ransomware is a type of cyberattack where malicious software encrypts an organization's data, making it inaccessible until a ransom is paid to the attacker. This aligns with the question's scenario, where denial-of- service is caused by malicious data encryption.
Let's analyze the options:
* A. Phishing:
* Phishing is a social engineering attack that tricks individuals into providing sensitive information, such as usernames, passwords, or credit card numbers. It does not involve encryption or direct denial-of-service.
* B. Ransomware (# Correct Answer):
* Ransomware encrypts critical data and demands a ransom for its release, effectively causing a denial-of-service scenario since the victim cannot access their own systems.
* Some well-known ransomware attacks include WannaCry and NotPetya.
* C. Hacking:
* Hacking is a broad term for unauthorized access to systems but does not specifically refer to denial-of-service through encryption. Ransomware is a specific type of hacking attack.
* D. Malware:
* Malware (malicious software) is a general category that includes viruses, trojans, worms, spyware, and ransomware. While ransomware is a type of malware, not all malware encrypts data to demand ransom.
* IIA Global Technology Audit Guide (GTAG) - Auditing Cybersecurity Risks - Discusses various cyber threats, including ransomware.
* NIST Cybersecurity Framework (CSF) - Defines ransomware as a major threat that disrupts business continuity.
* COBIT Framework (Control Objectives for Information and Related Technologies) - Addresses risks associated with ransomware and how internal auditors should assess controls.
* ISO/IEC 27001 - Information Security Management Systems (ISMS) - Identifies the importance of cybersecurity measures to prevent ransomware attacks.
IIA References:
Let's analyze the options:
* A. Phishing:
* Phishing is a social engineering attack that tricks individuals into providing sensitive information, such as usernames, passwords, or credit card numbers. It does not involve encryption or direct denial-of-service.
* B. Ransomware (# Correct Answer):
* Ransomware encrypts critical data and demands a ransom for its release, effectively causing a denial-of-service scenario since the victim cannot access their own systems.
* Some well-known ransomware attacks include WannaCry and NotPetya.
* C. Hacking:
* Hacking is a broad term for unauthorized access to systems but does not specifically refer to denial-of-service through encryption. Ransomware is a specific type of hacking attack.
* D. Malware:
* Malware (malicious software) is a general category that includes viruses, trojans, worms, spyware, and ransomware. While ransomware is a type of malware, not all malware encrypts data to demand ransom.
* IIA Global Technology Audit Guide (GTAG) - Auditing Cybersecurity Risks - Discusses various cyber threats, including ransomware.
* NIST Cybersecurity Framework (CSF) - Defines ransomware as a major threat that disrupts business continuity.
* COBIT Framework (Control Objectives for Information and Related Technologies) - Addresses risks associated with ransomware and how internal auditors should assess controls.
* ISO/IEC 27001 - Information Security Management Systems (ISMS) - Identifies the importance of cybersecurity measures to prevent ransomware attacks.
IIA References:
IIA-CIA-Part3-CN Exam Question 67
IT 審計員正在評估新購買的資訊系統的 IT 控制。審核員發現資料庫和應用程式等級未配置日誌記錄。營運管理層解釋說,他們沒有足夠的人員來管理日誌,而且他們認為保留日誌沒有任何好處。下列哪一項回答最能解釋與伐木實踐不足或缺失相關的風險?
Correct Answer: C
Logging at the database and application levels is a critical security control that enables monitoring, detecting, and investigating potential security incidents. The absence of logging significantly increases cybersecurity risks and can leave an organization vulnerable to undetected attacks.
Incident Response & Forensics: Without logs, the organization will be unable to determine the cause, origin, and impact of cyber incidents or system intrusions.
Compliance Requirements: Many regulatory frameworks (e.g., ISO 27001, NIST 800-53, GDPR, PCI-DSS, SOX) require logging for security monitoring and auditability.
Threat Detection: Logs help in identifying malicious activities, unauthorized access, and data breaches.
Accountability: Ensures that actions taken within the system can be traced back to specific users or administrators.
Option A (The organization will be unable to develop preventative actions based on analytics): While logging helps in analytics, its primary function is incident detection and forensic investigation.
Option B (The organization will not be able to trace and monitor the activities of database administrators):
This is partially correct, but logging is not just for administrators-it is essential for monitoring all system activities, including unauthorized access attempts.
Option D (The organization will be unable to upgrade the system to newer versions): Logging does not impact system upgrades; upgrades are related to software lifecycle management, not logging practices.
IIA's Global Technology Audit Guide (GTAG) - Information Security Controls recommends logging as a fundamental security control.
IIA Standard 2110 - IT Governance: Emphasizes the need for adequate IT risk management, including logging.
COSO Framework (Monitoring Component): Highlights the importance of system monitoring, which includes logging.
Why Option C is Correct:Why Other Options Are Incorrect:IIA References:Thus, the most appropriate answer is C. The organization will be unable to determine why intrusions and cyber incidents took place.
Incident Response & Forensics: Without logs, the organization will be unable to determine the cause, origin, and impact of cyber incidents or system intrusions.
Compliance Requirements: Many regulatory frameworks (e.g., ISO 27001, NIST 800-53, GDPR, PCI-DSS, SOX) require logging for security monitoring and auditability.
Threat Detection: Logs help in identifying malicious activities, unauthorized access, and data breaches.
Accountability: Ensures that actions taken within the system can be traced back to specific users or administrators.
Option A (The organization will be unable to develop preventative actions based on analytics): While logging helps in analytics, its primary function is incident detection and forensic investigation.
Option B (The organization will not be able to trace and monitor the activities of database administrators):
This is partially correct, but logging is not just for administrators-it is essential for monitoring all system activities, including unauthorized access attempts.
Option D (The organization will be unable to upgrade the system to newer versions): Logging does not impact system upgrades; upgrades are related to software lifecycle management, not logging practices.
IIA's Global Technology Audit Guide (GTAG) - Information Security Controls recommends logging as a fundamental security control.
IIA Standard 2110 - IT Governance: Emphasizes the need for adequate IT risk management, including logging.
COSO Framework (Monitoring Component): Highlights the importance of system monitoring, which includes logging.
Why Option C is Correct:Why Other Options Are Incorrect:IIA References:Thus, the most appropriate answer is C. The organization will be unable to determine why intrusions and cyber incidents took place.
IIA-CIA-Part3-CN Exam Question 68
隨著網路安全威脅的增加,管理階層應考慮下列哪些事項以確保實施強而有力的安全治理?
Correct Answer: D
Strong Security Governance Requires Well-Defined Policies:
Cybersecurity governance is built upon clear, documented, and enforceable security policies that outline expectations, roles, responsibilities, and processes.
Policies define acceptable behaviors, security controls, incident response, and compliance requirements.
IIA Standard 2110 - Governance: Requires organizations to establish effective IT security governance, including policies that address cybersecurity risks.
IIA GTAG (Global Technology Audit Guide) on Information Security Governance:
Recommends that clear policies should guide security controls, user access, and incident response to address cybersecurity threats.
A). Inventory of information assets (Incorrect)
While identifying critical information assets is essential for risk management, it does not constitute security governance on its own.
Asset inventories support governance but must be reinforced by policies that define how data should be protected.
B). Limited sharing of data files with external parties (Incorrect)
Restricting data sharing is a control measure, not a governance principle.
Policies define when, how, and under what conditions data can be shared securely.
C). Vulnerability assessment (Incorrect)
Assessments help identify security gaps but do not establish governance.
Effective governance ensures that vulnerabilities are identified, prioritized, and remediated in accordance with policies.
Explanation of Answer Choice D (Correct Answer):Explanation of Incorrect Answers:Conclusion:To ensure strong security governance, organizations must have clearly defined security policies (Option D) as a foundation for managing cybersecurity threats.
IIA References:
IIA Standard 2110 - Governance
IIA GTAG - Information Security Governance
Cybersecurity governance is built upon clear, documented, and enforceable security policies that outline expectations, roles, responsibilities, and processes.
Policies define acceptable behaviors, security controls, incident response, and compliance requirements.
IIA Standard 2110 - Governance: Requires organizations to establish effective IT security governance, including policies that address cybersecurity risks.
IIA GTAG (Global Technology Audit Guide) on Information Security Governance:
Recommends that clear policies should guide security controls, user access, and incident response to address cybersecurity threats.
A). Inventory of information assets (Incorrect)
While identifying critical information assets is essential for risk management, it does not constitute security governance on its own.
Asset inventories support governance but must be reinforced by policies that define how data should be protected.
B). Limited sharing of data files with external parties (Incorrect)
Restricting data sharing is a control measure, not a governance principle.
Policies define when, how, and under what conditions data can be shared securely.
C). Vulnerability assessment (Incorrect)
Assessments help identify security gaps but do not establish governance.
Effective governance ensures that vulnerabilities are identified, prioritized, and remediated in accordance with policies.
Explanation of Answer Choice D (Correct Answer):Explanation of Incorrect Answers:Conclusion:To ensure strong security governance, organizations must have clearly defined security policies (Option D) as a foundation for managing cybersecurity threats.
IIA References:
IIA Standard 2110 - Governance
IIA GTAG - Information Security Governance
IIA-CIA-Part3-CN Exam Question 69
下列哪项措施可以衡量即时流动性?
Correct Answer: A
The acid-test, or quick ratio, measures immediate liquidity by comparing the most liquid current assets to current liabilities. It usually excludes inventory and other less liquid current assets because they may not be quickly converted into cash. This makes it a stricter liquidity measure than the current ratio. The current ratio measures general short-term solvency, but it includes inventory and prepaid items. Profit margin measures profitability, not liquidity. Times interest earned measures the ability to cover interest expense from earnings, which is more closely related to solvency and debt service capacity. Internal auditors reviewing liquidity should consider quick ratio, cash flow, receivable quality, working capital, and cash conversion cycle.
Therefore, Option A is correct.
Therefore, Option A is correct.
IIA-CIA-Part3-CN Exam Question 70
高階管理層正在考慮是否採用直接核銷法或備抵法來記錄應收帳款壞帳。下列哪一項是使用直接沖銷法的最佳論點?
Correct Answer: A
The direct write-off method records bad debts only when an account is deemed uncollectible, meaning there is no estimation of bad debts in advance. This method is typically used when bad debts are immaterial (insignificant) because it does not adhere to the matching principle of accounting.
Simplicity and Practicality:
The direct write-off method is straightforward and only requires writing off bad debts as they occur.
It is best suited for companies where bad debt losses are minimal or rare.
Acceptable for Insignificant Losses:
If bad debts are not material, then estimating and recording an allowance in advance (as in the allowance method) may not be necessary.
Used by Small Businesses and Tax Accounting:
The IRS allows the direct write-off method for tax purposes because it recognizes expenses only when they occur.
Not Aligned with GAAP for Significant Losses:
Generally Accepted Accounting Principles (GAAP) prefer the allowance method, which estimates bad debts in advance to match expenses with related revenues.
B). It provides a better alignment with revenue:
Incorrect because the allowance method provides a better revenue-expense matching approach, not the direct write-off method.
C). It is the preferred method according to The IIA:
The IIA does not have a stated preference between the two methods; however, GAAP prefers the allowance method.
D). It states receivables at net realizable value on the balance sheet:
The allowance method states receivables at net realizable value (NRV) by estimating bad debts in advance, while the direct write-off method does not adjust receivables until a loss occurs.
IIA Standard 2120 - Risk Management: Internal auditors must assess financial risks, including credit risks and bad debt write-offs.
COSO Internal Control Framework - Financial Reporting Component: Emphasizes accurate financial reporting, where the allowance method is generally preferred for better estimation.
Key Reasons Why Option A is Correct:Why Other Options Are Incorrect:IIA References:Thus, the correct answer is A. It is useful when losses are considered insignificant.
Simplicity and Practicality:
The direct write-off method is straightforward and only requires writing off bad debts as they occur.
It is best suited for companies where bad debt losses are minimal or rare.
Acceptable for Insignificant Losses:
If bad debts are not material, then estimating and recording an allowance in advance (as in the allowance method) may not be necessary.
Used by Small Businesses and Tax Accounting:
The IRS allows the direct write-off method for tax purposes because it recognizes expenses only when they occur.
Not Aligned with GAAP for Significant Losses:
Generally Accepted Accounting Principles (GAAP) prefer the allowance method, which estimates bad debts in advance to match expenses with related revenues.
B). It provides a better alignment with revenue:
Incorrect because the allowance method provides a better revenue-expense matching approach, not the direct write-off method.
C). It is the preferred method according to The IIA:
The IIA does not have a stated preference between the two methods; however, GAAP prefers the allowance method.
D). It states receivables at net realizable value on the balance sheet:
The allowance method states receivables at net realizable value (NRV) by estimating bad debts in advance, while the direct write-off method does not adjust receivables until a loss occurs.
IIA Standard 2120 - Risk Management: Internal auditors must assess financial risks, including credit risks and bad debt write-offs.
COSO Internal Control Framework - Financial Reporting Component: Emphasizes accurate financial reporting, where the allowance method is generally preferred for better estimation.
Key Reasons Why Option A is Correct:Why Other Options Are Incorrect:IIA References:Thus, the correct answer is A. It is useful when losses are considered insignificant.
- Latest Upload
- 129PECB.ISO-14001-Lead-Auditor.v2026-08-14.q31
- 256CompTIA.SY0-701.v2026-08-14.q385
- 167CompTIA.XK0-006.v2026-08-14.q82
- 130Cisco.700-250.v2026-08-14.q34
- 257Cisco.300-420.v2026-08-13.q190
- 283IIA.IIA-CIA-Part3-CN.v2026-08-13.q328
- 174Fortinet.NSE7_SSE_AD-25.v2026-08-12.q38
- 237CyberAB.CMMC-CCP.v2026-08-12.q96
- 175SAP.C_ARCON.v2026-08-12.q39
- 166SAP.C_CR125.v2026-08-12.q33
[×]
Download PDF File
Enter your email address to download IIA.IIA-CIA-Part3-CN.v2026-08-13.q328 Practice Test
