IIA-CIA-Part3-CN Exam Question 111
組織的庫存週轉率下降,但毛利率上升,下列哪一項敘述最能解釋這種情況?
Correct Answer: D
A declining inventory turnover means that inventory is sitting longer before being sold, while an increasing gross margin rate suggests the company is making higher profits on each sale. This combination is often a sign of inventory overstatement, possibly due to accounting errors or fraud.
Correct Answer (D - The Organization's Inventory is Overstated)
Inventory turnover ratio = Cost of Goods Sold (COGS) / Average Inventory. A declining inventory turnover indicates higher inventory levels relative to sales.
Gross margin rate = (Revenue - COGS) / Revenue. An increasing gross margin means either higher selling prices or lower COGS.
Overstating inventory artificially reduces COGS, making gross margin appear higher.
The IIA's GTAG 8: Audit of Inventory Management explains that inflated inventory levels can distort financial reporting and lead to misinterpretations of business performance.
Why Other Options Are Incorrect:
Option A (Operating expenses are increasing):
An increase in operating expenses would not directly explain declining inventory turnover or increasing gross margin.
Gross margin focuses on revenue and COGS, not operating expenses.
Option B (Just-in-Time Inventory):
A just-in-time (JIT) system reduces inventory levels, leading to higher inventory turnover, which contradicts the scenario.
Option C (Inventory Theft):
If theft were occurring, inventory levels would decrease, leading to higher turnover, not declining turnover.
GTAG 8: Audit of Inventory Management - Discusses inventory valuation risks, including overstatement and its impact on financial ratios.
IIA Practice Guide: Assessing Inventory Risks - Covers fraud risks related to inventory manipulation.
Step-by-Step Explanation:IIA References for Validation:Thus, the best explanation for a declining inventory turnover with an increasing gross margin rate is inventory overstatement (D).
Correct Answer (D - The Organization's Inventory is Overstated)
Inventory turnover ratio = Cost of Goods Sold (COGS) / Average Inventory. A declining inventory turnover indicates higher inventory levels relative to sales.
Gross margin rate = (Revenue - COGS) / Revenue. An increasing gross margin means either higher selling prices or lower COGS.
Overstating inventory artificially reduces COGS, making gross margin appear higher.
The IIA's GTAG 8: Audit of Inventory Management explains that inflated inventory levels can distort financial reporting and lead to misinterpretations of business performance.
Why Other Options Are Incorrect:
Option A (Operating expenses are increasing):
An increase in operating expenses would not directly explain declining inventory turnover or increasing gross margin.
Gross margin focuses on revenue and COGS, not operating expenses.
Option B (Just-in-Time Inventory):
A just-in-time (JIT) system reduces inventory levels, leading to higher inventory turnover, which contradicts the scenario.
Option C (Inventory Theft):
If theft were occurring, inventory levels would decrease, leading to higher turnover, not declining turnover.
GTAG 8: Audit of Inventory Management - Discusses inventory valuation risks, including overstatement and its impact on financial ratios.
IIA Practice Guide: Assessing Inventory Risks - Covers fraud risks related to inventory manipulation.
Step-by-Step Explanation:IIA References for Validation:Thus, the best explanation for a declining inventory turnover with an increasing gross margin rate is inventory overstatement (D).
IIA-CIA-Part3-CN Exam Question 112
某組織與第三方服務提供者簽訂了合同,負責規劃、設計和建造新設施。高階管理層希望將所有風險轉移給建築商。組織將使用哪種類型的採購合約?
Correct Answer: B
A turnkey contract is a type of procurement agreement where the contractor is responsible for the entire project from planning and design to construction and delivery, ensuring that the organization receives a fully operational facility. In this case, the organization wants to transfer all risks to the builder, making a turnkey contract the most appropriate choice.
Full Risk Transfer: The contractor assumes all project risks, including design flaws, cost overruns, and delays.
Single-Point Responsibility: The builder is accountable for all aspects of the project until it is fully operational.
Minimal Client Involvement: The client does not have to manage the project's complexities.
Option A (Cost-plus contract): This contract type does not transfer all risk to the builder; instead, the client bears some risk as they pay for actual costs plus a profit margin.
Option C (Service contract): Service contracts typically cover specific services (e.g., maintenance, consulting), not full construction projects.
Option D (Solutions contract): A solutions contract generally refers to software or technology solutions, not physical facility construction.
IIA's Practice Guide on Contract Management and Risk Transfer: Highlights turnkey contracts as a method to shift project risks to third parties.
IIA's Business Knowledge for Internal Auditing (CIA Exam Part 3 Syllabus): Covers procurement and contract types, emphasizing risk transfer mechanisms.
Why Option B is Correct:Why Other Options Are Incorrect:IIA References:Thus, the most appropriate answer is B. Turnkey contract.
Full Risk Transfer: The contractor assumes all project risks, including design flaws, cost overruns, and delays.
Single-Point Responsibility: The builder is accountable for all aspects of the project until it is fully operational.
Minimal Client Involvement: The client does not have to manage the project's complexities.
Option A (Cost-plus contract): This contract type does not transfer all risk to the builder; instead, the client bears some risk as they pay for actual costs plus a profit margin.
Option C (Service contract): Service contracts typically cover specific services (e.g., maintenance, consulting), not full construction projects.
Option D (Solutions contract): A solutions contract generally refers to software or technology solutions, not physical facility construction.
IIA's Practice Guide on Contract Management and Risk Transfer: Highlights turnkey contracts as a method to shift project risks to third parties.
IIA's Business Knowledge for Internal Auditing (CIA Exam Part 3 Syllabus): Covers procurement and contract types, emphasizing risk transfer mechanisms.
Why Option B is Correct:Why Other Options Are Incorrect:IIA References:Thus, the most appropriate answer is B. Turnkey contract.
IIA-CIA-Part3-CN Exam Question 113
以下哪些员工调查问题最能有效衡量员工的组织承诺?
Correct Answer: D
Organizational commitment reflects an employee's attachment, loyalty, identification with the organization, and willingness to support its success. Asking whether employees would recommend the organization as an employer is a strong measure because it captures overall commitment, advocacy, and confidence in the organization. Questions about training, manager behavior, and pay measure specific satisfaction factors, but they do not directly assess broader organizational commitment. An employee may be satisfied with pay or training but still lack loyalty or willingness to recommend the organization. Internal audit may use commitment indicators when evaluating culture, control environment, ethics, retention risk, and organizational health. Therefore, Option D is the most effective survey question.
IIA-CIA-Part3-CN Exam Question 114
某個組織建立了自帶設備 (BYOD) 工作環境。下列哪一項策略最能解決因該環境而對組織網路帶來的風險增加?
Correct Answer: C
* Understanding BYOD Risks:
* A Bring-Your-Own-Device (BYOD) policy allows employees to use personal devices (e.g., laptops, smartphones, tablets) for work.
* This increases security risks such as unauthorized access, malware infections, data leakage, and non-compliance with IT security policies.
* Why Option C (Detection and Authentication Controls) Is Correct?
* Detection and authentication controls ensure that:
* Only authorized devices can connect to the organization's network.
* User authentication mechanisms (such as multi-factor authentication) verify identities before granting access.
* Devices with security vulnerabilities are flagged and restricted.
* This aligns with IIA Standard 2110 - Governance, which emphasizes IT security controls for risk mitigation.
* ISO 27001 and NIST Cybersecurity Framework also recommend device authentication and monitoring for secure network access.
* Why Other Options Are Incorrect?
* Option A (Limit personal use of employee devices):
* Limiting personal use does not fully address network security risks; malware can still infect devices.
* Option B (Control access through approvals and reviews):
* While access control is important, it does not mitigate the broader risks of compromised devices connecting to the network.
* Option D (Software scans and patch reminders):
* Patching is important, but it does not prevent unauthorized access or ensure authentication for devices.
* Implementing device detection and authentication controls is the most effective way to mitigate security risks in a BYOD environment.
* IIA Standard 2110 and ISO 27001 emphasize strong network security measures.
Final Justification:IIA References:
* IPPF Standard 2110 - Governance (IT Risk Management & BYOD Security)
* ISO 27001 - Information Security Management
* NIST Cybersecurity Framework - Access Control & Authentication
* A Bring-Your-Own-Device (BYOD) policy allows employees to use personal devices (e.g., laptops, smartphones, tablets) for work.
* This increases security risks such as unauthorized access, malware infections, data leakage, and non-compliance with IT security policies.
* Why Option C (Detection and Authentication Controls) Is Correct?
* Detection and authentication controls ensure that:
* Only authorized devices can connect to the organization's network.
* User authentication mechanisms (such as multi-factor authentication) verify identities before granting access.
* Devices with security vulnerabilities are flagged and restricted.
* This aligns with IIA Standard 2110 - Governance, which emphasizes IT security controls for risk mitigation.
* ISO 27001 and NIST Cybersecurity Framework also recommend device authentication and monitoring for secure network access.
* Why Other Options Are Incorrect?
* Option A (Limit personal use of employee devices):
* Limiting personal use does not fully address network security risks; malware can still infect devices.
* Option B (Control access through approvals and reviews):
* While access control is important, it does not mitigate the broader risks of compromised devices connecting to the network.
* Option D (Software scans and patch reminders):
* Patching is important, but it does not prevent unauthorized access or ensure authentication for devices.
* Implementing device detection and authentication controls is the most effective way to mitigate security risks in a BYOD environment.
* IIA Standard 2110 and ISO 27001 emphasize strong network security measures.
Final Justification:IIA References:
* IPPF Standard 2110 - Governance (IT Risk Management & BYOD Security)
* ISO 27001 - Information Security Management
* NIST Cybersecurity Framework - Access Control & Authentication
IIA-CIA-Part3-CN Exam Question 115
在會計中,關於借方和貸方術語,下列哪一項敘述是正確的?
Correct Answer: C
In accounting, the terms debit (Dr.) and credit (Cr.) refer to the two sides of an account in the double-entry accounting system.
Definition of Debit and Credit in Accounting:
Every financial transaction affects at least two accounts in a double-entry system: one account is debited, and another is credited.
Debits (Dr.) appear on the left side, while credits (Cr.) appear on the right side of an account.
Accounting Equation:
Step-by-Step Justification:Assets=Liabilities+Equity\text{Assets} = \text{Liabilities} + \text{Equity} Assets=Liabilities+Equity Debits increase assets and expenses.
Credits increase liabilities, equity, and revenues.
Why the Other Options Are Incorrect:
A). Debit indicates the right side of an account and credit the left side # Incorrect, as debits are always recorded on the left side, and credits are always on the right side.
B). Debit means an increase in an account and credit means a decrease. # Partially incorrect; it depends on the type of account:
For assets and expenses, debits increase and credits decrease.
For liabilities, equity, and revenues, credits increase and debits decrease.
D). Credit means an increase in an account and debit means a decrease. # Also incorrect because increases and decreases depend on the type of account (e.g., debits increase assets but decrease liabilities).
IIA Standard 1210.A1: Internal auditors must be familiar with fundamental accounting principles.
IIA Practice Guide: Auditing Financial Statements: Ensures proper understanding of debits and credits in financial reporting.
GAAP & IFRS Accounting Standards: Define how debits and credits are recorded in financial statements.
IIA References:Thus, the correct answer is C. Credit indicates the right side of an account and debit the left side. #
Definition of Debit and Credit in Accounting:
Every financial transaction affects at least two accounts in a double-entry system: one account is debited, and another is credited.
Debits (Dr.) appear on the left side, while credits (Cr.) appear on the right side of an account.
Accounting Equation:
Step-by-Step Justification:Assets=Liabilities+Equity\text{Assets} = \text{Liabilities} + \text{Equity} Assets=Liabilities+Equity Debits increase assets and expenses.
Credits increase liabilities, equity, and revenues.
Why the Other Options Are Incorrect:
A). Debit indicates the right side of an account and credit the left side # Incorrect, as debits are always recorded on the left side, and credits are always on the right side.
B). Debit means an increase in an account and credit means a decrease. # Partially incorrect; it depends on the type of account:
For assets and expenses, debits increase and credits decrease.
For liabilities, equity, and revenues, credits increase and debits decrease.
D). Credit means an increase in an account and debit means a decrease. # Also incorrect because increases and decreases depend on the type of account (e.g., debits increase assets but decrease liabilities).
IIA Standard 1210.A1: Internal auditors must be familiar with fundamental accounting principles.
IIA Practice Guide: Auditing Financial Statements: Ensures proper understanding of debits and credits in financial reporting.
GAAP & IFRS Accounting Standards: Define how debits and credits are recorded in financial statements.
IIA References:Thus, the correct answer is C. Credit indicates the right side of an account and debit the left side. #
- Latest Upload
- 138PECB.ISO-14001-Lead-Auditor.v2026-08-14.q31
- 268CompTIA.SY0-701.v2026-08-14.q385
- 171CompTIA.XK0-006.v2026-08-14.q82
- 139Cisco.700-250.v2026-08-14.q34
- 262Cisco.300-420.v2026-08-13.q190
- 294IIA.IIA-CIA-Part3-CN.v2026-08-13.q328
- 174Fortinet.NSE7_SSE_AD-25.v2026-08-12.q38
- 238CyberAB.CMMC-CCP.v2026-08-12.q96
- 177SAP.C_ARCON.v2026-08-12.q39
- 167SAP.C_CR125.v2026-08-12.q33
[×]
Download PDF File
Enter your email address to download IIA.IIA-CIA-Part3-CN.v2026-08-13.q328 Practice Test
