IIA-CIA-Part3-CN Exam Question 131
当组织授予员工从组织外部访问 IT 资源的身份验证权限时,以下哪种网络最适合组织使用?
Correct Answer: D
A virtual private network is best for employees who need to authenticate and access organizational IT resources from outside the organization. A VPN creates an encrypted tunnel over a public or external network, allowing remote users to connect securely to internal resources. A local area network is limited to a specific physical site, such as an office. A wide area network connects geographically separated locations, but it is not specifically a secure remote-access mechanism for individual users. A metropolitan area network covers a city or metropolitan region. Internal auditors reviewing remote access should evaluate VPN authentication, encryption, logging, endpoint compliance, session timeout, access rights, and monitoring.
Therefore, Option D is correct.
Therefore, Option D is correct.
IIA-CIA-Part3-CN Exam Question 132
下列哪一項是使用分層控制結構的特性?
Correct Answer: B
A hierarchical control structure is a traditional organizational framework where decision-making authority flows from top management down through various levels of hierarchy. It is characterized by centralized control, strict policies, formal procedures, and well-defined roles. This structure impacts organizational commitment and employee behavior in several ways:
Centralized Decision-Making:
Employees have limited autonomy in decision-making, leading to reduced job satisfaction and lower commitment to the organization.
Decisions are made at higher levels, and lower-level employees often feel disconnected from strategic goals.
Strict Policies and Procedures:
While hierarchical structures emphasize control, they often result in excessive bureaucracy, reducing employees' sense of ownership.
Employees may perceive rigid rules as restrictive rather than empowering, diminishing their commitment.
Emphasis on Extrinsic Rewards:
In hierarchical organizations, extrinsic motivators such as salaries, promotions, and benefits are emphasized more than intrinsic motivation factors like personal growth, autonomy, or recognition.
This focus can lead to employees feeling less engaged or committed.
Higher Turnover Risk:
Employees with lower organizational commitment may seek opportunities elsewhere, increasing turnover rates.
Research indicates that organizations with rigid hierarchical structures tend to have higher turnover compared to flexible, participative structures.
Option A (Less use of policies and procedures): Incorrect. Hierarchical control structures rely heavily on policies and procedures to maintain control and consistency.
Option C (Less emphasis on extrinsic rewards): Incorrect. Hierarchical structures often focus more on extrinsic rewards such as salary, promotions, and bonuses to motivate employees.
Option D (Less employee turnover): Incorrect. Due to decreased organizational commitment, hierarchical structures often experience higher turnover rather than lower.
IIA Standard 1100 - Independence and Objectivity: Hierarchical structures can impact the independence and objectivity of internal auditors due to rigid reporting lines.
IIA's Global Perspectives & Insights Report - "The Future of Work": Discusses how traditional hierarchical structures may reduce employee engagement and commitment.
COSO Internal Control - Integrated Framework: Highlights the importance of organizational structure in shaping control environments and employee commitment.
Why Other Options Are Incorrect:IIA References:Thus, the correct answer is B. Less organizational commitment by employees.
Centralized Decision-Making:
Employees have limited autonomy in decision-making, leading to reduced job satisfaction and lower commitment to the organization.
Decisions are made at higher levels, and lower-level employees often feel disconnected from strategic goals.
Strict Policies and Procedures:
While hierarchical structures emphasize control, they often result in excessive bureaucracy, reducing employees' sense of ownership.
Employees may perceive rigid rules as restrictive rather than empowering, diminishing their commitment.
Emphasis on Extrinsic Rewards:
In hierarchical organizations, extrinsic motivators such as salaries, promotions, and benefits are emphasized more than intrinsic motivation factors like personal growth, autonomy, or recognition.
This focus can lead to employees feeling less engaged or committed.
Higher Turnover Risk:
Employees with lower organizational commitment may seek opportunities elsewhere, increasing turnover rates.
Research indicates that organizations with rigid hierarchical structures tend to have higher turnover compared to flexible, participative structures.
Option A (Less use of policies and procedures): Incorrect. Hierarchical control structures rely heavily on policies and procedures to maintain control and consistency.
Option C (Less emphasis on extrinsic rewards): Incorrect. Hierarchical structures often focus more on extrinsic rewards such as salary, promotions, and bonuses to motivate employees.
Option D (Less employee turnover): Incorrect. Due to decreased organizational commitment, hierarchical structures often experience higher turnover rather than lower.
IIA Standard 1100 - Independence and Objectivity: Hierarchical structures can impact the independence and objectivity of internal auditors due to rigid reporting lines.
IIA's Global Perspectives & Insights Report - "The Future of Work": Discusses how traditional hierarchical structures may reduce employee engagement and commitment.
COSO Internal Control - Integrated Framework: Highlights the importance of organizational structure in shaping control environments and employee commitment.
Why Other Options Are Incorrect:IIA References:Thus, the correct answer is B. Less organizational commitment by employees.
IIA-CIA-Part3-CN Exam Question 133
下列哪一項關於實現內部稽核計畫所需資源的敘述是正確的?
Correct Answer: C
According to the Standards, internal audit activities can be provided through in-house resources, outsourcing, or a co-sourcing model. Therefore, it is possible for all resources to come from outside the organization, but ultimate responsibility and accountability remain with the CAE, management, and the board.
Option A is incorrect because oversight cannot be outsourced. Option B is incorrect-coordination with other assurance providers typically increases efficiency. Option D misstates requirements; co-sourcing is an option, not a mandatory practice.
Reference:
IIA Standards - Standard 2070: External Service Provider and Organizational Responsibility for Internal Auditing.
Option A is incorrect because oversight cannot be outsourced. Option B is incorrect-coordination with other assurance providers typically increases efficiency. Option D misstates requirements; co-sourcing is an option, not a mandatory practice.
Reference:
IIA Standards - Standard 2070: External Service Provider and Organizational Responsibility for Internal Auditing.
IIA-CIA-Part3-CN Exam Question 134
下列哪一項是旨在防止未經授權的使用者存取裝置資料或應用程式的智慧型裝置安全控制範例?
Correct Answer: B
Authentication is a key security control that prevents unauthorized users from accessing a smart device's data or applications. It ensures that only authorized individuals can use the device, reducing risks such as data breaches, identity theft, and cyberattacks.
* (A) Anti-malware software.
* Incorrect. Anti-malware software protects against malicious programs, but it does not control user access to a device.
* (B) Authentication. #
* Correct. Authentication mechanisms (such as passwords, biometrics, PINs, and two-factor authentication) prevent unauthorized access to a device's data and applications.
* IIA GTAG "Managing and Auditing IT Vulnerabilities" highlights authentication as a primary control for protecting smart devices.
* (C) Spyware.
* Incorrect. Spyware is a security threat, not a preventive control. It is a type of malicious software that steals data from a device.
* (D) Rooting.
* Incorrect. Rooting (on Android) or jailbreaking (on iOS) refers to modifying a device to remove security restrictions, which increases security risks rather than preventing unauthorized access.
* IIA GTAG - "Managing and Auditing IT Vulnerabilities"
* IIA Standard 2120 - Risk Management
* NIST Cybersecurity Framework - Identity and Access Management
Analysis of Answer Choices:IIA References:Thus, the correct answer is B, as authentication is the most effective security control for preventing unauthorized access to smart devices.
* (A) Anti-malware software.
* Incorrect. Anti-malware software protects against malicious programs, but it does not control user access to a device.
* (B) Authentication. #
* Correct. Authentication mechanisms (such as passwords, biometrics, PINs, and two-factor authentication) prevent unauthorized access to a device's data and applications.
* IIA GTAG "Managing and Auditing IT Vulnerabilities" highlights authentication as a primary control for protecting smart devices.
* (C) Spyware.
* Incorrect. Spyware is a security threat, not a preventive control. It is a type of malicious software that steals data from a device.
* (D) Rooting.
* Incorrect. Rooting (on Android) or jailbreaking (on iOS) refers to modifying a device to remove security restrictions, which increases security risks rather than preventing unauthorized access.
* IIA GTAG - "Managing and Auditing IT Vulnerabilities"
* IIA Standard 2120 - Risk Management
* NIST Cybersecurity Framework - Identity and Access Management
Analysis of Answer Choices:IIA References:Thus, the correct answer is B, as authentication is the most effective security control for preventing unauthorized access to smart devices.
IIA-CIA-Part3-CN Exam Question 135
一位新經理收到了有關專案提案的內部回報命運的計算結果。經理應該將計算結果與什麼進行比較,以確定專案是否可以接受?
Correct Answer: C
The internal rate of return (IRR) is a measure used to evaluate the profitability of an investment. The project is considered acceptable if its IRR is greater than or equal to the required rate of return (RRR), which is the minimum return an organization expects from an investment.
Correct Answer (C - Compare to the Required Rate of Return)
The required rate of return (RRR) represents the minimum acceptable return for the project.
If IRR # RRR, the project is acceptable. If IRR < RRR, the project is rejected.
The IIA Practice Guide: Auditing Capital Investments suggests comparing IRR to the RRR to ensure financial feasibility.
Why Other Options Are Incorrect:
Option A (Compare to the annual cost of capital):
The cost of capital (WACC - Weighted Average Cost of Capital) is an important factor, but RRR is the direct benchmark for IRR comparison.
Option B (Compare to the annual interest rate):
Interest rates do not determine project feasibility-they only affect financing costs.
Option D (Compare to the net present value - NPV):
NPV and IRR are related, but they serve different purposes.
IRR is compared against RRR, while NPV measures absolute profitability in dollar terms.
IIA Practice Guide: Auditing Capital Investments - Discusses IRR, RRR, and investment decision-making.
IIA GTAG 3: Business Case Development - Explains how financial metrics like IRR and RRR are used in decision-making.
Step-by-Step Explanation:IIA References for Validation:Thus, C is the correct answer because IRR should be compared to the required rate of return to determine project acceptability.
Correct Answer (C - Compare to the Required Rate of Return)
The required rate of return (RRR) represents the minimum acceptable return for the project.
If IRR # RRR, the project is acceptable. If IRR < RRR, the project is rejected.
The IIA Practice Guide: Auditing Capital Investments suggests comparing IRR to the RRR to ensure financial feasibility.
Why Other Options Are Incorrect:
Option A (Compare to the annual cost of capital):
The cost of capital (WACC - Weighted Average Cost of Capital) is an important factor, but RRR is the direct benchmark for IRR comparison.
Option B (Compare to the annual interest rate):
Interest rates do not determine project feasibility-they only affect financing costs.
Option D (Compare to the net present value - NPV):
NPV and IRR are related, but they serve different purposes.
IRR is compared against RRR, while NPV measures absolute profitability in dollar terms.
IIA Practice Guide: Auditing Capital Investments - Discusses IRR, RRR, and investment decision-making.
IIA GTAG 3: Business Case Development - Explains how financial metrics like IRR and RRR are used in decision-making.
Step-by-Step Explanation:IIA References for Validation:Thus, C is the correct answer because IRR should be compared to the required rate of return to determine project acceptability.
- Latest Upload
- 138PECB.ISO-14001-Lead-Auditor.v2026-08-14.q31
- 279CompTIA.SY0-701.v2026-08-14.q385
- 171CompTIA.XK0-006.v2026-08-14.q82
- 140Cisco.700-250.v2026-08-14.q34
- 267Cisco.300-420.v2026-08-13.q190
- 309IIA.IIA-CIA-Part3-CN.v2026-08-13.q328
- 174Fortinet.NSE7_SSE_AD-25.v2026-08-12.q38
- 239CyberAB.CMMC-CCP.v2026-08-12.q96
- 177SAP.C_ARCON.v2026-08-12.q39
- 167SAP.C_CR125.v2026-08-12.q33
[×]
Download PDF File
Enter your email address to download IIA.IIA-CIA-Part3-CN.v2026-08-13.q328 Practice Test
