IIA-CIA-Part3-CN Exam Question 136
在制定有效的基于风险的审计优先事项计划时,内部审计活动应首先:
Correct Answer: D
A risk-based internal audit plan must begin with the organization's objectives because risks are meaningful only in relation to objectives. Internal audit needs to understand what the organization is trying to achieve before identifying events that could prevent achievement, delay achievement, or create unacceptable exposure. After objectives are understood, the audit activity can identify risks, assess their likelihood and impact, consider management's risk responses, evaluate existing assurance coverage, and prioritize engagements. Option A is important but should follow the review of objectives. Option B is premature because controls cannot be evaluated effectively until the related objectives and risks are understood. Option C is also premature because risks cannot be prioritized before they are identified and linked to objectives.
Therefore, the correct starting point for risk-based audit planning is Option D.
Therefore, the correct starting point for risk-based audit planning is Option D.
IIA-CIA-Part3-CN Exam Question 137
以下哪种数据分析方法涉及分析事件趋势以确定发生了什么?
Correct Answer: B
Descriptive analytics explains what happened by summarizing historical data, event trends, frequencies, totals, exceptions, or patterns. In internal audit, descriptive analytics may show transaction volumes, trend lines, error rates, payment patterns, system access activity, or incident counts. Diagnostic analytics goes further by explaining why something happened. Predictive analytics estimates what may happen in the future.
Prescriptive analytics recommends what should be done based on analysis or optimization. The question specifically states that event trends are analyzed to determine what happened, which is the defining purpose of descriptive analytics. Internal auditors commonly begin with descriptive analytics before performing diagnostic, predictive, or prescriptive procedures. Therefore, Option B is correct.
Prescriptive analytics recommends what should be done based on analysis or optimization. The question specifically states that event trends are analyzed to determine what happened, which is the defining purpose of descriptive analytics. Internal auditors commonly begin with descriptive analytics before performing diagnostic, predictive, or prescriptive procedures. Therefore, Option B is correct.
IIA-CIA-Part3-CN Exam Question 138
當所有其他變數都相同時,與普通股相比,下列哪一項對債券融資是正確的?
Correct Answer: C
When a company finances through bonds (debt) instead of issuing common stock (equity), it increases earnings per share (EPS) because bond financing does not dilute ownership, whereas issuing new stock does.
Impact on Earnings Per Share (EPS):
EPS formula: EPS=Net Income#Preferred DividendsNumber of Outstanding Shares\text{EPS} = \frac{\text
{Net Income} - \text{Preferred Dividends}}{\text{Number of Outstanding Shares}} EPS=Number of Outstanding SharesNet Income#Preferred Dividends Since bond financing does not increase the number of shares outstanding, net income is distributed among fewer shareholders, increasing EPS.
If the company issues more stock instead of bonds, EPS decreases because the same earnings are divided among more shares.
Why Bond Financing Affects EPS Favorably:
Interest on bonds is tax-deductible, reducing taxable income and increasing net profits.
Unlike dividends, which are paid on common stock and reduce retained earnings, bondholders receive fixed interest payments that do not dilute equity ownership.
A). Lower shareholder control: #
Bondholders do not get voting rights, whereas issuing more stock reduces existing shareholders' control.
This statement would be true for stock financing, not bond financing.
B). Lower indebtedness: #
Bonds increase a company's debt obligations, not reduce them.
If a company uses stock financing instead of bonds, it avoids taking on debt.
D). Higher overall company earnings: #
While bonds increase EPS, they do not necessarily increase total earnings.
The company must pay interest on bonds, which could reduce net income if not managed properly.
IIA Standard 2110 (Governance): Ensures management selects financing strategies that align with financial stability.
COSO ERM Framework - Financial Risk Management: Evaluates how financing choices impact shareholder value and risk exposure.
IFRS & GAAP Accounting Standards on Debt vs. Equity Financing: Explain how bond financing increases EPS compared to issuing new shares.
Step-by-Step Justification:Why Not the Other Options?IIA References:
Impact on Earnings Per Share (EPS):
EPS formula: EPS=Net Income#Preferred DividendsNumber of Outstanding Shares\text{EPS} = \frac{\text
{Net Income} - \text{Preferred Dividends}}{\text{Number of Outstanding Shares}} EPS=Number of Outstanding SharesNet Income#Preferred Dividends Since bond financing does not increase the number of shares outstanding, net income is distributed among fewer shareholders, increasing EPS.
If the company issues more stock instead of bonds, EPS decreases because the same earnings are divided among more shares.
Why Bond Financing Affects EPS Favorably:
Interest on bonds is tax-deductible, reducing taxable income and increasing net profits.
Unlike dividends, which are paid on common stock and reduce retained earnings, bondholders receive fixed interest payments that do not dilute equity ownership.
A). Lower shareholder control: #
Bondholders do not get voting rights, whereas issuing more stock reduces existing shareholders' control.
This statement would be true for stock financing, not bond financing.
B). Lower indebtedness: #
Bonds increase a company's debt obligations, not reduce them.
If a company uses stock financing instead of bonds, it avoids taking on debt.
D). Higher overall company earnings: #
While bonds increase EPS, they do not necessarily increase total earnings.
The company must pay interest on bonds, which could reduce net income if not managed properly.
IIA Standard 2110 (Governance): Ensures management selects financing strategies that align with financial stability.
COSO ERM Framework - Financial Risk Management: Evaluates how financing choices impact shareholder value and risk exposure.
IFRS & GAAP Accounting Standards on Debt vs. Equity Financing: Explain how bond financing increases EPS compared to issuing new shares.
Step-by-Step Justification:Why Not the Other Options?IIA References:
IIA-CIA-Part3-CN Exam Question 139
一家金融機構經常收到客戶發送的各種電子郵件請求,要求將資金從帳戶中匯出。哪種驗證活動最能幫助機構避免成為網路釣魚的受害者?
Correct Answer: B
Phishing attacks often target financial institutions by impersonating customers and requesting fraudulent fund transfers. The best way to verify such requests is to independently contact the customer using a trusted communication channel, such as the phone number on record.
Verbal confirmation via a trusted number prevents fraudsters from exploiting email spoofing or compromised accounts.
This aligns with industry best practices, including multi-factor verification for high-risk transactions.
A). Reviewing the customer's wire activity to determine whether the request is typical. (Incorrect) While reviewing transaction history can help detect anomalies, fraudsters can mimic previous transaction patterns, making this method unreliable on its own.
B). Calling the customer at the phone number on record to validate the request. (Correct) Direct phone verification ensures that the actual account owner is making the request.
This is a widely recommended anti-fraud measure in financial institutions.
C). Replying to the customer via email to validate the sender and request. (Incorrect) If the email account is compromised, the fraudster will control the response.
Email validation is not secure for financial transactions.
D). Reviewing the customer record to verify whether the customer has authorized wire requests from that email address. (Incorrect) While this can help identify unregistered emails, attackers often spoof or hack real customer emails.
Email-based verification alone is not sufficient.
IIA GTAG 16 - Security Risk: IT and Cybersecurity recommends multi-factor authentication for high-risk financial transactions.
IIA Standard 2120 - Risk Management highlights the need for robust fraud prevention mechanisms, including direct customer verification.
FFIEC (Federal Financial Institutions Examination Council) Cybersecurity Guidelines emphasize the importance of out-of-band authentication for wire transfers.
Explanation of Answer Choices:IIA References:Thus, the correct answer is B. Calling the customer at the phone number on record to validate the request.
Verbal confirmation via a trusted number prevents fraudsters from exploiting email spoofing or compromised accounts.
This aligns with industry best practices, including multi-factor verification for high-risk transactions.
A). Reviewing the customer's wire activity to determine whether the request is typical. (Incorrect) While reviewing transaction history can help detect anomalies, fraudsters can mimic previous transaction patterns, making this method unreliable on its own.
B). Calling the customer at the phone number on record to validate the request. (Correct) Direct phone verification ensures that the actual account owner is making the request.
This is a widely recommended anti-fraud measure in financial institutions.
C). Replying to the customer via email to validate the sender and request. (Incorrect) If the email account is compromised, the fraudster will control the response.
Email validation is not secure for financial transactions.
D). Reviewing the customer record to verify whether the customer has authorized wire requests from that email address. (Incorrect) While this can help identify unregistered emails, attackers often spoof or hack real customer emails.
Email-based verification alone is not sufficient.
IIA GTAG 16 - Security Risk: IT and Cybersecurity recommends multi-factor authentication for high-risk financial transactions.
IIA Standard 2120 - Risk Management highlights the need for robust fraud prevention mechanisms, including direct customer verification.
FFIEC (Federal Financial Institutions Examination Council) Cybersecurity Guidelines emphasize the importance of out-of-band authentication for wire transfers.
Explanation of Answer Choices:IIA References:Thus, the correct answer is B. Calling the customer at the phone number on record to validate the request.
IIA-CIA-Part3-CN Exam Question 140
内部审计活动已完成对组织数据存储中心的初步风险分析,并发现了一些值得关注的问题。以下哪项是下一步最合适的措施?
Correct Answer: D
After an initial risk analysis identifies areas of concern, the next appropriate step is risk assessment. Risk assessment evaluates the significance of identified risks by considering likelihood, impact, control effectiveness, vulnerability, and priority. Risk identification has already occurred because several areas of concern were found. Identification of context normally occurs earlier, when the auditor or risk team defines objectives, scope, environment, criteria, and risk appetite. Risk response comes after assessment because management must understand the severity and priority of risks before deciding whether to accept, reduce, avoid, or share them. In internal audit planning, this sequence is critical because audit resources should be focused on higher-risk areas. Therefore, after initial risk analysis, the most appropriate next step is risk assessment, Option D.
- Latest Upload
- 128Microsoft.AB-210.v2026-08-15.q30
- 216CuramSoftware.CS0-003.v2026-08-15.q217
- 148PECB.ISO-14001-Lead-Auditor.v2026-08-14.q31
- 346CompTIA.SY0-701.v2026-08-14.q385
- 192CompTIA.XK0-006.v2026-08-14.q82
- 151Cisco.700-250.v2026-08-14.q34
- 303Cisco.300-420.v2026-08-13.q190
- 371IIA.IIA-CIA-Part3-CN.v2026-08-13.q328
- 189Fortinet.NSE7_SSE_AD-25.v2026-08-12.q38
- 270CyberAB.CMMC-CCP.v2026-08-12.q96
[×]
Download PDF File
Enter your email address to download IIA.IIA-CIA-Part3-CN.v2026-08-13.q328 Practice Test
