IIA-CIA-Part3-CN Exam Question 176
活動組織的員工使用特定的技術來解決問題和改善流程。該技術包括五個步驟:定義、測量、分析、改進和控制。下列哪一項最能描述這種方法?
Correct Answer: A
The Define, Measure, Analyze, Improve, and Control (DMAIC) methodology is the core framework of Six Sigma, a data-driven process improvement approach that aims to reduce defects, enhance efficiency, and optimize performance.
(A) Correct - Six Sigma.
DMAIC is a structured Six Sigma methodology used for problem-solving and process improvement.
It helps organizations identify inefficiencies, eliminate errors, and standardize processes.
(B) Incorrect - Quality circle.
A quality circle is a group of employees who meet to discuss and resolve work-related issues, but it does not follow the structured DMAIC approach.
(C) Incorrect - Value chain analysis.
Value chain analysis focuses on evaluating business activities to improve competitive advantage, not structured process improvement like Six Sigma.
(D) Incorrect - Theory of constraints.
The Theory of Constraints (TOC) focuses on identifying and eliminating bottlenecks in processes, but it does not use the DMAIC approach.
IIA's Global Internal Audit Standards - Process Improvement and Risk Management Emphasizes methodologies like Six Sigma for operational efficiency.
COSO's ERM Framework - Continuous Improvement and Quality Management
Discusses the role of Six Sigma in improving processes and reducing risks.
IIA's Guide on Business Process Auditing
Recommends structured approaches such as Six Sigma for evaluating process efficiency.
Analysis of Answer Choices:IIA References and Internal Auditing Standards:
(A) Correct - Six Sigma.
DMAIC is a structured Six Sigma methodology used for problem-solving and process improvement.
It helps organizations identify inefficiencies, eliminate errors, and standardize processes.
(B) Incorrect - Quality circle.
A quality circle is a group of employees who meet to discuss and resolve work-related issues, but it does not follow the structured DMAIC approach.
(C) Incorrect - Value chain analysis.
Value chain analysis focuses on evaluating business activities to improve competitive advantage, not structured process improvement like Six Sigma.
(D) Incorrect - Theory of constraints.
The Theory of Constraints (TOC) focuses on identifying and eliminating bottlenecks in processes, but it does not use the DMAIC approach.
IIA's Global Internal Audit Standards - Process Improvement and Risk Management Emphasizes methodologies like Six Sigma for operational efficiency.
COSO's ERM Framework - Continuous Improvement and Quality Management
Discusses the role of Six Sigma in improving processes and reducing risks.
IIA's Guide on Business Process Auditing
Recommends structured approaches such as Six Sigma for evaluating process efficiency.
Analysis of Answer Choices:IIA References and Internal Auditing Standards:
IIA-CIA-Part3-CN Exam Question 177
根据 IIA 指南,在评估组织对当地社区的社会和环境影响时,内部审计师最应该执行以下哪些步骤?
* 确定之前的事件是否已被报告、管理和解决。
* 确定是否存在业务应急计划。
* 确定报告的透明度程度。
* 确定是否对所有相关项目进行了成本效益分析。
* 确定之前的事件是否已被报告、管理和解决。
* 确定是否存在业务应急计划。
* 确定报告的透明度程度。
* 确定是否对所有相关项目进行了成本效益分析。
Correct Answer: A
When evaluating social and environmental impact on the local community, internal audit should determine whether previous incidents were reported, managed, and resolved, and whether reporting is transparent. Prior incidents reveal how management handles actual community impact, complaints, environmental events, safety issues, or reputational concerns. Transparency in reporting is critical because stakeholders need reliable information about social and environmental performance. A business contingency plan may be relevant to continuity but is not the most important community-impact evaluation step. Cost-benefit analysis of related projects may support investment decisions, but it does not directly show whether community impact is responsibly managed. Internal audit should focus on accountability, incident management, stakeholder communication, and reporting credibility. Therefore, Option A is correct.
IIA-CIA-Part3-CN Exam Question 178
根據 IIA 指導,下列哪一項關於溝通參與結果的敘述是正確的?
Correct Answer: B
The IIA Standards require that significant governance, risk management, or control issues be communicated to senior management and the board, regardless of whether they arise from assurance or advisory engagements.
Option A is misleading, as it overstates the audit committee's role. Option C is incorrect because responsibility for final communication lies with the CAE, not the supervisor. Option D is also incorrect since the audit committee does not approve every report; that responsibility rests with internal audit leadership.
Reference:
IIA Standards - Standard 2440: Disseminating Results.
Option A is misleading, as it overstates the audit committee's role. Option C is incorrect because responsibility for final communication lies with the CAE, not the supervisor. Option D is also incorrect since the audit committee does not approve every report; that responsibility rests with internal audit leadership.
Reference:
IIA Standards - Standard 2440: Disseminating Results.
IIA-CIA-Part3-CN Exam Question 179
一家製藥公司的內部稽核師負責規劃網路安全審計並進行風險評估。下列哪一項被認為是對組織最重要的網路威脅?
Correct Answer: B
When conducting a cybersecurity risk assessment, an internal auditor must evaluate the most significant threats based on their potential impact on the organization. In the pharmaceutical industry, intellectual property (IP), such as research and development (R & D) data, is one of the most valuable and sensitive assets.
(A) Cybercriminals hacking into the organization ' s time and expense system to collect employee personal data:While the loss of employee personal data is a serious concern due to privacy and regulatory implications (e.g., GDPR, CCPA), it does not pose as critical a threat as the loss of proprietary pharmaceutical research.
(B) Hackers breaching the organization ' s network to access research and development reports (Correct Answer):R & D reports contain proprietary drug formulas, clinical trial results, and patent-pending innovations, making them highly valuable to competitors and cybercriminals. A breach could lead to intellectual property theft, financial losses, loss of competitive advantage, and regulatory non-compliance (e.
g., FDA, EMA requirements). This is considered the most significant threat because:
It could result in billions of dollars in lost revenue.
Competitors or state-sponsored hackers could exploit stolen research.
It could disrupt drug development and approval processes.
(C) A denial-of-service (DoS) attack that prevents access to the organization ' s website:While DoS attacks can damage an organization ' s reputation and disrupt operations, they generally do not cause the same level of financial or strategic harm as the loss of critical R & D data. Most organizations have cybersecurity measures (e.g., load balancers, CDNs) to mitigate DoS risks.
(D) A hacker accessing the financial information of the company:Unauthorized access to financial data can be serious, leading to fraud or reputational damage. However, publicly traded companies already disclose much of their financial data, and financial breaches typically have a lower long-term impact compared to intellectual property theft.
IIA Global Technology Audit Guide (GTAG) 15: Information Security Governance: Recommends that internal auditors prioritize risks that impact strategic assets, such as intellectual property.
IIA Standard 2120 - Risk Management: Requires internal auditors to evaluate the organization's risk management processes, emphasizing risks with significant financial and operational consequences.
IIA Practice Advisory 2110-2: Assessing the Adequacy of Risk Management Processes: Highlights that internal auditors must identify risks that could threaten the organization's long-term objectives, such as IP theft.
COSO ERM Framework: Encourages prioritization of risks that have high impact on an organization's value and strategic objectives, such as cyber threats to proprietary research.
Analysis of Each Option:IIA References:Conclusion:Given the pharmaceutical industry ' s reliance on proprietary R & D, a breach compromising research reports represents the most significant cyber threat.
Therefore, option (B) is the correct answer.
(A) Cybercriminals hacking into the organization ' s time and expense system to collect employee personal data:While the loss of employee personal data is a serious concern due to privacy and regulatory implications (e.g., GDPR, CCPA), it does not pose as critical a threat as the loss of proprietary pharmaceutical research.
(B) Hackers breaching the organization ' s network to access research and development reports (Correct Answer):R & D reports contain proprietary drug formulas, clinical trial results, and patent-pending innovations, making them highly valuable to competitors and cybercriminals. A breach could lead to intellectual property theft, financial losses, loss of competitive advantage, and regulatory non-compliance (e.
g., FDA, EMA requirements). This is considered the most significant threat because:
It could result in billions of dollars in lost revenue.
Competitors or state-sponsored hackers could exploit stolen research.
It could disrupt drug development and approval processes.
(C) A denial-of-service (DoS) attack that prevents access to the organization ' s website:While DoS attacks can damage an organization ' s reputation and disrupt operations, they generally do not cause the same level of financial or strategic harm as the loss of critical R & D data. Most organizations have cybersecurity measures (e.g., load balancers, CDNs) to mitigate DoS risks.
(D) A hacker accessing the financial information of the company:Unauthorized access to financial data can be serious, leading to fraud or reputational damage. However, publicly traded companies already disclose much of their financial data, and financial breaches typically have a lower long-term impact compared to intellectual property theft.
IIA Global Technology Audit Guide (GTAG) 15: Information Security Governance: Recommends that internal auditors prioritize risks that impact strategic assets, such as intellectual property.
IIA Standard 2120 - Risk Management: Requires internal auditors to evaluate the organization's risk management processes, emphasizing risks with significant financial and operational consequences.
IIA Practice Advisory 2110-2: Assessing the Adequacy of Risk Management Processes: Highlights that internal auditors must identify risks that could threaten the organization's long-term objectives, such as IP theft.
COSO ERM Framework: Encourages prioritization of risks that have high impact on an organization's value and strategic objectives, such as cyber threats to proprietary research.
Analysis of Each Option:IIA References:Conclusion:Given the pharmaceutical industry ' s reliance on proprietary R & D, a breach compromising research reports represents the most significant cyber threat.
Therefore, option (B) is the correct answer.
IIA-CIA-Part3-CN Exam Question 180
下列哪一項績效衡量因素阻礙了盈餘管理?
Correct Answer: D
Earnings management occurs when companies manipulate financial reporting to meet targets, often leading to unethical practices or financial misstatements. The best way to disincentivize earnings management is to link performance to nonfinancial measures such as customer satisfaction and employee training, which cannot be directly manipulated through financial reporting.
Avoiding Short-Term Financial Manipulation:
When performance is tied to financial metrics (e.g., return on investment, stock price, or production quotas), there is a higher risk of earnings manipulation, such as shifting revenues, deferring expenses, or aggressive accounting practices.
Nonfinancial measures, however, emphasize long-term value creation and are harder to manipulate.
Sustainable Business Growth:
Customer satisfaction and employee training foster long-term profitability by improving product quality, brand reputation, and workforce capabilities.
Companies focusing on these measures build sustainable competitive advantages without distorting financial results.
Regulatory and Ethical Considerations:
Internal auditors, following IIA Standard 2120 (Risk Management), must evaluate risks related to unethical financial reporting.
Regulatory bodies (e.g., SEC, PCAOB, and COSO) emphasize reducing the risk of fraudulent financial reporting by incorporating broader performance measures beyond financial results.
A). Linking performance to profitability measures such as return on investment:
ROI and similar metrics can pressure executives to inflate earnings or cut necessary expenses to meet short- term targets.
B). Linking performance to the stock price:
Stock-based incentives can lead to earnings manipulation (e.g., stock buybacks, revenue recognition adjustments) to inflate stock prices artificially.
C). Linking performance to quotas such as units produced:
Production-based targets can result in overproduction or quality compromises, leading to inefficient resource allocation and long-term financial issues.
IIA Standard 2120 (Risk Management): Internal auditors must assess risks related to financial reporting integrity.
COSO's Internal Control Framework: Emphasizes performance measures beyond financial results to ensure ethical management practices.
IIA Practice Guide: Assessing Organizational Governance: Encourages balanced scorecards, including nonfinancial KPIs, to reduce financial misstatement risks.
Step-by-Step Justification:Why Not the Other Options?IIA References:Thus, the correct answer is D. Linking performance to nonfinancial measures such as customer satisfaction and employee training. #
Avoiding Short-Term Financial Manipulation:
When performance is tied to financial metrics (e.g., return on investment, stock price, or production quotas), there is a higher risk of earnings manipulation, such as shifting revenues, deferring expenses, or aggressive accounting practices.
Nonfinancial measures, however, emphasize long-term value creation and are harder to manipulate.
Sustainable Business Growth:
Customer satisfaction and employee training foster long-term profitability by improving product quality, brand reputation, and workforce capabilities.
Companies focusing on these measures build sustainable competitive advantages without distorting financial results.
Regulatory and Ethical Considerations:
Internal auditors, following IIA Standard 2120 (Risk Management), must evaluate risks related to unethical financial reporting.
Regulatory bodies (e.g., SEC, PCAOB, and COSO) emphasize reducing the risk of fraudulent financial reporting by incorporating broader performance measures beyond financial results.
A). Linking performance to profitability measures such as return on investment:
ROI and similar metrics can pressure executives to inflate earnings or cut necessary expenses to meet short- term targets.
B). Linking performance to the stock price:
Stock-based incentives can lead to earnings manipulation (e.g., stock buybacks, revenue recognition adjustments) to inflate stock prices artificially.
C). Linking performance to quotas such as units produced:
Production-based targets can result in overproduction or quality compromises, leading to inefficient resource allocation and long-term financial issues.
IIA Standard 2120 (Risk Management): Internal auditors must assess risks related to financial reporting integrity.
COSO's Internal Control Framework: Emphasizes performance measures beyond financial results to ensure ethical management practices.
IIA Practice Guide: Assessing Organizational Governance: Encourages balanced scorecards, including nonfinancial KPIs, to reduce financial misstatement risks.
Step-by-Step Justification:Why Not the Other Options?IIA References:Thus, the correct answer is D. Linking performance to nonfinancial measures such as customer satisfaction and employee training. #
- Latest Upload
- 128Microsoft.AB-210.v2026-08-15.q30
- 216CuramSoftware.CS0-003.v2026-08-15.q217
- 148PECB.ISO-14001-Lead-Auditor.v2026-08-14.q31
- 357CompTIA.SY0-701.v2026-08-14.q385
- 192CompTIA.XK0-006.v2026-08-14.q82
- 151Cisco.700-250.v2026-08-14.q34
- 304Cisco.300-420.v2026-08-13.q190
- 379IIA.IIA-CIA-Part3-CN.v2026-08-13.q328
- 189Fortinet.NSE7_SSE_AD-25.v2026-08-12.q38
- 271CyberAB.CMMC-CCP.v2026-08-12.q96
[×]
Download PDF File
Enter your email address to download IIA.IIA-CIA-Part3-CN.v2026-08-13.q328 Practice Test
