IIA-CIA-Part3-CN Exam Question 221
一位內部稽核員觀察到,該組織的災難復原解決方案將利用幾英里外城鎮的冷站點。下列哪一項可能是此災難復原/解決方案的特徵?
Correct Answer: C
A cold site is a disaster recovery option that provides only basic infrastructure (such as power, space, and network connectivity) but does not have pre-installed IT equipment such as servers and storage. Organizations must procure and install servers and restore data before resuming operations, leading to longer recovery times.
Let's analyze each option:
Option A: Data is synchronized in real-time
Incorrect.
Real-time data synchronization is a feature of hot sites, which have fully operational infrastructure and data replication.
Cold sites do not support real-time synchronization because they lack servers and storage.
Option B: Recovery time is expected to be less than one week
Incorrect.
Cold sites require significant setup time since servers and infrastructure must be procured, configured, and installed.
Recovery time can often exceed one week, depending on the complexity of IT systems.
Option C: Servers are not available and need to be procured
Correct.
A cold site lacks computing hardware (e.g., servers, storage, network devices), meaning the organization must purchase or transport servers to the site before recovery can begin.
IIA Reference: Internal auditors assess disaster recovery strategies, including the limitations of cold sites and their impact on business continuity. (IIA GTAG: Auditing Business Continuity and Disaster Recovery) Option D: Recovery resources and data restore processes have not been defined.
Incorrect.
Even though a cold site lacks IT infrastructure, the organization still has a disaster recovery plan, which includes predefined recovery steps, resource planning, and data restoration procedures.
Thus, the verified answer is C. Servers are not available and need to be procured.
Let's analyze each option:
Option A: Data is synchronized in real-time
Incorrect.
Real-time data synchronization is a feature of hot sites, which have fully operational infrastructure and data replication.
Cold sites do not support real-time synchronization because they lack servers and storage.
Option B: Recovery time is expected to be less than one week
Incorrect.
Cold sites require significant setup time since servers and infrastructure must be procured, configured, and installed.
Recovery time can often exceed one week, depending on the complexity of IT systems.
Option C: Servers are not available and need to be procured
Correct.
A cold site lacks computing hardware (e.g., servers, storage, network devices), meaning the organization must purchase or transport servers to the site before recovery can begin.
IIA Reference: Internal auditors assess disaster recovery strategies, including the limitations of cold sites and their impact on business continuity. (IIA GTAG: Auditing Business Continuity and Disaster Recovery) Option D: Recovery resources and data restore processes have not been defined.
Incorrect.
Even though a cold site lacks IT infrastructure, the organization still has a disaster recovery plan, which includes predefined recovery steps, resource planning, and data restoration procedures.
Thus, the verified answer is C. Servers are not available and need to be procured.
IIA-CIA-Part3-CN Exam Question 222
关于使用安全套接字层 (SSL) 作为控制手段,以下哪项陈述是准确的?
Correct Answer: A
Secure Sockets Layer, and its successor TLS, is used to protect communications between a client and server through encryption and authentication mechanisms. SSL/TLS helps verify the identity of the server through digital certificates and protects information sent between the client and server from interception or alteration.
It does not prevent phishing by itself, because a malicious site can still deceive users through look-alike domains or social engineering. It also does not prevent malware infections; anti-malware, patching, filtering, and user awareness controls are needed for that. Temporary session keys may be used within SSL/TLS, but the strongest answer given is that SSL supports authentication and secure transmission of information.
Therefore, Option A is correct.
It does not prevent phishing by itself, because a malicious site can still deceive users through look-alike domains or social engineering. It also does not prevent malware infections; anti-malware, patching, filtering, and user awareness controls are needed for that. Temporary session keys may be used within SSL/TLS, but the strongest answer given is that SSL supports authentication and secure transmission of information.
Therefore, Option A is correct.
IIA-CIA-Part3-CN Exam Question 223
下列何者最能描述所有者權益?
Correct Answer: A
Owner's equity represents the residual interest in a company's assets after deducting liabilities. It is a fundamental concept in financial accounting, reflecting the net worth of a business.
Formula:Owner's Equity=Assets#Liabilities\text{Owner's Equity} = \text{Assets} - \text{Liabilities}Owner' s Equity=Assets#Liabilities Represents the True Value of Ownership - It measures the owner's claim on the business after settling all obligations.
Directly Tied to the Accounting Equation - Assets=Liabilities+Owner's Equity\text{Assets} = \text
{Liabilities} + \text{Owner's Equity}Assets=Liabilities+Owner's Equity Rearranging the equation: Owner' s Equity=Assets#Liabilities\text{Owner's Equity} = \text{Assets} - \text{Liabilities}Owner' s Equity=Assets#Liabilities Commonly Used in Financial Statements - Found in the Balance Sheet under the "Equity" section.
B). Total assets - Incorrect because assets include both owner-financed and liability-financed resources.
C). Total liabilities - Incorrect because liabilities represent debts owed, not ownership value.
D). Owner's contribution plus drawings - Incorrect because it only considers investments and withdrawals, not retained earnings or net assets.
IIA's GTAG on Business Financial Management - Discusses financial statement analysis, including owner's equity.
COSO's Internal Control - Integrated Framework - Highlights financial reporting accuracy, including equity calculations.
IFRS & GAAP Accounting Standards - Define owner's equity as assets minus liabilities in financial reporting.
Why Option A is Correct?Why Not the Other Options?IIA References:
Formula:Owner's Equity=Assets#Liabilities\text{Owner's Equity} = \text{Assets} - \text{Liabilities}Owner' s Equity=Assets#Liabilities Represents the True Value of Ownership - It measures the owner's claim on the business after settling all obligations.
Directly Tied to the Accounting Equation - Assets=Liabilities+Owner's Equity\text{Assets} = \text
{Liabilities} + \text{Owner's Equity}Assets=Liabilities+Owner's Equity Rearranging the equation: Owner' s Equity=Assets#Liabilities\text{Owner's Equity} = \text{Assets} - \text{Liabilities}Owner' s Equity=Assets#Liabilities Commonly Used in Financial Statements - Found in the Balance Sheet under the "Equity" section.
B). Total assets - Incorrect because assets include both owner-financed and liability-financed resources.
C). Total liabilities - Incorrect because liabilities represent debts owed, not ownership value.
D). Owner's contribution plus drawings - Incorrect because it only considers investments and withdrawals, not retained earnings or net assets.
IIA's GTAG on Business Financial Management - Discusses financial statement analysis, including owner's equity.
COSO's Internal Control - Integrated Framework - Highlights financial reporting accuracy, including equity calculations.
IFRS & GAAP Accounting Standards - Define owner's equity as assets minus liabilities in financial reporting.
Why Option A is Correct?Why Not the Other Options?IIA References:
IIA-CIA-Part3-CN Exam Question 224
下列哪一項是 IT 治理控制的最佳範例?
Correct Answer: A
IT governance controls ensure that an organization ' s IT systems align with business objectives, manage risks, and comply with regulatory requirements. These controls cover areas such as security, financial oversight, change management, and operational efficiency.
Let's analyze each option:
Option A: Controls that focus on segregation of duties, financial, and change management.
Correct.
Segregation of duties (SoD) prevents conflicts of interest and reduces fraud risk.
Financial controls ensure IT expenditures align with budgets and policies.
Change management controls ensure system modifications follow formal approval and testing procedures.
These areas are core components of IT governance, ensuring security, compliance, and efficiency.
IIA Reference: Internal auditors evaluate IT governance using frameworks like COBIT (Control Objectives for Information and Related Technologies) and ISO 27001. (IIA GTAG: Auditing IT Governance) Option B: Personnel policies that define and enforce conditions for staff in sensitive IT areas.
Incorrect.
While personnel policies support IT security, they do not fully represent IT governance controls. IT governance is broader and includes risk management, compliance, and operational efficiency.
Option C: Standards that support IT policies by more specifically defining required actions.
Incorrect.
Standards are part of IT governance but are not controls themselves. IT governance requires enforcement mechanisms like segregation of duties and change management to ensure compliance.
Option D: Controls that focus on data structures and the minimum level of documentation required.
Incorrect.
While data governance is a subset of IT governance, IT governance includes wider financial, security, and operational controls.
Thus, the verified answer is A. Controls that focus on segregation of duties, financial, and change management.
Let's analyze each option:
Option A: Controls that focus on segregation of duties, financial, and change management.
Correct.
Segregation of duties (SoD) prevents conflicts of interest and reduces fraud risk.
Financial controls ensure IT expenditures align with budgets and policies.
Change management controls ensure system modifications follow formal approval and testing procedures.
These areas are core components of IT governance, ensuring security, compliance, and efficiency.
IIA Reference: Internal auditors evaluate IT governance using frameworks like COBIT (Control Objectives for Information and Related Technologies) and ISO 27001. (IIA GTAG: Auditing IT Governance) Option B: Personnel policies that define and enforce conditions for staff in sensitive IT areas.
Incorrect.
While personnel policies support IT security, they do not fully represent IT governance controls. IT governance is broader and includes risk management, compliance, and operational efficiency.
Option C: Standards that support IT policies by more specifically defining required actions.
Incorrect.
Standards are part of IT governance but are not controls themselves. IT governance requires enforcement mechanisms like segregation of duties and change management to ensure compliance.
Option D: Controls that focus on data structures and the minimum level of documentation required.
Incorrect.
While data governance is a subset of IT governance, IT governance includes wider financial, security, and operational controls.
Thus, the verified answer is A. Controls that focus on segregation of duties, financial, and change management.
IIA-CIA-Part3-CN Exam Question 225
为了评估组织隐私保护计划的有效性,内部审计人员应该采取以下哪些方法?
Correct Answer: D
The most effective way to assess a privacy program is to analyze the life cycle of sensitive data. This includes how personal or confidential data are collected, classified, used, stored, shared, retained, archived, and destroyed. Privacy effectiveness depends on whether controls operate throughout the full data life cycle, not merely whether policies exist. Employee interviews may provide useful context but are not sufficient.
Penetration tests assess technical security weaknesses, not the overall privacy program. Reviewing policies and procedures confirms design but does not prove operational effectiveness. Internal audit should trace sensitive data flows, assess consent, access, retention, third-party sharing, breach response, and monitoring.
Therefore, Option D is correct.
Penetration tests assess technical security weaknesses, not the overall privacy program. Reviewing policies and procedures confirms design but does not prove operational effectiveness. Internal audit should trace sensitive data flows, assess consent, access, retention, third-party sharing, breach response, and monitoring.
Therefore, Option D is correct.
- Latest Upload
- 134Microsoft.AB-210.v2026-08-15.q30
- 227CuramSoftware.CS0-003.v2026-08-15.q217
- 149PECB.ISO-14001-Lead-Auditor.v2026-08-14.q31
- 357CompTIA.SY0-701.v2026-08-14.q385
- 192CompTIA.XK0-006.v2026-08-14.q82
- 152Cisco.700-250.v2026-08-14.q34
- 306Cisco.300-420.v2026-08-13.q190
- 389IIA.IIA-CIA-Part3-CN.v2026-08-13.q328
- 190Fortinet.NSE7_SSE_AD-25.v2026-08-12.q38
- 272CyberAB.CMMC-CCP.v2026-08-12.q96
[×]
Download PDF File
Enter your email address to download IIA.IIA-CIA-Part3-CN.v2026-08-13.q328 Practice Test
