IIA-CIA-Part3-CN Exam Question 316
根據11A指導;關於電子商務交易中所使用的網站,下列哪一項敘述是正確的?
Correct Answer: D
E-commerce transactions involve multiple security layers to ensure the protection of customers' sensitive financial information. The correct answer is D, as payment gateways serve as intermediaries that authorize online credit card transactions by securely transmitting the payment details to the bank or card networks for approval. Let's examine each option carefully:
Option A: HTTP sites provide sufficient security to protect customers' credit card information.
Incorrect. HyperText Transfer Protocol (HTTP) does not provide encryption, meaning that data transmitted over an HTTP connection can be intercepted by malicious actors. Instead, Secure HTTP (HTTPS), which uses Secure Sockets Layer (SSL) or Transport Layer Security (TLS), is required to encrypt the data.
IIA Reference: Internal auditors evaluating e-commerce security should verify that organizations use HTTPS for secure transactions. (IIA GTAG: Information Security Governance) Option B: Web servers store credit cardholders' information submitted for payment.
Incorrect. While web servers may temporarily process customer data, they should not store sensitive credit card information due to security risks. Instead, organizations follow the Payment Card Industry Data Security Standard (PCI DSS), which mandates secure storage and encryption protocols.
IIA Reference: IIA Standards recommend compliance with PCI DSS to protect sensitive payment information. (IIA Practice Guide: Auditing IT Governance) Option C: Database servers send cardholders' information for authorization in clear text.
Incorrect. Transmitting cardholder data in clear text is a severe security vulnerability. Secure encryption protocols such as SSL/TLS or tokenization must be used to protect data in transit.
IIA Reference: Internal auditors should ensure encryption measures are in place for financial transactions.
(IIA GTAG: Auditing Cybersecurity Risk)
Option D: Payment gateways authorize credit card online payments.
Correct. Payment gateways act as secure intermediaries between merchants and payment processors, verifying the transaction details before authorization. This ensures a secure transaction by encrypting sensitive data before transmitting it for approval.
IIA Reference: IIA guidance on IT controls emphasizes the importance of secure payment processing through payment gateways. (IIA GTAG: Managing and Auditing IT Vulnerabilities)
Option A: HTTP sites provide sufficient security to protect customers' credit card information.
Incorrect. HyperText Transfer Protocol (HTTP) does not provide encryption, meaning that data transmitted over an HTTP connection can be intercepted by malicious actors. Instead, Secure HTTP (HTTPS), which uses Secure Sockets Layer (SSL) or Transport Layer Security (TLS), is required to encrypt the data.
IIA Reference: Internal auditors evaluating e-commerce security should verify that organizations use HTTPS for secure transactions. (IIA GTAG: Information Security Governance) Option B: Web servers store credit cardholders' information submitted for payment.
Incorrect. While web servers may temporarily process customer data, they should not store sensitive credit card information due to security risks. Instead, organizations follow the Payment Card Industry Data Security Standard (PCI DSS), which mandates secure storage and encryption protocols.
IIA Reference: IIA Standards recommend compliance with PCI DSS to protect sensitive payment information. (IIA Practice Guide: Auditing IT Governance) Option C: Database servers send cardholders' information for authorization in clear text.
Incorrect. Transmitting cardholder data in clear text is a severe security vulnerability. Secure encryption protocols such as SSL/TLS or tokenization must be used to protect data in transit.
IIA Reference: Internal auditors should ensure encryption measures are in place for financial transactions.
(IIA GTAG: Auditing Cybersecurity Risk)
Option D: Payment gateways authorize credit card online payments.
Correct. Payment gateways act as secure intermediaries between merchants and payment processors, verifying the transaction details before authorization. This ensures a secure transaction by encrypting sensitive data before transmitting it for approval.
IIA Reference: IIA guidance on IT controls emphasizes the importance of secure payment processing through payment gateways. (IIA GTAG: Managing and Auditing IT Vulnerabilities)
IIA-CIA-Part3-CN Exam Question 317
當需要刪除員工的存取權限時,下列哪一項驗證設備憑證最難撤銷?
Correct Answer: B
Comprehensive and Detailed In-Depth Explanation:
Biometric authentication (e.g., fingerprint, retina scan) is the most difficult to revoke because it is linked to an individual's physical attributes, which cannot be changed like passwords or physical devices.
Option A (Traditional key lock) - Can be revoked by retrieving the key or changing the lock.
Option C (Card-key system) - Can be revoked by deactivating the card.
Option D (Proximity device) - Can be revoked by disabling the device.
Since biometric data is permanently tied to an individual, revoking access is complex, making Option B the correct answer.
Reference: IIA IT Security & Authentication Controls
Biometric authentication (e.g., fingerprint, retina scan) is the most difficult to revoke because it is linked to an individual's physical attributes, which cannot be changed like passwords or physical devices.
Option A (Traditional key lock) - Can be revoked by retrieving the key or changing the lock.
Option C (Card-key system) - Can be revoked by deactivating the card.
Option D (Proximity device) - Can be revoked by disabling the device.
Since biometric data is permanently tied to an individual, revoking access is complex, making Option B the correct answer.
Reference: IIA IT Security & Authentication Controls
IIA-CIA-Part3-CN Exam Question 318
有效的 IT 變更管理需要下列哪一項?
Correct Answer: B
Effective IT Change Management Principles:
Change management ensures that modifications to IT systems are controlled, tested, and implemented in a way that reduces risks.
A structured and consistent process is required to prevent disruptions, maintain system integrity, and comply with governance requirements.
IIA Standard 2110 - Governance:
IT governance must include structured change management processes.
Change management should be repeatable and standardized to ensure effectiveness.
IIA GTAG (Global Technology Audit Guide) on Change Management:
Change management must be conducted in a controlled environment to minimize unintended consequences and security risks.
A). The sole responsibility for change management is assigned to an experienced and competent IT team.
(Incorrect)
While IT plays a key role, change management should involve multiple stakeholders, including business units, security, compliance, and risk management teams.
IIA Standard 2120 - Risk Management states that risk oversight should not be assigned to a single function.
C). Internal audit participates in the implementation of change management throughout the organization.
(Incorrect)
Internal audit evaluates change management but does not implement it.
IIA Standard 1000 - Purpose, Authority, and Responsibility emphasizes that internal audit provides independent assurance rather than operational involvement.
D). All changes to systems must be approved by the highest level of authority within an organization.
(Incorrect)
Approvals should be based on a risk-based hierarchy rather than requiring executive-level approval for all changes.
IIA GTAG - Change Management recommends a tiered approval system based on change complexity and risk impact.
Explanation of Incorrect Answers:Conclusion:The most critical factor in effective IT change management is having a consistent, controlled process (Option B).
IIA References:
IIA Standard 2110 - Governance
IIA Standard 2120 - Risk Management
IIA Standard 1000 - Purpose, Authority, and Responsibility
IIA GTAG - Change Management
Change management ensures that modifications to IT systems are controlled, tested, and implemented in a way that reduces risks.
A structured and consistent process is required to prevent disruptions, maintain system integrity, and comply with governance requirements.
IIA Standard 2110 - Governance:
IT governance must include structured change management processes.
Change management should be repeatable and standardized to ensure effectiveness.
IIA GTAG (Global Technology Audit Guide) on Change Management:
Change management must be conducted in a controlled environment to minimize unintended consequences and security risks.
A). The sole responsibility for change management is assigned to an experienced and competent IT team.
(Incorrect)
While IT plays a key role, change management should involve multiple stakeholders, including business units, security, compliance, and risk management teams.
IIA Standard 2120 - Risk Management states that risk oversight should not be assigned to a single function.
C). Internal audit participates in the implementation of change management throughout the organization.
(Incorrect)
Internal audit evaluates change management but does not implement it.
IIA Standard 1000 - Purpose, Authority, and Responsibility emphasizes that internal audit provides independent assurance rather than operational involvement.
D). All changes to systems must be approved by the highest level of authority within an organization.
(Incorrect)
Approvals should be based on a risk-based hierarchy rather than requiring executive-level approval for all changes.
IIA GTAG - Change Management recommends a tiered approval system based on change complexity and risk impact.
Explanation of Incorrect Answers:Conclusion:The most critical factor in effective IT change management is having a consistent, controlled process (Option B).
IIA References:
IIA Standard 2110 - Governance
IIA Standard 2120 - Risk Management
IIA Standard 1000 - Purpose, Authority, and Responsibility
IIA GTAG - Change Management
IIA-CIA-Part3-CN Exam Question 319
組織使用目標管理方法,員工績效是基於既定目標。關於此方法,下列哪一項敘述是正確的?
Correct Answer: C
* Understanding Management by Objectives (MBO):
* MBO is a performance management approach where employees set clear, measurable goals aligned with organizational objectives.
* Success depends on employee participation in goal-setting to increase motivation, commitment, and performance.
* Why MBO Works Best with Employee Involvement:
* Engagement and Accountability: Employees are more motivated and accountable when they help define their goals.
* Alignment with Organizational Strategy: Ensures that goals at all levels support the company's broader objectives.
* Improved Communication: Encourages collaboration between management and employees, leading to better alignment of expectations.
* Why Other Options Are Incorrect:
* A. It is particularly helpful to management when the organization is facing rapid change:
* MBO is not well-suited for rapidly changing environments, as predefined goals may become irrelevant quickly.
* B. It is more successful when adopted by mechanistic organizations:
* Mechanistic organizations (rigid structures, strict hierarchies) often struggle with MBO because it requires flexibility and employee participation.
* D. It is particularly successful in environments that are prone to having poor employer- employee relations:
* While MBO can improve communication, it is not a solution for poor employer- employee relations, as trust and collaboration are essential for its success.
* IIA's Perspective on Performance Management and Organizational Success:
* IIA Standard 2120 - Risk Management emphasizes the need for effective goal-setting and employee involvement in performance assessment.
* Balanced Scorecard Framework supports MBO principles by aligning employee performance with strategic objectives.
* COSO ERM Framework highlights the importance of employee engagement in goal-setting to enhance decision-making and risk management.
IIA References:
* IIA Standard 2120 - Risk Management & Employee Performance Assessment
* COSO ERM - Performance & Risk Alignment
* Balanced Scorecard Approach - Employee Participation in Goal Setting
Thus, the correct and verified answer is C. It is more successful when goal setting is performed not only by management, but by all team members, including lower-level staff.
* MBO is a performance management approach where employees set clear, measurable goals aligned with organizational objectives.
* Success depends on employee participation in goal-setting to increase motivation, commitment, and performance.
* Why MBO Works Best with Employee Involvement:
* Engagement and Accountability: Employees are more motivated and accountable when they help define their goals.
* Alignment with Organizational Strategy: Ensures that goals at all levels support the company's broader objectives.
* Improved Communication: Encourages collaboration between management and employees, leading to better alignment of expectations.
* Why Other Options Are Incorrect:
* A. It is particularly helpful to management when the organization is facing rapid change:
* MBO is not well-suited for rapidly changing environments, as predefined goals may become irrelevant quickly.
* B. It is more successful when adopted by mechanistic organizations:
* Mechanistic organizations (rigid structures, strict hierarchies) often struggle with MBO because it requires flexibility and employee participation.
* D. It is particularly successful in environments that are prone to having poor employer- employee relations:
* While MBO can improve communication, it is not a solution for poor employer- employee relations, as trust and collaboration are essential for its success.
* IIA's Perspective on Performance Management and Organizational Success:
* IIA Standard 2120 - Risk Management emphasizes the need for effective goal-setting and employee involvement in performance assessment.
* Balanced Scorecard Framework supports MBO principles by aligning employee performance with strategic objectives.
* COSO ERM Framework highlights the importance of employee engagement in goal-setting to enhance decision-making and risk management.
IIA References:
* IIA Standard 2120 - Risk Management & Employee Performance Assessment
* COSO ERM - Performance & Risk Alignment
* Balanced Scorecard Approach - Employee Participation in Goal Setting
Thus, the correct and verified answer is C. It is more successful when goal setting is performed not only by management, but by all team members, including lower-level staff.
IIA-CIA-Part3-CN Exam Question 320
首席審計主管想要實施企業範圍的資源規劃軟體。下列哪項內部稽核評估可以為軟體實施成功的可能性提供整體保證?
Correct Answer: A
Planning (ERP) software implementation, to evaluate whether the organization is prepared for the change.
This type of audit helps identify potential risks, resource availability, process gaps, and stakeholder alignment, which are critical for successful implementation.
A). Readiness assessment (Correct Answer) - This assessment evaluates if the organization has the necessary resources, technology, and processes in place for a successful ERP implementation.
B). Project risk assessment - While a project risk assessment identifies potential threats to project success, it does not provide an overall assurance on readiness before implementation.
C). Post-implementation review - This is conducted after the project is completed and does not help assess the likelihood of success before implementation.
D). Key phase review - This approach evaluates progress during implementation but does not provide enterprise-wide assurance before starting the project.
IIA GTAG 12 - Auditing IT Projects recommends a readiness assessment before launching major IT initiatives.
IIA IPPF Standard 2120 - Risk Management emphasizes identifying pre-implementation risks to improve project success.
COBIT 2019 - APO03 (Managed Enterprise Architecture) supports readiness evaluations before system rollouts.
Explanation of Each Option:IIA References:
This type of audit helps identify potential risks, resource availability, process gaps, and stakeholder alignment, which are critical for successful implementation.
A). Readiness assessment (Correct Answer) - This assessment evaluates if the organization has the necessary resources, technology, and processes in place for a successful ERP implementation.
B). Project risk assessment - While a project risk assessment identifies potential threats to project success, it does not provide an overall assurance on readiness before implementation.
C). Post-implementation review - This is conducted after the project is completed and does not help assess the likelihood of success before implementation.
D). Key phase review - This approach evaluates progress during implementation but does not provide enterprise-wide assurance before starting the project.
IIA GTAG 12 - Auditing IT Projects recommends a readiness assessment before launching major IT initiatives.
IIA IPPF Standard 2120 - Risk Management emphasizes identifying pre-implementation risks to improve project success.
COBIT 2019 - APO03 (Managed Enterprise Architecture) supports readiness evaluations before system rollouts.
Explanation of Each Option:IIA References:
- Latest Upload
- 136Microsoft.AB-210.v2026-08-15.q30
- 245CuramSoftware.CS0-003.v2026-08-15.q217
- 149PECB.ISO-14001-Lead-Auditor.v2026-08-14.q31
- 359CompTIA.SY0-701.v2026-08-14.q385
- 194CompTIA.XK0-006.v2026-08-14.q82
- 153Cisco.700-250.v2026-08-14.q34
- 307Cisco.300-420.v2026-08-13.q190
- 414IIA.IIA-CIA-Part3-CN.v2026-08-13.q328
- 193Fortinet.NSE7_SSE_AD-25.v2026-08-12.q38
- 278CyberAB.CMMC-CCP.v2026-08-12.q96
[×]
Download PDF File
Enter your email address to download IIA.IIA-CIA-Part3-CN.v2026-08-13.q328 Practice Test
