Which of the following intangible assets is considered to have an indefinite life?
Correct Answer: C
An intangible asset is an asset that lacks physical substance but has value due to its legal rights or expected economic benefits. Some intangible assets have finite useful lives (e.g., copyrights, patents) and are amortized, while others have indefinite useful lives and are not amortized but tested for impairment. * (A) Underground oil deposits. # * Incorrect. Oil deposits are natural resources, not intangible assets. They are classified as depletable assets because their value declines as they are extracted. * (B) Copyright. # * Incorrect. A copyright grants exclusive rights to reproduce and distribute creative works, but it has a finite legal life (typically 50-100 years, depending on jurisdiction). It is amortized over time. * (C) Trademark. # * Correct. A trademark (e.g., a company's logo or brand name) is considered an indefinite-life intangible asset because it can be renewed indefinitely as long as the business continues to use it and follows renewal requirements. * According to IIA GTAG - "Auditing Intangible Assets", trademarks are subject to impairment testing, but they are not amortized unless their useful life becomes definite. * (D) Land. # * Incorrect. Land is a tangible asset, not an intangible one. While it has an indefinite life, it does not fit the category of intangible assets. * IIA GTAG - "Auditing Intangible Assets" * IIA Standard 2130 - Control Activities (Asset Management) * IFRS and GAAP Guidelines - Indefinite and Finite-Lived Intangible Assets Analysis of Answer Choices:IIA References:Thus, the correct answer is C (Trademark), as trademarks have indefinite lives unless there is evidence to the contrary.
IIA-CIA-Part3 Exam Question 77
Which of the following attributes of data are cybersecurity controls primarily designed to protect?
Correct Answer: B
Cybersecurity controls are primarily designed to protect the Confidentiality, Integrity, and Availability (CIA) of data. These are the three fundamental principles of cybersecurity and are essential for protecting organizational information assets. Let's analyze each option: Option A: Veracity, velocity, and variety. Incorrect. These attributes are commonly associated with big data and data analytics rather than cybersecurity. Cybersecurity controls focus on ensuring that data is secure, rather than on its volume, speed, or diversity. IIA Reference: Cybersecurity risk management frameworks emphasize the CIA triad over big data attributes. (IIA GTAG: Auditing Cybersecurity Risk) Option B: Integrity, availability, and confidentiality. Correct. These three principles are at the core of cybersecurity: Confidentiality: Ensures that sensitive information is only accessible to authorized individuals. Integrity: Protects data from unauthorized modifications or corruption. Availability: Ensures that data and systems are accessible when needed. IIA Reference: The IIA's guidance on IT governance highlights the CIA triad as the foundation of cybersecurity. (IIA GTAG: Information Security Governance) Option C: Accessibility, accuracy, and effectiveness. Incorrect. While these attributes are important in data management and usability, they do not directly define cybersecurity controls. Option D: Authorization, logical access, and physical access. Incorrect. While these are essential security components, they fall under broader IT security measures rather than forming the fundamental principles of cybersecurity.
IIA-CIA-Part3 Exam Question 78
An internal audit activity is piloting a data analytics model, which aims to identify anomalies in payments to vendors and potential fraud indicators. Which of the following would be the most appropriate criteria for assessing the success of the piloted model?
Correct Answer: A
To assess the success of a piloted data analytics model in identifying anomalies in vendor payments and potential fraud, the most appropriate criterion is the accuracy of the model in identifying true positives-cases flagged as anomalies that were later confirmed as valid fraud risks. Effectiveness of the Model: The primary goal of the model is to enhance the internal audit activity's ability to detect fraudulent transactions. The best way to measure success is to analyze how many flagged transactions were confirmed as fraudulent or erroneous. Reduction of False Positives and False Negatives: A model that generates too many false positives (incorrectly flagged transactions) can lead to inefficiencies, while too many false negatives (missed fraudulent cases) can reduce the effectiveness of fraud detection. Alignment with Internal Audit Standards: According to IIA Standard 1220 - Due Professional Care, internal auditors must apply appropriate tools and techniques (such as data analytics) to enhance audit effectiveness. The model's success should be assessed based on its ability to provide reliable, actionable insights. IIA Practice Guide on Data Analytics: Recommends assessing the predictive accuracy of models by comparing flagged transactions against actual outcomes. B). The development and maintenance costs associated with the model (Incorrect) While cost is a consideration, it does not directly assess the effectiveness of the model in detecting fraud. High costs may indicate inefficiency, but they do not determine whether the model is accurately identifying fraudulent transactions. IIA Standard 2100 - Nature of Work emphasizes that internal audit activities must contribute to the improvement of governance, risk management, and control, which requires a focus on results rather than just cost. C). The feedback of auditors involved with developing the model (Incorrect) Feedback is useful but subjective. The ultimate test of success is not auditor perception but whether the model correctly identifies fraudulent or anomalous transactions. IIA Practice Guide: Auditing Data Analytics suggests that while stakeholder feedback is valuable, empirical validation (accuracy of flagged cases) should be the primary success measure. D). The number of criminal investigations initiated based on the outcomes of the model (Incorrect) While fraud detection can lead to investigations, the number of investigations is not necessarily an accurate measure of model success. Some flagged cases may not lead to criminal investigations due to materiality, lack of sufficient evidence, or management decisions. According to IIA Standard 2120 - Risk Management, internal auditors must evaluate fraud risk management effectiveness, which includes detecting and preventing fraud, not just the legal consequences. Explanation of Answer Choice A (Correct Answer):Explanation of Incorrect Answers:Conclusion:The best success criterion for the piloted data analytics model is the percentage of cases flagged by the model and confirmed as positives (Option A), as it directly measures the model's effectiveness in detecting actual fraud cases. IIA References: IIA Standard 1220 - Due Professional Care IIA Standard 2100 - Nature of Work IIA Standard 2120 - Risk Management IIA Practice Guide: Auditing Data Analytics
IIA-CIA-Part3 Exam Question 79
Which of the following physical access controls is most likely to be based on the "something you have" concept?
Correct Answer: C
Comprehensive and Detailed In-Depth Explanation: Authentication methods are categorized into three factors: Something you know (e.g., passwords, PINs). Something you have (e.g., ID cards, key fobs, smart cards). Something you are (e.g., biometrics like fingerprints, retina scans). Option C (A card-key scanner) aligns with "something you have", as it requires a physical token (card) for authentication. Option A (Retina scan) and Option D (Fingerprint scanner) fall under biometric authentication ("something you are"). Option B (PIN code reader) is based on "something you know". Thus, C is the correct answer because a card-key represents a physical access control mechanism based on possession. Reference: IIA IT Security & Authentication Controls
IIA-CIA-Part3 Exam Question 80
Which of the following types of date analytics would be used by a hospital to determine which patients are likely to require remittance for additional treatment?
Correct Answer: A
Definition of Predictive Analytics: Predictive analytics uses historical data, machine learning, and statistical algorithms to forecast future outcomes. In the healthcare sector, it is used to predict patient readmission rates and identify those at high risk of needing additional treatment. How Predictive Analytics Applies to Hospitals: Hospitals analyze patient histories, symptoms, treatments, and recovery rates to determine the likelihood of readmission. Predictive models help healthcare providers take proactive measures, such as tailored post-discharge care plans, to reduce readmission risks. This leads to better patient outcomes and cost savings. Why Other Options Are Incorrect: B). Prescriptive analytics: Prescriptive analytics goes beyond prediction and provides recommendations for action. In this case, the hospital is only determining which patients are likely to require additional treatment, not recommending treatments. C). Descriptive analytics: Descriptive analytics focuses on summarizing past data without making predictions. It would be used to report on past patient admissions but not to predict future readmissions. D). Diagnostic analytics: Diagnostic analytics analyzes the causes of past events but does not forecast future patient readmissions. IIA's Perspective on Data Analytics in Decision-Making: IIA GTAG (Global Technology Audit Guide) on Data Analytics emphasizes the role of predictive analytics in risk assessment and operational efficiency. COSO ERM Framework supports predictive modeling as part of strategic risk management. IIA References: IIA GTAG - Data Analytics in Risk Management COSO Enterprise Risk Management (ERM) Framework NIST Big Data Framework for Predictive Analytics