According to IIA guidance, which of the following statements is true with regard to workstation computers that access company information stored on the network?
Correct Answer: B
Reference: IIA Business Knowledge for Internal Auditing, Workstation Security section.
IIA-CIA-Part3 Exam Question 92
Which of the following Issues would be a major concern for internal auditors when using a free software to analyze a third-party vendor's big data?
Correct Answer: C
Comprehensive and Detailed Step-by-Step Explanation with all IIA References: Understanding the Concern: Internal auditors must assess risks when using free software for data analysis, particularly regarding data security, confidentiality, and integrity. When analyzing third-party vendor data, the primary risk is data compromise, unauthorized access, or data loss due to inadequate security controls in free software. Why Data Security is the Biggest Concern: Free software often lacks robust security measures, making sensitive vendor data susceptible to breaches, cyberattacks, or loss. Ensuring compliance with data protection regulations (e.g., GDPR, CCPA) and contractual obligations with third-party vendors is critical. Why Other Options Are Incorrect: A). The ability to use the software with ease # While usability is important, security risks outweigh ease of use in an internal audit context. B). The ability to purchase upgraded features # Upgrades may improve analysis capabilities but do not address security concerns. D). The ability to download the software # Installing software is a technical issue, not a major audit concern compared to security. IIA Standards and References: IIA Standard 2110 - Governance: Internal auditors should ensure data security risks are addressed in technology use. IIA Standard 2120 - Risk Management: Auditors must evaluate the organization's ability to safeguard data. IIA GTAG (Global Technology Audit Guide) on Data Analytics (2017): Recommends ensuring security of third-party data when using analytical tools. Thus, the correct answer is C: The ability to ensure that big data entered into the software is secure from potential compromises or loss.
IIA-CIA-Part3 Exam Question 93
Which of the following represents a basis for consolidation under the International Financial Reporting Standards?
Correct Answer: B
Under International Financial Reporting Standards (IFRS 10 - Consolidated Financial Statements), an entity is required to consolidate its financial statements based on the control principle rather than ownership percentage alone. Why Option B (Control ownership) is Correct: According to IFRS 10, consolidation is required when an entity has control over another entity. Control is defined as having power over the investee, exposure to variable returns, and the ability to influence those returns. Even if an entity owns less than 50% of voting rights, it may still have control through contractual arrangements, rights over key decisions, or majority board influence. Why Other Options Are Incorrect: Option A (Variable entity approach): This is a concept used in U.S. GAAP (ASC 810 - Variable Interest Entities) rather than IFRS. IFRS focuses on the broader control model. Option C (Risk and reward): IFRS previously considered risk and reward under IAS 27/SIC-12, but IFRS 10 replaced this with the control model. Option D (Voting interest): Voting rights alone do not determine consolidation under IFRS. Control can exist even without majority voting rights through contractual arrangements or potential voting rights. IFRS 10 - Consolidated Financial Statements: Defines the principle of control for consolidation. IIA GTAG - "Auditing Financial Reporting Risks": Discusses the impact of IFRS consolidation principles. COSO ERM Framework: Emphasizes risk assessment in financial reporting, including consolidation decisions. IIA References:Thus, the correct answer is B. Control ownership.
IIA-CIA-Part3 Exam Question 94
The internal audit activity has identified accounting errors that resulted in the organization overstating its net income for the fiscal year. Which of the following is the most likely cause of this overstatement?
Correct Answer: B
Understanding Net Income Overstatement: Net Income (NI) = Revenue - Expenses If net income is overstated, then expenses must be understated or revenue must be overstated. Cost of Goods Sold (COGS) is an expense that directly affects net income. Why Understated COGS Causes Overstated Net Income: COGS = Beginning Inventory + Purchases - Ending Inventory If COGS is understated, expenses are lower than they should be, resulting in a higher net income. Why Other Options Are Incorrect: A). Beginning inventory overstated: This would increase COGS (not decrease it), leading to a lower net income. C). Ending inventory understated: This would increase COGS, reducing net income. D). COGS overstated: This would result in a lower net income, not an overstatement. IIA Standards and References: IIA Standard 2120 - Risk Management: Internal auditors must assess financial misstatements and risks. IIA Practice Guide: Auditing Financial Statement Close Processes (2018): Emphasizes accuracy in inventory and expense reporting. COSO Internal Control - Integrated Framework: Supports accuracy in financial reporting and controls over misstated financial data. Thus, the correct answer is B: Cost of goods sold was understated for the year.
IIA-CIA-Part3 Exam Question 95
An organization has decided to allow its managers to use their own smart phones at work. With this change, which of the following is most important to Include In the IT department's comprehensive policies and procedures?
Correct Answer: A
When an organization allows managers to use their own smartphones at work under a Bring Your Own Device (BYOD) policy, IT security and risk management become critical. The most important policy and procedure to include would be documenting the process for discontinuing use of the devices to ensure data security, compliance, and risk mitigation when employees leave the company or change roles. Data Security & Compliance: Ensuring that sensitive company data is removed securely when an employee leaves or replaces a device is crucial to prevent unauthorized access. Access Control & Endpoint Management: The IT department needs a clear policy to revoke access to corporate applications and networks when a device is no longer in use. Risk Mitigation: Unauthorized access to company systems through lost, stolen, or retired devices can lead to security breaches. Option B (Required removal of personal pictures and contacts): Personal data does not impact company security and is irrelevant to corporate IT policies. Option C (Required documentation of expiration of contract with service provider): This is the employee's responsibility, not the organization's, and does not address security risks. Option D (Required sign-off on conflict of interest statement): While conflict of interest policies are important, they are unrelated to IT security concerns related to BYOD. IIA's GTAG (Global Technology Audit Guide) on Managing and Auditing IT Vulnerabilities emphasizes the importance of BYOD risk management, including clear procedures for device decommissioning. IIA's Business Knowledge for Internal Auditing (CIA Exam Syllabus - Part 3) highlights IT governance frameworks that require policies for data access and security when using personal devices. Why Option A is Correct:Why Other Options Are Incorrect:IIA References:Thus, the most appropriate answer is A. Required documentation of process for discontinuing use of the devices.