Which of the following statements is true regarding user-developed applications (UDAs)?
Correct Answer: B
User-Developed Applications (UDAs) are applications, spreadsheets, databases, or tools created and maintained by end-users rather than IT departments. They provide flexibility but also introduce risks related to security, accuracy, and change management. * Why Option B is Correct: * UDAs lack formal change management controls. * Since they are typically not subject to rigorous testing and documentation, modifications may introduce errors. * Updating or correcting a formula, macro, or script in a UDA may have unintended consequences that go unnoticed, leading to data integrity issues. * Why Other Options Are Incorrect: * Option A (UDAs are less flexible and more difficult to configure than traditional IT applications): * Incorrect. UDAs are more flexible and easier to modify compared to traditional IT applications, which undergo strict change controls. * Option C (UDAs typically are subjected to application development and change management controls): * Incorrect. Most UDAs lack formal governance or IT oversight. They are typically developed by business users with little or no structured IT controls. * Option D (Using UDAs typically enhances the organization's ability to comply with regulatory factors): * Incorrect. UDAs introduce compliance risks due to lack of security, audit trails, and formal change controls. * IIA GTAG - "Auditing User-Developed Applications": Discusses risks and controls related to UDAs. * IIA Practice Advisory 2130-1 (Control Risk Self-Assessment): Highlights the importance of internal controls over UDAs. * COSO Internal Control - Integrated Framework: Recommends applying IT general controls (ITGCs) to UDAs. IIA References:Thus, the correct answer is B. Updating UDAs may lead to various errors resulting from changes or corrections.
IIA-CIA-Part3 Exam Question 57
An organization produces two products, X and Y. The materials used for the production of both products are limited to 500 kilograms (kg) per month. All other resources are unlimited and their costs are fixed. Individual product details are as follows: Product X: Selling price per unit: $10; Materials per unit at $1/kg: 2 kg; Monthly demand: 100 units. Product Y: Selling price per unit: $13; Materials per unit at $1/kg: 6 kg; Monthly demand: 120 units. In order to maximize profit, how much of product Y should the organization produce each month?
Correct Answer: A
When a limiting factor exists, production should prioritize the product with the highest contribution per unit of scarce resource. Material is limited to 500 kg. Product X has contribution of $10 # $2 material cost = $8 per unit, or $4 per kg. Product Y has contribution of $13 # $6 material cost = $7 per unit, or about $1.17 per kg. Product X gives higher contribution per kg, so the organization should satisfy full demand for X first. Producing 100 units of X uses 200 kg, leaving 300 kg. Product Y requires 6 kg per unit, so 300 kg allows production of 50 units. Internal audit should verify that scarce-resource decisions use contribution per limiting factor, not contribution per unit alone. Therefore, Option A is correct.
IIA-CIA-Part3 Exam Question 58
Which of the following scenarios best illustrates a spear phishing attack?
Correct Answer: C
Understanding Spear Phishing Attacks: Spear phishing is a targeted cyberattack where attackers send personalized emails to trick individuals into providing sensitive data (e.g., passwords, financial information). Unlike regular phishing, which casts a wide net, spear phishing is highly customized and often appears to come from a trusted source. Why Option C Is Correct? The scenario describes a highly personalized email (related to a golf membership) that tricks the recipient into clicking a malicious hyperlink and entering sensitive data. This matches the definition of a spear phishing attack, where an attacker tailors a scam specifically for an individual. IIA GTAG 16 - Data Analytics and ISO 27001 emphasize the need for security awareness training to mitigate such threats. Why Other Options Are Incorrect? Option A (Website attack causing a server crash): This describes a Denial-of-Service (DoS) attack, not spear phishing. Option B (Generic recorded message requesting password data): This is vishing (voice phishing), not spear phishing. Spear phishing relies on personalized emails. Option D (Fake social media investment opportunity): This describes mass phishing, which targets multiple users, unlike spear phishing, which is highly targeted. Spear phishing is a targeted attack that uses personal details to deceive individuals, making option C the best choice. IIA GTAG 16 and ISO 27001 emphasize cybersecurity awareness to prevent such attacks. Final Justification:IIA References: IIA GTAG 16 - Data Analytics in Cybersecurity Audits ISO 27001 - Cybersecurity Best Practices NIST SP 800-61 - Incident Response Guidelines for Phishing Attacks
IIA-CIA-Part3 Exam Question 59
An organization that sells products to a foreign subsidiary wants to charge a price that will decrease import tariffs. Which of the following is the best course of action for the organization?
Correct Answer: A
Comprehensive and Detailed In-Depth Explanation: Transfer pricing refers to the pricing of goods, services, and intangibles transferred between related entities. In international transactions, companies often adjust transfer prices to minimize tax liabilities and import tariffs. Decreasing the transfer price (Option A) results in a lower declared customs value, reducing import tariffs paid to the foreign country. Increasing the transfer price (Option B) would raise import tariffs, making it less favorable. Charging the arm's length price (Option C) ensures compliance with tax regulations but does not necessarily reduce import tariffs. Optimal transfer pricing (Option D) is a general term that does not specifically focus on reducing tariffs. Thus, decreasing the transfer price is the best approach. Reference: IIA Business Acumen - Transfer Pricing Strategies
IIA-CIA-Part3 Exam Question 60
According to the COSO enterprise risk management framework, which of the following is not a typical responsibility of the chief risk officer?
Correct Answer: C
The chief risk officer typically coordinates enterprise risk management by establishing risk language, supporting risk categories, defining ERM roles, facilitating risk reporting, and integrating ERM into management activities. However, providing the board with an independent, objective risk perspective on financial reporting is more closely aligned with internal audit or external audit assurance responsibilities, not the CRO's typical management role. The CRO is part of management and may provide risk reporting, but independence and objectivity in assurance over financial reporting are not typical CRO responsibilities. Internal audit should preserve independence by evaluating risk management processes without owning them. Therefore, Option C is not a typical chief risk officer responsibility.