An organization ' s chief audit executive scheduled an assurance engagement on the key processes and controls related to organizational culture. Which approach to auditing the organization ' s culture did the CAE use?
Correct Answer: C
A targeted approach is used when internal audit performs a specific engagement focused directly on organizational culture, including culture-related processes, controls, risks, and indicators. This differs from an integrated approach, where culture considerations are embedded into multiple audits across the audit plan. A top-down approach would begin with senior leadership, governance, tone at the top, and strategic cultural expectations. A blended approach would combine direct culture audits with culture assessment within other engagements. In this question, the CAE scheduled an assurance engagement specifically on key processes and controls related to organizational culture, making it a focused or targeted engagement. Therefore, Option C is correct.
IIA-CIA-Part3 Exam Question 62
An attacker, posing as a bank representative, convinced an employee to release certain, financial information that ultimately resulted in fraud. Which of the following best describes this cybersecurity risk?
Correct Answer: D
Social engineering is a psychological manipulation technique used by attackers to trick individuals into divulging sensitive information. Instead of exploiting technical vulnerabilities, it targets human weaknesses such as trust, fear, or urgency. * Manipulates Human Behavior - The attacker impersonates a trusted entity (a bank representative) to deceive the employee. * Leads to Unauthorized Information Disclosure - The employee unknowingly provides sensitive financial data. * Results in Fraud - The stolen information is misused, causing financial loss. * A. Shoulder Surfing - This occurs when an attacker physically observes someone entering sensitive data (e.g., watching a person type a password). * B. Pharming - This involves redirecting users to a fraudulent website to steal their credentials, not direct impersonation. * C. Phishing - This is a broad category of social engineering that typically involves emails or fake websites, whereas this scenario describes a direct impersonation attack. * IIA's GTAG on Cybersecurity - Discusses social engineering as a key risk for organizations. * NIST SP 800-61 (Incident Handling Guide) - Identifies social engineering as a common attack vector. * COBIT 2019 (IT Governance Framework) - Highlights human-related cybersecurity risks. Why Social Engineering is the Correct Answer?Why Not the Other Options?IIA References:
IIA-CIA-Part3 Exam Question 63
What security feature would Identity a legitimate employee using her own smart device to gam access to an application run by the organization?
Correct Answer: B
To ensure security when employees use their own smart devices to access organizational applications, the best approach is to allow only pre-approved devices that meet the organization's security standards. Device Security & Compliance: Approved devices are verified for security measures like encryption, mobile device management (MDM), and antivirus protection. Risk Management: Restricting access to pre-approved devices reduces the risk of malware, unauthorized access, and vulnerabilities. IT Control & Monitoring: IT can enforce security updates, compliance policies, and access control mechanisms on pre-approved devices. Option A (Using a jailbroken or rooted smart device feature): Jailbroken or rooted devices remove security protections and create severe security vulnerabilities. Option C (Obtaining written assurance from the employee that security policies and procedures are followed): Written assurances alone are not a security measure; technical controls must be enforced. Option D (Introducing a security question known only by the employee): Security questions are weak authentication measures and do not verify the legitimacy of a device. IIA's GTAG on Information Security Management stresses the importance of device security and requiring IT- approved devices. NIST Special Publication 800-124 (referenced in IIA's IT Audit Guidance) highlights best practices for securing mobile devices in an enterprise setting, recommending pre-approved devices. Why Option B is Correct:Why Other Options Are Incorrect:IIA References:Thus, the most appropriate answer is B. Using only smart devices previously approved by the organization.
IIA-CIA-Part3 Exam Question 64
A capital investment project will have a higher net present value, everything else being equal, if it has:
Correct Answer: D
Net present value is based on the time value of money. Cash received earlier has a higher present value than the same amount received later because earlier cash can be reinvested and is exposed to less uncertainty. Therefore, if total cash inflows are the same, a project with larger inflows in earlier years will have a higher NPV. Option A is incorrect because a higher initial investment increases cash outflow and lowers NPV. Option B is also wrong because a higher discount rate reduces the present value of future cash inflows. Option C is incorrect because later cash inflows are discounted more heavily. Internal auditors reviewing capital budgeting should test whether timing assumptions, discount rates, and cash-flow forecasts are reasonable. Therefore, Option D is correct.
IIA-CIA-Part3 Exam Question 65
Which of the following assumptions regarding cost-volume-profit analysis is true?
Correct Answer: A
Cost-volume-profit analysis relies on simplifying assumptions. One key assumption is that changes in total costs and revenues are driven by changes in activity volume within the relevant range. Costs are classified as fixed or variable, and their behavior is assumed to remain predictable over the range analyzed. Option B is incorrect because cost and revenue behavior is not assumed to be inverse. Option C is incorrect because when multiple products are sold, CVP analysis usually assumes the sales mix remains constant. Option D is incorrect because both fixed and variable costs must be classified accurately. Internal auditors reviewing budgeting or break-even analysis should verify that CVP assumptions are reasonable and disclosed. Therefore, Option A is correct.