The chief audit executive (CAE) identified an unacceptable risk and believes that the risk is not being mitigated to an acceptable level. Which of the following is the CAE ' s next step in this situation?
Correct Answer: D
When internal audit identifies a risk that appears unacceptable, the CAE should first discuss the matter with the responsible management. This ensures management has an opportunity to explain their rationale or adjust actions before escalation. Option A (direct escalation to senior management) or Option C (to the board) are appropriate only if management refuses to act. Option B (sending a letter with a deadline) is not aligned with IIA guidance. Reference: IIA Standards - Standard 2600: Communicating the Acceptance of Risks.
IIA-CIA-Part3 Exam Question 197
When determining the level of physical controls required for a workstation, which of the following factors should be considered?
Correct Answer: B
When determining the level of physical controls required for a workstation, the most critical factor is its value to the business. Physical controls are security measures implemented to protect assets from unauthorized access, damage, or theft. Asset Value # Determines the level of protection required. Risk Assessment # Identifies threats like theft, sabotage, or natural disasters. Compliance Requirements # Ensures alignment with security regulations and best practices. (A) Ease of use. Incorrect: While user-friendliness is important, security measures are primarily based on asset value and risk, not convenience. IIA Standard 2110 (Governance) emphasizes security over ease of use. (B) Value to the business. (Correct Answer) The higher the workstation ' s importance to business operations, the stronger the physical controls required. Workstations handling sensitive data or critical systems require additional security. COSO ERM - Risk Assessment requires evaluating asset value when designing security controls. (C) Intrusion prevention. Partially correct but secondary: Intrusion prevention is one of many security concerns, but the primary driver for determining physical controls is the asset's business value. (D) Ergonomic model. Incorrect: Ergonomics is about user comfort and efficiency, not security. IIA Standard 2120 - Risk Management: Requires risk-based decision-making, including evaluating asset value. GTAG 9 - Identity and Access Management: Stresses that security measures must align with asset value and business risk. COSO ERM - Risk Assessment: Establishes asset value as a key determinant in risk-based security controls. Factors Considered in Physical Security Decisions:Analysis of Each Option:IIA References Supporting the The answer:Thus, the correct answer is (B) because the level of physical controls should be determined based on how critical the workstation is to business operations.
IIA-CIA-Part3 Exam Question 198
When would a contract be dosed out?
Correct Answer: B
A contract is closed out when all the contractual terms have been fully satisfied, including the completion of deliverables, final payments, and any post-contract evaluations or obligations. Correct Answer (B - When all contractual obligations have been discharged) According to contract management principles and IIA standards, a contract is officially closed out once: All agreed-upon deliverables have been completed. All payments and financial obligations are settled. Final performance evaluations or audits are completed. The contract is formally reviewed and documented for closure. The IIA's GTAG 3: Contract Management Framework supports that contract closure occurs after full performance and obligations are met. Why Other Options Are Incorrect: Option A (When there's a dispute between contracting parties): Disputes do not necessarily close out a contract; instead, they may lead to mediation, renegotiation, or legal action. The contract remains active until resolved. The IIA's Practice Guide: Auditing Contracts recommends dispute resolution mechanisms but does not define them as a reason for contract closure. Option C (When there is a force majeure event): A force majeure (unforeseen event like natural disasters or war) may suspend or modify contractual obligations but does not always lead to closure. The contract may be renegotiated or resumed once conditions allow. Option D (When the termination clause is enacted): Termination and closure are not the same. Termination means ending the contract before full obligations are met, whereas closure means fulfilling all obligations. IIA GTAG 3: Contract Management Framework explains that contract termination can occur under specific clauses, but closure happens only after all duties are fulfilled. IIA GTAG 3: Contract Management Framework - Covers contract lifecycle, including closeout procedures. IIA Practice Guide: Auditing Contracts - Details contract auditing, dispute resolution, and obligations fulfillment. Step-by-Step Explanation:IIA References for Validation:
IIA-CIA-Part3 Exam Question 199
Which of the following is most important for an internal auditor to check with regard to the database version?
Correct Answer: B
The most important database version issue is whether the version is still supported by the vendor. Unsupported database software may no longer receive security patches, bug fixes, compatibility updates, or technical support. This creates significant operational, cybersecurity, compliance, and availability risk. Using the most recent version is not always necessary because organizations may deliberately delay upgrades until stability and compatibility are confirmed. A recent upgrade does not automatically mean the version is secure or supported. Restricting access to version information may reduce reconnaissance risk, but it is secondary to vendor support status. Internal audit should review version support, patch management, upgrade planning, known vulnerabilities, and compensating controls. Therefore, Option B is correct.
IIA-CIA-Part3 Exam Question 200
Which of the following best describes the primary objective of cybersecurity?