Which of the following best describes the concept of relevant cost?
Correct Answer: B
A relevant cost is a future cost that differs among decision alternatives. It matters because it can influence the decision being made. Costs that are the same under all alternatives are irrelevant because they do not change the outcome. Past costs are sunk costs and should not affect current decisions because they cannot be changed, even if they differ historically. For example, in a make-or-buy decision, avoidable future production costs are relevant, while already-incurred equipment costs are usually not. Internal auditors reviewing management decisions should determine whether analyses improperly include sunk costs or exclude avoidable future costs. Option A is incorrect because a future cost that is the same among alternatives is irrelevant. Options C and D are incorrect because past costs are not relevant to future decisions. Therefore, Option B is correct.
IIA-CIA-Part3 Exam Question 202
Which of the following activities best illustrates a user's authentication control?
Correct Answer: C
Authentication control is a security measure used to verify the identity of users before granting access to systems or data. Authentication methods ensure that only authorized individuals can access resources. * Why Option C (Users have to validate their identity with a smart card) is Correct: * Authentication is the process of verifying a user's identity before granting access. * Smart card authentication is a strong authentication method because it requires a physical device (smart card) and a PIN or biometric verification. * This falls under multi-factor authentication (MFA), enhancing security by combining something the user has (smart card) with something they know (PIN). * Why Other Options Are Incorrect: * Option A (Identity requests are approved in two steps): * Incorrect because this refers to identity approval (authorization), not authentication. * Option B (Logs are checked for misaligned identities and access rights): * Incorrect because log monitoring is a detective control, not an authentication control. * Option D (Functions can be performed based on access rights): * Incorrect because this describes authorization (determining what a user can do after authentication). * IIA GTAG - "Auditing Identity and Access Management": Covers authentication methods like smart cards and multi-factor authentication. * COBIT 2019 - DSS05 (Manage Security Services): Recommends strong authentication controls, including smart card validation. * NIST Cybersecurity Framework - "Access Control Guidelines": Highlights authentication best practices, including smart card use. IIA References:
IIA-CIA-Part3 Exam Question 203
What relationship exists between decentralization and the degree, importance, and range of lower-level decision making?
Correct Answer: B
Decentralization refers to the process by which decision-making authority is distributed to lower levels of management within an organization. The degree, importance, and range of decision-making at lower levels are directly related to the extent of decentralization. Direct Relationship Defined: As decentralization increases, more decision-making power is transferred to lower levels of the organization. This means that managers and employees at lower levels are empowered to make a broader range of decisions with greater significance. The Importance of Lower-Level Decision-Making in a Decentralized Structure: A decentralized structure allows lower-level managers to respond quickly to operational issues and make important decisions without seeking approval from top management. This enables increased efficiency, innovation, and adaptability in a dynamic business environment. IIA's Perspective on Governance and Decision-Making: According to the International Professional Practices Framework (IPPF) by the Institute of Internal Auditors (IIA), internal auditors must assess the governance structure of an organization, which includes understanding how decision-making authority is allocated. The IIA's Three Lines Model highlights the role of management in decision-making, emphasizing the need for a clear and effective delegation of authority. IIA Standard 2110 - Governance states that internal auditors must evaluate decision-making processes to ensure they align with the organization's objectives and risk management strategies. Supporting Business Concepts: Decentralized organizations like multinational corporations, franchises, and divisional structures benefit from empowering lower levels with decision-making authority. In contrast, centralized organizations retain control at the top, limiting the scope of decisions at lower levels. A direct relationship exists because the more decentralized a company is, the greater the responsibility of lower levels in making crucial decisions. IIA References: IPPF Standards: Standard 2110 - Governance IIA's Three Lines Model - Emphasizing clear delegation of authority COSO Internal Control Framework - Discusses decentralized decision-making in control environments Business Knowledge for Internal Auditing (IIA Study Guide) - Governance and decision-making structure
IIA-CIA-Part3 Exam Question 204
With regard to project management, which of the following statements about project crashing Is true?
Correct Answer: D
* Definition of Project Crashing: * Project crashing is a schedule compression technique used in project management to reduce the project completion time without changing its scope. * It involves adding extra resources (labor, equipment, budget) to critical path activities to complete them faster. * Key Aspects of Project Crashing: * Reduces project duration by increasing resources. * Leads to higher costs due to additional labor or expedited material procurement. * Used when project deadlines must be met and standard scheduling techniques are insufficient. * Why Other Options Are Incorrect: * A. It leads to an increase in risk and often results in rework: * While crashing can increase costs and risk, it does not necessarily result in rework unless poorly executed. * B. It is an optimization technique where activities are performed in parallel rather than sequentially: * This describes fast-tracking, not crashing. Fast-tracking involves overlapping tasks, while crashing adds resources to speed up tasks. * C. It involves a revaluation of project requirements and/or scope: * Crashing does not change project scope; it only shortens the schedule by allocating additional resources. * IIA's Perspective on Project Risk and Management: * IIA Standard 2110 - Governance emphasizes the importance of project risk assessment, including schedule compression risks. * COSO ERM Framework identifies project cost overruns and resource misallocations as key risks in project execution. * PMBOK (Project Management Body of Knowledge) defines crashing as a schedule compression technique used when deadlines must be met at additional cost. IIA References: * IIA Standard 2110 - Governance & Risk Oversight in Project Management * COSO Enterprise Risk Management (ERM) - Project Risk Considerations * PMBOK Guide - Schedule Compression Techniques (Crashing & Fast-Tracking) Thus, the correct and verified answer is D. It is a compression technique in which resources are added so the project is completed faster.
IIA-CIA-Part3 Exam Question 205
Which of the following risks is best addressed by encryption?
Correct Answer: B
Comprehensive and Detailed In-Depth Explanation: Encryption is a security measure that protects the confidentiality of sensitive data by converting it into an unreadable format. This directly addresses privacy risks by preventing unauthorized access to personal or confidential information. Option A (Information integrity risk) - Integrity controls (e.g., checksums, hash functions) address this risk. Option C (Access risk) - Managed through authentication and access controls, not encryption. Option D (Software risk) - Related to vulnerabilities, which encryption does not directly mitigate. Since encryption protects privacy by securing sensitive data, Option B is correct. Reference: IIA IT Security - Data Privacy & Encryption Standards