IIA-CIA-Part3 Exam Question 221
A one-time password would most likely be generated in which of the following situations?
Correct Answer: D
A one-time password (OTP) is a unique, temporary password that is valid for a single login session or transaction. It is commonly used in multi-factor authentication (MFA) systems to enhance security.
Correct Answer (D - When an Employee Uses a Key Fob to Produce a Token) Key fobs generate a time-sensitive one-time password (OTP), which is used in conjunction with a traditional password to enhance security.
These devices are part of two-factor authentication (2FA) or multi-factor authentication (MFA) methods.
The IIA GTAG 9: Identity and Access Management discusses OTP tokens as a strong security control to prevent unauthorized access.
Why Other Options Are Incorrect:
Option A (When an employee accesses an online digital certificate):
Digital certificates authenticate users or devices, but they do not generate one-time passwords.
Option B (When an employee ' s biometrics have been accepted):
Biometric authentication (e.g., fingerprint, facial recognition) grants access based on biological traits, not an OTP.
Option C (When an employee creates a unique digital signature):
Digital signatures authenticate documents and transactions, but they are not time-sensitive one-time passwords.
IIA GTAG 9: Identity and Access Management - Covers OTP tokens as a security measure.
IIA Practice Guide: Auditing IT Security Controls - Recommends OTPs as part of secure authentication.
Step-by-Step Explanation:IIA References for Validation:Thus, D is the correct answer because key fobs generate one-time passwords for secure authentication.
Correct Answer (D - When an Employee Uses a Key Fob to Produce a Token) Key fobs generate a time-sensitive one-time password (OTP), which is used in conjunction with a traditional password to enhance security.
These devices are part of two-factor authentication (2FA) or multi-factor authentication (MFA) methods.
The IIA GTAG 9: Identity and Access Management discusses OTP tokens as a strong security control to prevent unauthorized access.
Why Other Options Are Incorrect:
Option A (When an employee accesses an online digital certificate):
Digital certificates authenticate users or devices, but they do not generate one-time passwords.
Option B (When an employee ' s biometrics have been accepted):
Biometric authentication (e.g., fingerprint, facial recognition) grants access based on biological traits, not an OTP.
Option C (When an employee creates a unique digital signature):
Digital signatures authenticate documents and transactions, but they are not time-sensitive one-time passwords.
IIA GTAG 9: Identity and Access Management - Covers OTP tokens as a security measure.
IIA Practice Guide: Auditing IT Security Controls - Recommends OTPs as part of secure authentication.
Step-by-Step Explanation:IIA References for Validation:Thus, D is the correct answer because key fobs generate one-time passwords for secure authentication.
IIA-CIA-Part3 Exam Question 222
Which of the following corporate social responsibility strategies is likely to be most effective in minimizing confrontations with influential activists and lobbyists?
Correct Answer: A
The most effective CSR strategy for minimizing confrontations with activists and lobbyists is continual evaluation of stakeholder needs and opinions. Activists and lobbyists often challenge organizations when they believe stakeholder concerns are ignored, concealed, or handled reactively. Ongoing stakeholder engagement allows the organization to identify concerns early, understand expectations, adjust practices, and communicate credibly. Strict legal compliance is necessary but may not satisfy broader social expectations. Publicity campaigns can backfire if they appear superficial or unsupported by action. Philanthropy may build goodwill but does not address underlying stakeholder concerns. Internal audit can assess whether CSR governance includes stakeholder mapping, grievance mechanisms, transparent reporting, and escalation procedures.
Therefore, Option A is correct.
Therefore, Option A is correct.
IIA-CIA-Part3 Exam Question 223
Which of the following is an example of internal auditors applying data mining techniques for exploratory purposes?
Correct Answer: C
Data Mining for Exploratory Purposes:
Exploratory data mining involves analyzing large datasets to identify trends, patterns, and risks before conducting specific audits.
Internal auditors use data mining to assess risks and determine potential audit subjects, making it a key input in audit planning.
Aligns with IIA Practice Guide on Data Analytics:
Exploratory analysis helps auditors prioritize areas with high-risk indicators.
Supports IIA Standard 2010 - Planning, which requires risk-based audit planning.
A). Internal auditors perform reconciliation procedures to support an external audit of financial reporting.
(Incorrect)
Reconciliation is a procedural task, not an exploratory data mining activity.
Supports external audit rather than internal audit's strategic risk assessment role.
B). Internal auditors perform a systems-focused analysis to review relevant controls. (Incorrect) This relates more to evaluating control effectiveness rather than exploratory data mining.
Does not directly contribute to identifying new audit areas.
D). Internal auditors test IT general controls with regard to operating effectiveness versus design. (Incorrect) Testing IT general controls is a structured evaluation, not an exploratory data mining technique.
Exploratory data mining is used to identify risks before formal testing occurs.
Explanation of Answer Choice C (Correct Answer):Explanation of Incorrect Answers:Conclusion:The best example of exploratory data mining by internal auditors is risk assessment for audit planning (Option C).
IIA References:
IIA Standard 2010 - Planning
IIA Practice Guide: Data Analytics
Exploratory data mining involves analyzing large datasets to identify trends, patterns, and risks before conducting specific audits.
Internal auditors use data mining to assess risks and determine potential audit subjects, making it a key input in audit planning.
Aligns with IIA Practice Guide on Data Analytics:
Exploratory analysis helps auditors prioritize areas with high-risk indicators.
Supports IIA Standard 2010 - Planning, which requires risk-based audit planning.
A). Internal auditors perform reconciliation procedures to support an external audit of financial reporting.
(Incorrect)
Reconciliation is a procedural task, not an exploratory data mining activity.
Supports external audit rather than internal audit's strategic risk assessment role.
B). Internal auditors perform a systems-focused analysis to review relevant controls. (Incorrect) This relates more to evaluating control effectiveness rather than exploratory data mining.
Does not directly contribute to identifying new audit areas.
D). Internal auditors test IT general controls with regard to operating effectiveness versus design. (Incorrect) Testing IT general controls is a structured evaluation, not an exploratory data mining technique.
Exploratory data mining is used to identify risks before formal testing occurs.
Explanation of Answer Choice C (Correct Answer):Explanation of Incorrect Answers:Conclusion:The best example of exploratory data mining by internal auditors is risk assessment for audit planning (Option C).
IIA References:
IIA Standard 2010 - Planning
IIA Practice Guide: Data Analytics
IIA-CIA-Part3 Exam Question 224
How can the concept of relevant cost help management with behavioral analyses?
Correct Answer: D
Relevant cost refers to costs that will change depending on a specific business decision. It is crucial for decision-making as it helps management assess the financial impact of alternatives.
Relevant costs focus on future costs that differ between decision alternatives.
They help management analyze how different choices impact profitability.
This supports decision-making in areas such as pricing, outsourcing, and product discontinuation.
A). It explains the assumption that both costs and revenues are linear through the relevant range # Incorrect.
While linear cost behavior is often assumed, it is not the primary purpose of relevant cost analysis.
B). It enables management to calculate a minimum number of units to produce and sell without having to incur a loss # Incorrect. This describes break-even analysis, not relevant cost analysis.
C). It enables management to predict how costs such as the depreciation of equipment will be affected by a change in business decisions # Incorrect. Depreciation is a sunk cost and is not considered relevant for decision-making.
The IIA's Practice Guide: Financial Decision-Making and Internal Audit's Role outlines how relevant cost analysis aids business strategy.
International Professional Practices Framework (IPPF) Standard 2120 states that internal auditors should assess management's cost-analysis techniques.
Managerial Accounting Concepts (by IMA and COSO) emphasize relevant costs in strategic decision-making.
Why Option D is Correct?Explanation of the Other Options:IIA References & Best Practices:Thus, the correct answer is D. It enables management to make business decisions, as it explains the cost that will be incurred for a given course of action.
Relevant costs focus on future costs that differ between decision alternatives.
They help management analyze how different choices impact profitability.
This supports decision-making in areas such as pricing, outsourcing, and product discontinuation.
A). It explains the assumption that both costs and revenues are linear through the relevant range # Incorrect.
While linear cost behavior is often assumed, it is not the primary purpose of relevant cost analysis.
B). It enables management to calculate a minimum number of units to produce and sell without having to incur a loss # Incorrect. This describes break-even analysis, not relevant cost analysis.
C). It enables management to predict how costs such as the depreciation of equipment will be affected by a change in business decisions # Incorrect. Depreciation is a sunk cost and is not considered relevant for decision-making.
The IIA's Practice Guide: Financial Decision-Making and Internal Audit's Role outlines how relevant cost analysis aids business strategy.
International Professional Practices Framework (IPPF) Standard 2120 states that internal auditors should assess management's cost-analysis techniques.
Managerial Accounting Concepts (by IMA and COSO) emphasize relevant costs in strategic decision-making.
Why Option D is Correct?Explanation of the Other Options:IIA References & Best Practices:Thus, the correct answer is D. It enables management to make business decisions, as it explains the cost that will be incurred for a given course of action.
IIA-CIA-Part3 Exam Question 225
Which of the following should internal auditors be attentive of when reviewing personal data consent and opt- in/opt-out management process?
Correct Answer: B
When reviewing personal data consent and opt-in/opt-out management processes, internal auditors should focus on ensuring compliance with data protection regulations, such as the General Data Protection Regulation (GDPR) and other applicable data privacy laws. The most critical aspect is ensuring that personal data is processed strictly in line with the consent obtained from individuals.
Data Processing in Accordance with Consent (Correct Choice: B)
IIA Standard 2110 - Governance requires internal auditors to assess whether the organization has effective processes for ensuring compliance with laws and regulations, including data privacy obligations.
GDPR Article 5(1)(b) (Purpose Limitation Principle) mandates that personal data must be collected for specified, explicit, and legitimate purposes and must not be further processed in a manner incompatible with those purposes.
Internal auditors should verify that the organization adheres to this principle by ensuring that data is only used for the purpose for which consent was granted.
Why the Other Options Are Incorrect:
Option A: " Whether customers are asked to renew their consent for their data processing at least quarterly. " (Incorrect) GDPR does not mandate a quarterly renewal of consent. Instead, it requires that consent be freely given, specific, informed, and unambiguous. Periodic renewal may be advisable in some cases, but it is not a strict regulatory requirement.
IIA Standard 2120 - Risk Management requires auditors to evaluate compliance risk exposure, but excessive consent renewals could lead to inefficiencies without adding value.
Option C: " Whether the organization has established explicit and entitywide policies on data transfer to third parties. " (Incorrect) While data transfer policies are critical (as required under GDPR Articles 44-50 on international data transfers), they do not directly relate to the opt-in/opt-out process or consent management.
IIA Standard 2201 - Engagement Planning encourages reviewing policies, but the key focus should be on processing data according to the purpose of consent.
Option D: " Whether customers have an opportunity to opt-out the right to be forgotten from organizational records and systems. " (Incorrect) The right to be forgotten (GDPR Article 17) allows individuals to request data deletion, but it is not an opt-out feature in the traditional sense. Organizations must evaluate each request based on legal grounds before erasing data.
IIA Standard 2130 - Compliance requires verifying whether the organization ensures compliance with data privacy rights, but an opt-out for the right to be forgotten is not a primary audit focus.
IIA Standard 2110 - Governance (Ensuring regulatory compliance)
IIA Standard 2120 - Risk Management (Managing data privacy risks)
IIA Standard 2130 - Compliance (Reviewing legal obligations on personal data) IIA Standard 2201 - Engagement Planning (Evaluating policies and controls) GDPR Article 5(1)(b) - Purpose Limitation Principle (Processing data as per consent) GDPR Articles 17, 44-50 (Data protection and right to be forgotten considerations) Step-by-Step Justification for the Answer:IIA References for This Answer:Thus, Option B is the correct choice as it aligns with the purpose limitation principle and internal audit's role in assessing compliance with data protection laws.
Data Processing in Accordance with Consent (Correct Choice: B)
IIA Standard 2110 - Governance requires internal auditors to assess whether the organization has effective processes for ensuring compliance with laws and regulations, including data privacy obligations.
GDPR Article 5(1)(b) (Purpose Limitation Principle) mandates that personal data must be collected for specified, explicit, and legitimate purposes and must not be further processed in a manner incompatible with those purposes.
Internal auditors should verify that the organization adheres to this principle by ensuring that data is only used for the purpose for which consent was granted.
Why the Other Options Are Incorrect:
Option A: " Whether customers are asked to renew their consent for their data processing at least quarterly. " (Incorrect) GDPR does not mandate a quarterly renewal of consent. Instead, it requires that consent be freely given, specific, informed, and unambiguous. Periodic renewal may be advisable in some cases, but it is not a strict regulatory requirement.
IIA Standard 2120 - Risk Management requires auditors to evaluate compliance risk exposure, but excessive consent renewals could lead to inefficiencies without adding value.
Option C: " Whether the organization has established explicit and entitywide policies on data transfer to third parties. " (Incorrect) While data transfer policies are critical (as required under GDPR Articles 44-50 on international data transfers), they do not directly relate to the opt-in/opt-out process or consent management.
IIA Standard 2201 - Engagement Planning encourages reviewing policies, but the key focus should be on processing data according to the purpose of consent.
Option D: " Whether customers have an opportunity to opt-out the right to be forgotten from organizational records and systems. " (Incorrect) The right to be forgotten (GDPR Article 17) allows individuals to request data deletion, but it is not an opt-out feature in the traditional sense. Organizations must evaluate each request based on legal grounds before erasing data.
IIA Standard 2130 - Compliance requires verifying whether the organization ensures compliance with data privacy rights, but an opt-out for the right to be forgotten is not a primary audit focus.
IIA Standard 2110 - Governance (Ensuring regulatory compliance)
IIA Standard 2120 - Risk Management (Managing data privacy risks)
IIA Standard 2130 - Compliance (Reviewing legal obligations on personal data) IIA Standard 2201 - Engagement Planning (Evaluating policies and controls) GDPR Article 5(1)(b) - Purpose Limitation Principle (Processing data as per consent) GDPR Articles 17, 44-50 (Data protection and right to be forgotten considerations) Step-by-Step Justification for the Answer:IIA References for This Answer:Thus, Option B is the correct choice as it aligns with the purpose limitation principle and internal audit's role in assessing compliance with data protection laws.
- Other Version
- 1489IIA.IIA-CIA-Part3.v2026-06-17.q220
- 1557IIA.IIA-CIA-Part3.v2026-02-23.q167
- 9707IIA.IIA-CIA-Part3.v2025-03-17.q270
- 6421IIA.IIA-CIA-Part3.v2022-09-07.q162
- 66IIA.Examsreviews.IIA-CIA-Part3.v2022-05-25.by.lucy.248q.pdf
- 9574IIA.IIA-CIA-Part3.v2022-03-09.q248
- 9918IIA.IIA-CIA-Part3.v2021-09-30.q250
- 100IIA.Prepawayete.IIA-CIA-Part3.v2021-08-09.by.levi.152q.pdf
- Latest Upload
- 156Cohesity.COH-285.v2026-08-22.q118
- 134Microsoft.AB-900.v2026-08-22.q35
- 252IIA.IIA-CIA-Part3.v2026-08-22.q367
- 163CheckPoint.156-315.82.v2026-08-22.q62
- 161Microsoft.GH-300.v2026-08-21.q53
- 164GIAC.GOSI.v2026-08-21.q46
- 499PMI.PMP-CN.v2026-08-21.q921
- 199Salesforce.Data-Architect.v2026-08-20.q121
- 182API.API-1184.v2026-08-20.q59
- 188Salesforce.OmniStudio-Developer.v2026-08-20.q83
[×]
Download PDF File
Enter your email address to download IIA.IIA-CIA-Part3.v2026-08-22.q367 Practice Test
