Which statement is true regarding the development of a risk-based internal audit plan?
Correct Answer: B
A risk-based audit plan must be aligned with the organization's objectives and risk management system. According to the Standards, the CAE must consider the organization's risk management framework and assess key risks to develop the plan. A maturity review (Option A) is not a prerequisite, nor is a mandated percentage of strategic coverage (Option C). Option D is incorrect because an organization does not need to follow a specific external framework to develop a risk-based plan; internal risk identification suffices. Reference: IIA Standards - Standard 2010: Planning; Implementation Guide 2010.
IIA-CIA-Part3 Exam Question 337
Which of the following statements about assurance maps is true?
Correct Answer: A
An assurance map provides an overview of assurance activities across the organization and helps identify gaps (uncovered risks) and duplications (overlap of work). This enhances coordination among assurance providers and supports the board's governance oversight. Option B is incorrect because the board does not coordinate activities; internal audit facilitates assurance mapping. Option C misinterprets the tool-it does not assign specific audits. Option D refers to staff competencies, not assurance coverage. Reference: IIA Practice Guide - Coordination and Reliance: Developing an Assurance Map.
IIA-CIA-Part3 Exam Question 338
Which of the following is generally considered a best practice related to data backup? * Performing full system backups on weekdays. * Storing system backups onsite in a secured location. * Testing system backup media periodically. * Verifying backup media can be retrieved within seven years.
Correct Answer: B
Periodic testing of backup media is a recognized backup best practice because backups have value only if data can actually be restored when needed. Media may be corrupted, incomplete, unreadable, encrypted incorrectly, or incompatible with recovery systems. Performing full backups on weekdays is not universally a best practice; backup frequency and type should be based on recovery objectives and system criticality. Storing backups only onsite is weak because a local disaster may destroy both production systems and backups. Verifying retrieval within seven years is too arbitrary; retention should be based on legal, regulatory, operational, and recovery requirements. Internal auditors should review backup schedules, offsite storage, encryption, media integrity, restore testing, and retention. Therefore, Option B is correct.
IIA-CIA-Part3 Exam Question 339
An internal auditor reviews a data population and calculates the mean, median, and range. What is the most likely purpose of performing this analytic technique?
Correct Answer: C
When an internal auditor calculates the mean (average), median (middle value), and range (difference between highest and lowest values) of a data population, the primary purpose is to assess the distribution of data and detect anomalies. Let's analyze the answer choices: Option A: To inform the classification of the data population. Incorrect. Classification typically involves categorizing data into specific groups, which requires different statistical or analytical techniques like clustering or decision trees. Mean, median, and range are more useful for identifying distribution patterns. Option B: To determine the completeness and accuracy of the data. Incorrect. While summary statistics can highlight extreme values, completeness and accuracy are usually assessed through data reconciliation, validation checks, and comparison with source records. Option C: To identify whether the population contains outliers. Correct. The range (difference between the largest and smallest values) helps to detect extreme values. The mean and median can show whether the data is symmetrical or skewed (which may indicate outliers). If the mean is significantly different from the median, it suggests potential outliers pulling the average in one direction. IIA Reference: Internal auditors use data analytics to detect anomalies and potential fraud by identifying outliers. (IIA GTAG: Auditing with Data Analytics) Option D: To determine whether duplicates in the data inflate the range. Incorrect. Duplicates may affect the data set, but range calculations alone do not determine whether duplicates exist. Duplicate identification usually involves checking for repeated entries, not just extreme values.
IIA-CIA-Part3 Exam Question 340
According to IIA guidance, which of the following statements is true regarding the chief audit executive's (CAE's) responsibility for following up on management action plans?
Correct Answer: C
The CAE is responsible for monitoring progress selectively based on risk significance. Not every recommendation requires follow-up with the same intensity. Instead, the CAE should focus on high-risk issues and verify whether management has taken corrective actions. Option A is too rigid and does not reflect risk-based prioritization. Option B is incorrect because the purpose of follow-up is not to revalidate audit issues but to ensure corrective actions were implemented. Option D incorrectly reverses the escalation order (unresolved issues must go from management # senior management # board). Reference: IIA Standards - Standard 2500: Monitoring Progress.