Which of the following statements is true with regard to capital budgeting?
Correct Answer: D
The annual rate of return method estimates profitability by dividing expected annual net income by the average investment. It is an accounting-based capital budgeting technique and does not directly consider the time value of money. Option A is incorrect because a proposal is normally acceptable under net present value when NPV is positive, not negative. Option B incorrectly describes internal rate of return; IRR is the discount rate at which the present value of cash inflows equals the present value of cash outflows. Option C is incorrect because the payback method measures how long it takes to recover the original investment, not the investment plus expected return. Internal auditors should understand capital budgeting methods when reviewing investment decisions. Therefore, Option D is correct.
IIA-CIA-Part3 Exam Question 347
Based on test results, an IT auditor concluded that the organization would suffer unacceptable loss of data if there was a disaster at its data center. Which of the following test results would likely lead the auditor to this conclusion?
Correct Answer: D
Reference: IIA Business Knowledge for Internal Auditing, IT Risk and Controls section, Disaster Recovery and Business Continuity principles.
IIA-CIA-Part3 Exam Question 348
The audit committee has asked the internal audit activity to integrate data analytics into all work programs going forward. To accomplish this, which of the following describes the first step an audit team should take when planning for an audit?
Correct Answer: C
The first step in audit data analytics is to identify the business question or audit objective, the data required, and the expected result. Analytics should be driven by a risk, control, or business need, not by collecting data first and searching for something interesting. Once the audit question is defined, the auditor can determine data sources, fields, extraction scope, cleansing requirements, tests, and interpretation criteria. Training and resources are important, but they are capability enablers, not the first planning step for a specific audit. Obtaining as much data as possible is inefficient and may create privacy or relevance issues. Management approval is not the starting point for audit analytics. Therefore, Option C is correct.
IIA-CIA-Part3 Exam Question 349
Which of the following Issues would be a major concern for internal auditors when using a free software to analyze a third-party vendor's big data?
Correct Answer: C
Comprehensive and Detailed Step-by-Step Explanation with all IIA References: Understanding the Concern: Internal auditors must assess risks when using free software for data analysis, particularly regarding data security, confidentiality, and integrity. When analyzing third-party vendor data, the primary risk is data compromise, unauthorized access, or data loss due to inadequate security controls in free software. Why Data Security is the Biggest Concern: Free software often lacks robust security measures, making sensitive vendor data susceptible to breaches, cyberattacks, or loss. Ensuring compliance with data protection regulations (e.g., GDPR, CCPA) and contractual obligations with third-party vendors is critical. Why Other Options Are Incorrect: A). The ability to use the software with ease # While usability is important, security risks outweigh ease of use in an internal audit context. B). The ability to purchase upgraded features # Upgrades may improve analysis capabilities but do not address security concerns. D). The ability to download the software # Installing software is a technical issue, not a major audit concern compared to security. IIA Standards and References: IIA Standard 2110 - Governance: Internal auditors should ensure data security risks are addressed in technology use. IIA Standard 2120 - Risk Management: Auditors must evaluate the organization's ability to safeguard data. IIA GTAG (Global Technology Audit Guide) on Data Analytics (2017): Recommends ensuring security of third-party data when using analytical tools. Thus, the correct answer is C: The ability to ensure that big data entered into the software is secure from potential compromises or loss.
IIA-CIA-Part3 Exam Question 350
Which of the following purchasing scenarios would gain the greatest benefit from implementing electronic data interchange?
Correct Answer: A
Electronic data interchange provides the greatest benefit in a time-sensitive just-in-time purchasing environment because JIT depends on fast, accurate, and reliable communication between buyers and suppliers. EDI reduces manual processing, data entry errors, purchase order delays, invoice delays, and confirmation problems. Custom purchases may require negotiation or special specifications that reduce EDI standardization benefits. Variable volumes sensitive to material cost require procurement analysis but do not necessarily benefit most from EDI. An inefficient purchasing process may benefit from process redesign first; automating a poor process can simply accelerate errors. Internal audit should evaluate EDI controls over authorization, completeness, transmission security, acknowledgments, and vendor master data. Therefore, Option A is correct.