Which of the following lists is comprised of computer hardware only?
Correct Answer: D
Comprehensive and Detailed In-Depth Explanation: Computer hardware refers to the physical components of a computer system. Workstation: A high-performance computer designed for technical or scientific applications. Modem: A device that modulates and demodulates signals for data transmission over communication lines. Disk drive: A device that reads and/or writes data to a disk storage medium. Option D lists only physical components, fitting the definition of computer hardware. In contrast: Value-added network (option A): A hosted service offering specialized networking services, not a physical component. Data warehouse (option B): A system used for reporting and data analysis, representing a data storage concept rather than a physical device. Firewall (option C): While it can be hardware, it is often implemented as software; thus, the term doesn't exclusively denote hardware. Therefore, option D accurately represents a list of computer hardware components. References: The Institute of Internal Auditors. (n.d.). CIA Exam Syllabus. Retrieved from [https://www.theiia.org/en /certifications/cia
IIA-CIA-Part3 Exam Question 357
A small furniture-manufacturing firm with 100 employees is located in a two-story building and does not plan to expand. The furniture manufactured is not special-ordered or custom-made. The most likely structure for this organization would be:
Correct Answer: A
A small organization producing standard products is most likely to use functional departmentalization. This structure groups employees by common functions such as production, sales, purchasing, accounting, and administration. It is efficient for smaller, stable organizations because it promotes specialization, clear reporting lines, and economies of expertise without unnecessary complexity. Product departmentalization is more likely when an organization has multiple distinct product lines requiring separate management. A matrix structure is more complex and is generally used where employees report across both functional and project or product lines. A divisional structure is normally used by larger organizations with multiple products, regions, or markets. Internal audit should understand organizational structure because it affects accountability, segregation of duties, communication, and control design. Therefore, Option A is correct.
IIA-CIA-Part3 Exam Question 358
An internal auditor conducts a data privacy audit engagement. Which of the following will most likely be treated as personal information?
Correct Answer: B
Internet protocol addresses are commonly treated as personal information because they can identify, locate, or be linked to an individual user, device, account, or household when combined with other data. In a privacy audit, internal auditors should treat IP addresses as sensitive because they may reveal browsing activity, access locations, system usage, and user behavior. Behavioral information and mobile device identifiers can also be sensitive in certain contexts, but the most broadly recognized answer is IP addresses. Device type alone is usually less specific and may not identify a person without other data. Internal auditors should evaluate whether personal information is classified, protected, retained properly, and processed according to privacy requirements. Therefore, Option B is correct.
IIA-CIA-Part3 Exam Question 359
Which of the following descriptions of the internal control system are indicators that risks are managed effectively? * Existing controls promote compliance with applicable laws and regulations. * The control environment is designed to address all identified risks to the organization. * Key controls for significant risks to the organization remain consistent over time. * Monitoring systems are in place to alert management to unexpected events.
Correct Answer: B
Effective risk management is indicated by controls that promote compliance with laws and regulations and by monitoring systems that alert management to unexpected events. These show that the organization has control activities and monitoring processes linked to risk exposure. Statement 2 is unrealistic because no control environment can address all identified risks completely; risk responses must be prioritized based on risk appetite and cost-benefit considerations. Statement 3 is not necessarily positive because key controls should change when risks, systems, regulations, or processes change. Internal audit should evaluate whether controls are risk-based, adaptive, monitored, and aligned with objectives. The most valid indicators listed are compliance-supporting controls and effective monitoring systems. Therefore, Option B is correct.
IIA-CIA-Part3 Exam Question 360
Which of the following items best describes the strategy of outsourcing?
Correct Answer: B
* Understanding Outsourcing: * Outsourcing refers to contracting business processes, functions, or expertise to an external service provider. * Companies use outsourcing to reduce costs, access specialized skills, and improve efficiency. * Why Option B (Contracting Functions or Knowledge-Related Work with an External Provider) Is Correct? * Outsourcing involves delegating specific business functions (e.g., IT support, payroll, customer service) to external specialists. * IIA Standard 2110 - Governance supports evaluating outsourcing risks and effectiveness. * ISO 37500 - Outsourcing Management Framework emphasizes knowledge-based work outsourcing for expertise gains. * Why Other Options Are Incorrect? * Option A (Foreign service providers for cost savings): * While some outsourcing involves foreign providers, outsourcing is not limited to offshoring. * Option C (Internal service provider): * Internal service providers do not involve outsourcing, as the work remains within the company. * Option D (External + internal provider collaboration): * This describes co-sourcing, not pure outsourcing. * Outsourcing involves contracting business functions to an external provider, making option B correct. * IIA Standard 2110 supports governance over outsourcing decisions and risk management. Final Justification:IIA References: * IPPF Standard 2110 - Governance (Outsourcing & Vendor Risk Management) * ISO 37500 - Outsourcing Management Framework * COSO ERM - Third-Party Risk Management in Outsourcing