IIA-CRMA-ADV Exam Question 116

Which of the following control activities is the most effective to ensure users' levels of access are appropriate for their current roles?
  • IIA-CRMA-ADV Exam Question 117

    An organization decides to take no action on one of its financial risks because the cost of implementing the control outweighs the value of the asset being protected. Which of the following best describes this risk strategy?
  • IIA-CRMA-ADV Exam Question 118

    Which of the following statements describes a control failure that is not directly attributable to a customer billing application?
    1. End users have raised a number of concerns regarding data integrity.
    2. An untested program change is transferred from the test environment to production.
    3. Purchase history does not reconcile with accounts receivable for some customers.
    4. End user security is inadvertently granted to an unauthorized individual by management.
  • IIA-CRMA-ADV Exam Question 119

    Click the Exhibit.

    Internal auditors are asked to keep track of how many hours per day they spend planning the audit, conducting the engagement, and writing the audit report. The data for two days has been collected as follows:
    Day 1
    Day 2
    Planning the audit
    2 hours
    3 hours
    Conducting the engagement
    1 hour
    1 hour
    Writing the audit report
    2 hours
    4 hours
    Which of the following graphs depicts the data accurately?
  • IIA-CRMA-ADV Exam Question 120

    The chief audit executive (CAE) is planning to conduct an internal assessment of the internal audit activity (IAA). Part of this assessment will include benchmarking. According to IIA guidance, which of the following qualitative metrics would be appropriate for the CAE to use?
    1. Average client customer satisfaction score for a given year.
    2. Client survey comments on how to improve the IAA.
    3. Auditor interviews once an audit has been completed.
    4. Percentage of audits completed within 90 days.