IIA IIA-CIA-Part2 Practice Test - Questions Answers, Page 4

List of questions
Question 31

New environmental regulations require the board to certify that the organization's reported pollutant emissions data is accurate. The chief audit executive (CAE) is planning an audit to provide assurance over the organization's compliance with the environmental regulations. Which of the following groups or individuals is most important for the CAE to consult to determine the scope of the audit?
The most important group or individual for the CAE to consult to determine the scope of the audit regarding compliance with new environmental regulations is the environmental, health, and safety manager. This individual or group has specialized knowledge about the organization's operations, regulatory requirements, and existing controls related to environmental compliance. Consulting with the environmental, health, and safety manager ensures that the audit scope is comprehensive and accurately addresses the pertinent risks and compliance requirements.
Reference: IIA Standard 2201 -- Planning Considerations, IIA Practice Advisory 2210.A1-1
Question 32

The board has asked the internal audit activity (IAA) to be involved in the organization's enterprise risk management process. Which of the following activities is appropriate for IAA to perform without safeguards?
According to IIA guidance, the internal audit activity (IAA) can evaluate risk management processes without the need for safeguards. This activity aligns with the internal auditors' role in providing assurance on the effectiveness of the risk management process. Coaching management (Option A) and developing risk management strategies (Option B) involve direct participation in management functions, which could impair objectivity and require safeguards. Facilitating the identification and evaluation of risks (Option C) might also involve a degree of management participation that could compromise independence without proper safeguards.
Reference: IIA Standard 2120 -- Risk Management, IIA Practice Guide -- Assessing the Adequacy of Risk Management Processes
Question 33

According to IIA guidance, which of the following statements are true regarding the internal audit plan?
1. The audit plan is based on an assessment of risks to the organization.
2. The audit plan is designed to determine the effectiveness of the organization's risk management process.
3. The audit plan is developed by senior management of the organization.
4. The audit plan is aligned with the organization's goals.
According to IIA guidance, the internal audit plan should be based on an assessment of risks to the organization (1), designed to determine the effectiveness of the organization's risk management process (2), and aligned with the organization's goals (4). The development of the audit plan is typically the responsibility of the chief audit executive, often with input from senior management and the audit committee, rather than being solely developed by senior management (3).
Reference: IIA Standard 2010 -- Planning, IIA Practice Guide -- Developing the Internal Audit Plan
Question 34

An internal auditor is assessing the organization's risk management framework. Which of the following formulas should he use to calculate the residual risk?
The appropriate formula to calculate residual risk is (Probability of events) (Impacts). Residual risk is the risk that remains after controls are implemented to mitigate the inherent risk. It reflects the remaining exposure after considering the effectiveness of existing controls. This formula takes into account the likelihood of an event occurring and the potential impact if it does occur.
Reference: IIA Practice Guide -- Assessing the Adequacy of Risk Management Processes, COSO Framework
Question 35

Which of the following statements is false regarding roles and responsibilities pertaining to risk management and control?
The statement that 'Senior management is charged with overseeing the establishment risk management and control processes' is false. Senior management is typically responsible for establishing risk management and control processes, not just overseeing them. The board or its committees usually have the oversight role.
Question 36

Which of the following should be included in a privacy audit engagement?
1. Assess the appropriateness of the information gathered.
2. Review the methods used to collect information.
3. Consider whether the information collected is in compliance with applicable laws.
4. Determine how the information is stored.
A privacy audit engagement should comprehensively cover all aspects related to the collection, storage, and compliance of personal information. This includes assessing the appropriateness of the information gathered (1), reviewing the methods used to collect the information (2), ensuring the information collected complies with applicable laws (3), and determining how the information is stored (4). This comprehensive approach ensures that the organization adheres to privacy standards and regulations effectively.
Reference: = IIA's Practice Guide: ''Privacy Impact Assessment'' and IIA Standard 2110.A2 -
Question 37

Due to price risk from the foreign currency purchase of aviation fuel, an airliner has purchased forward contracts to hedge against fluctuations in the exchange rate. When recalculating the exchange losses from individual purchases of jet fuel, which of the following details does the internal auditor need to validate?
1. The hedge documentation designating the hedge.
2. The spot exchange rate on the transaction date.
3. The terms of the forward contract.
4. The amount of fuel purchased.
When recalculating exchange losses from foreign currency purchases, the internal auditor needs to validate the spot exchange rate on the transaction date (2) and the terms of the forward contract (3). These details are crucial to accurately assess the financial impact and ensure that the hedge is effectively mitigating the exchange rate risk.
Reference: = IIA's Practice Guide: ''Auditing Derivatives'' and IIA Standard 1220 - Due Professional Care.
Question 38

Which of the following statements describes an engagement planning best practice?
Best practices for engagement planning involve setting objectives that align with the business objectives of the audit client. This ensures that the audit is relevant and provides valuable insights to the organization. Planning should also be systematic and documented, ensuring that specific testing procedures and expected outcomes are outlined and communicated.
Reference: = IIA Standard 2200 - Engagement Planning and IIA Practice Guide: ''Planning the Engagement''.
Question 39

Which of the following is not a primary purpose for conducting a walk-through during the initial stages of an assurance engagement?
The primary purposes of a walk-through during the initial stages of an assurance engagement are to help develop process maps (A), determine segregation of duties (B), and identify residual risks (C). Testing the adequacy of controls (D) is generally performed after these initial steps to ensure a thorough understanding of the process and risks involved.
Reference: = IIA Standard 2201 - Planning Considerations and IIA Practice Guide: ''Walkthroughs for Internal Auditors''.
Question 40

After the team member who specialized in fraud investigations left the internal audit team, the chief audit executive decided to outsource fraud investigations to a third party service provider on an as needed basis. Which of the following is most likely to be a disadvantage of this outsourcing decision?
Outsourcing fraud investigations to a third-party service provider can result in a lack of familiarity with the organization's specific operations, culture, and history. This can be a disadvantage as external investigators may require more time to understand the context and nuances of the organization, potentially affecting the efficiency and effectiveness of the investigation.
Reference: = IIA Standard 1210 - Proficiency and IIA Practice Guide: ''Internal Audit and Fraud''.
Question