Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

CIA IIA-CIA-Part2 Syllabus Exam Questions Answers

Page: 15 / 56
Total 800 questions

Internal Audit Engagement Questions and Answers

Question 57

An IT auditor is reviewing the access controls in an organization ' s accounting application. The auditor intends to deploy a tool that can help test the logical controls embedded in the system to ensure employee access is granted according to need. Which of the following would help achieve this objective?

Options:

A.

Utility software

B.

Generalized audit software

C.

Audit expert systems.

D.

integrated test facility

Question 58

In the following risk control map risks have been categorized based on the level of significance and the associated level of control. Which of the following statements is true regarding Risk C?

Options:

A.

The level of control is appropriate given the level of risk

B.

The level of control is excessive given the level of risk

C.

The level of control is inadequate given the level of risk

D.

There is not enough of information to determine whether the controls are appropriate or not

Question 59

According to IIA guidance, which of the following is true regarding audit supervision?

1. Supervision should be performed throughout the planning, examination, evaluation, communication, and follow-up stages of the audit engagement.

2. Supervision should extend to training, time reporting, and expense control, as well as administrative matters.

3. Supervision should include review of engagement workpapers, with documented evidence of the review.

Options:

A.

1 and 2 only

B.

1 and 3 only

C.

2 and 3 only

D.

1, 2, and 3

Question 60

Which of the following is an appropriate responsibility for the internal audit activity with regard to the organization ' s risk management program?

Options:

A.

Identifying and managing risks in line with the entity ' s risk appetite.

B.

Ensuring that a proper and effective risk management process exists.

C.

Attaining an adequate understanding of the entity ' s key mitigation strategies.

D.

Identifying and ensuring that appropriate controls exist to mitigate risks.

Page: 15 / 56
Total 800 questions