Updated Jun 25, 2026 Certification Exam IIA-CIA-Part3 Dumps - Practice Test Questions
Updated Verified IIA-CIA-Part3 dumps Q&As - Pass Guarantee or Full Refund
NEW QUESTION # 256
Which of the following best describes the purpose of fixed manufacturing costs?
- A. To incur stable costs despite operating capacity.
- B. To ensure availability of production facilities.
- C. To decrease direct expenses related to production.
- D. To increase the total unit cost under absorption costing
Answer: B
Explanation:
Fixed manufacturing costs refer to costs that do not vary with the level of production activity within a relevant range. These costs include expenses such as depreciation, rent, property taxes, and salaries of permanent employees in the production facility. Their primary purpose is to ensure the availability and operational readiness of production facilities, regardless of fluctuations in production levels.
* (A) Correct - To ensure availability of production facilitiesFixed manufacturing costs are incurred to maintain and operate production facilities, ensuring that they remain functional and available for production when needed. These costs exist even if no units are produced, emphasizing their role in sustaining the production infrastructure.
* (B) Incorrect - To decrease direct expenses related to productionFixed manufacturing costs are unrelated to direct expenses, such as raw materials and labor, which vary with production volume.
Instead, they remain constant regardless of output levels.
* (C) Incorrect - To incur stable costs despite operating capacityWhile fixed costs remain stable within a relevant range, their primary purpose is not just cost stability but ensuring production facilities' availability and functionality.
* (D) Incorrect - To increase the total unit cost under absorption costingUnder absorption costing, fixed manufacturing costs are allocated to units produced, affecting per-unit cost calculations. However, this is an accounting treatment rather than the core purpose of fixed manufacturing costs.
* IIA's Global Internal Audit Standards - Managing Resources Effectively
* Fixed manufacturing costs ensure operational resources are available and managed efficiently.
* IIA's Guide on Cost Management and Internal Control
* Highlights the role of cost structures, including fixed costs, in ensuring business continuity.
* IIA's Practice Advisory on Cost Accounting Controls
* Discusses the importance of maintaining production facilities to ensure operational readiness.
Breakdown of Answer Choices:IIA References and Internal Auditing Standards:Would you like further clarification on any point?
NEW QUESTION # 257
When writing a business memorandum, the writer should choose a writing style that achieves all of the following except:
- A. Develops ideas without overstatement.
- B. Suits the method of presentation and delivery.
- C. Draws positive attention to the writing style.
- D. Treats all receivers with respect.
Answer: C
NEW QUESTION # 258
An employee was promoted within the organization and relocated to a new office in a different building. A few months later, security personnel discovered that the employee's smart card was being used to access the building where she previously worked. Which of the following security controls could prevent such an incident from occurring?
- A. Two-level authentication.
- B. Photos on smart cards.
- C. Restriction of access hours.
- D. Regular review of logs.
Answer: B
NEW QUESTION # 259
An entity has 100.000 outstanding ordinary shares with a market value of US $20 per share. Dividends of US $2 per share were paid in the current year, and the entity has a dividend-payout ratio of 40%. The price-to-earnings ratio of the entity is:
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
Explanation:
The P-E ratio equals the share price divided by EPS. If the dividends per share equaled US $2 and the dividend-payout ratio was 40%, EPS must have been US $5 $2 - .4). Accordingly, the P-E ratio is 4 US $20 share price - $5 EPS). Entity A has 50,000 ordinary shares and 10,000 preference shares outstanding at the start of the year on January 1. The preference shares are entitled to a US $2 per share annual cash dividend, payable on December 31. The entity had profit of US $1517,000 for the year. On April 1, the entity issued 15,000 additional ordinary shares for cash. Entity B. is identical to entity A in all respects except that it had 75.000 ordinary shares outstanding for the entire year.
NEW QUESTION # 260
In Year 2, the entity had cash provided by operations of:
- A. US $219,000
- B. US $469,000
- C. US $344,000
- D. US $244,000
Answer: A
Explanation:
Cash provided by operations equals profit, plus depreciation, minus the increase in accounts receivable, minus the decrease in accounts payable. The cash provided is US $219,000 [$294,000 + $50,000 -$300,000 - $200,000) -$275,000 - $250,000)]. An increase in receivables is a noncash component of profit. A decrease in accounts payable is added when adjusting cost of goods sold to reflect cash paid to suppliers. Thus, it is subtracted when adjusting profit to arrive at cash provided by operations. An entity has the following statements:
NEW QUESTION # 261
Which of the following describes the most appropriate set of tests for auditing a workstation's logical access controls?
- A. Review the list of people with access badges to the room containing the workstation and a log of those who accessed the room
- B. Review the password length, frequency of change, and list of users for the workstation's login process
- C. Review the list of people who attempted to access the workstation and failed, as well as error messages
- D. Review the passwords of those who attempted unsuccessfully to access the workstation and the log of their activity
Answer: B
Explanation:
Reference: IIA Business Knowledge for Internal Auditing, Logical Access Controls section.
NEW QUESTION # 262
Company R produces and sells two products. Product A costs US$10 per unit and Product B costs US $5 per unit. Product A is selling very well, but sales of Product B are low. In order to increase sales of Product B, Company R has begun setting a price of US $13 for one of each. What is the pricing method?
- A. Product-bundle pricing.
- B. Value pricing.
- C. Collusive pricing.
- D. By-product pricing.
Answer: A
Explanation:
Product-bundle pricing entails selling combinations of products at a price lower than the combined prices of the individual items. This strategy promotes sales of items consumers might not otherwise buy.
NEW QUESTION # 263
A major disadvantage of the life cycle approach to system development is that it is not well-suited for projects that are:
- A. Unstructured.
- B. Large.
- C. Complex.
- D. Structured.
Answer: A
Explanation:
The life cycle approach is best employed when systems are large and highly structured, users understand the tasks to be performed by the information system, and the developers have directly applicable experience in designing similar systems. In the life cycle process. each stage of development is highly structured, and requirements are clearly defined. However, when the task is unstructured, prototyping may be the better approach.
NEW QUESTION # 264
COBIT is:
- A. A set of guidelines to assist in implementing adequate controls over IT processes.
- B. Published by the Committee of Sponsoring Organizations.
- C. A set of risks and responses to technology challenges.
- D. The update of the previous Systems Auditability and Control reports.
Answer: A
Explanation:
COBIT Control Objectives for Information and related Technology) is an IT control framework copyrighted by the IT Governance Institute ITG1). COBIT is a set of guidelines to assist management and business process owners in implementing adequate controls over IT processes and resources. It is designed to be an IT governance tool that facilitates understanding and managing the risks and benefits associated with information and related IT.
NEW QUESTION # 265
Which of the following is required in effective IT change management?
- A. All changes to systems must be approved by the highest level of authority within an organization.
- B. Change management follows a consistent process and is done in a controlled environment.
- C. The sole responsibility for change management is assigned to an experienced and competent IT team
- D. Internal audit participates in the implementation of change management throughout the organisation.
Answer: B
Explanation:
* Effective IT Change Management Principles:
* Change management ensures that modifications to IT systems are controlled, tested, and implemented in a way that reduces risks.
* A structured and consistent process is required to prevent disruptions, maintain system integrity, and comply with governance requirements.
* IIA Standard 2110 - Governance:
* IT governance must include structured change management processes.
* Change management should be repeatable and standardized to ensure effectiveness.
* IIA GTAG (Global Technology Audit Guide) on Change Management:
* Change management must be conducted in a controlled environment to minimize unintended consequences and security risks.
* A. The sole responsibility for change management is assigned to an experienced and competent IT team. (Incorrect)
* While IT plays a key role, change management should involve multiple stakeholders, including business units, security, compliance, and risk management teams.
* IIA Standard 2120 - Risk Management states that risk oversight should not be assigned to a single function.
* C. Internal audit participates in the implementation of change management throughout the organization. (Incorrect)
* Internal audit evaluates change management but does not implement it.
* IIA Standard 1000 - Purpose, Authority, and Responsibility emphasizes that internal audit provides independent assurance rather than operational involvement.
* D. All changes to systems must be approved by the highest level of authority within an organization. (Incorrect)
* Approvals should be based on a risk-based hierarchy rather than requiring executive-level approval for all changes.
* IIA GTAG - Change Management recommends a tiered approval system based on change complexity and risk impact.
Explanation of Incorrect Answers:Conclusion:The most critical factor in effective IT change management is having a consistent, controlled process (Option B).
IIA References:
* IIA Standard 2110 - Governance
* IIA Standard 2120 - Risk Management
* IIA Standard 1000 - Purpose, Authority, and Responsibility
* IIA GTAG - Change Management
NEW QUESTION # 266
An organization has instituted a bring-your-own-device (BYOD) work environment. Which of the following policies best addresses the increased risk to the organization's network incurred by this environment?
- A. Use management software scan and then prompt parch reminders when devices connect to the network
- B. Institute detection and authentication controls for all devices used for network connectivity and data storage.
- C. Limit the use of the employee devices for personal use to mitigate the risk of exposure to organizational data.
- D. Ensure that relevant access to key applications is strictly controlled through an approval and review process.
Answer: B
Explanation:
* Understanding BYOD Risks:
* A Bring-Your-Own-Device (BYOD) policy allows employees to use personal devices (e.g., laptops, smartphones, tablets) for work.
* This increases security risks such as unauthorized access, malware infections, data leakage, and non-compliance with IT security policies.
* Why Option C (Detection and Authentication Controls) Is Correct?
* Detection and authentication controls ensure that:
* Only authorized devices can connect to the organization's network.
* User authentication mechanisms (such as multi-factor authentication) verify identities before granting access.
* Devices with security vulnerabilities are flagged and restricted.
* This aligns with IIA Standard 2110 - Governance, which emphasizes IT security controls for risk mitigation.
* ISO 27001 and NIST Cybersecurity Framework also recommend device authentication and monitoring for secure network access.
* Why Other Options Are Incorrect?
* Option A (Limit personal use of employee devices):
* Limiting personal use does not fully address network security risks; malware can still infect devices.
* Option B (Control access through approvals and reviews):
* While access control is important, it does not mitigate the broader risks of compromised devices connecting to the network.
* Option D (Software scans and patch reminders):
* Patching is important, but it does not prevent unauthorized access or ensure authentication for devices.
* Implementing device detection and authentication controls is the most effective way to mitigate security risks in a BYOD environment.
* IIA Standard 2110 and ISO 27001 emphasize strong network security measures.
Final Justification:IIA References:
* IPPF Standard 2110 - Governance (IT Risk Management & BYOD Security)
* ISO 27001 - Information Security Management
* NIST Cybersecurity Framework - Access Control & Authentication
NEW QUESTION # 267
An organization has an agreement with a third-party vendor to have a fully operational facility, duplicate of the original site and configured to the organization's needs, in order to quickly recover operational capability in the event of a disaster, Which of the following best describes this approach to disaster recovery planning?
- A. Cold recovery plan,
- B. Storage area network recovery plan.
- C. Outsourced recovery plan.
- D. Hot recovery plan
Answer: B
NEW QUESTION # 268
In which of the following plans is an employee most likely to find guidance on action and performance standards?
- A. Tactical plans.
- B. Mission plans.
- C. Operational plans.
- D. Strategic plans.
Answer: C
NEW QUESTION # 269
Which of following best demonstrates the application of the cost principle?
- A. A building purchased last year for 1 million is currently worth £1,2 million , and the company adjusts the records to reflect the current value
- B. A company reports assets at either historical or fair value, depending which is closer to market value.
- C. A building purchased last year for $1 million is currently worth 1.2 million, but the company still reports the building at $1 million.
- D. A company reports trading and investment securities at their market cost
Answer: C
Explanation:
The cost principle (historical cost principle) states that assets should be recorded at their original purchase price, regardless of changes in market value.
Correct Answer (B - A Building Purchased Last Year for $1 Million Is Still Reported at $1 Million, Despite an Increase in Value) Under the cost principle, assets remain recorded at their historical cost, not adjusted for market fluctuations.
The only exception is for certain financial instruments, such as trading securities, which are reported at fair market value.
The IIA Practice Guide: Auditing Financial Reporting and Accounting Estimates states that fixed assets (such as buildings) should be recorded at cost unless an impairment occurs.
Why Other Options Are Incorrect:
Option A (Trading and Investment Securities Reported at Market Cost):
Securities can be reported at market value, but this does not follow the cost principle, which applies to tangible assets.
Option C (Adjusting the Building's Value to $1.2 Million):
Violates the cost principle-historical cost does not change due to market appreciation.
Option D (Reporting Assets at Either Historical or Fair Value):
This is not the cost principle; it describes fair value accounting, which is different.
IIA Practice Guide: Auditing Financial Reporting and Accounting Estimates - Defines the cost principle and asset valuation rules.
Generally Accepted Accounting Principles (GAAP) - Requires fixed assets to be recorded at historical cost.
Step-by-Step Explanation:IIA References for Validation:Thus, B is the correct answer because the cost principle requires assets to be recorded at their original purchase price, regardless of market value changes.
NEW QUESTION # 270
A company had US $30 million in total sales last year and expects US $40 million in total sales this year. Ten percent of each year's sales are on credit that will be paid the following year. The company anticipates the following expenses for this year:
Depreciation of US $5 million.
Labor, materials, taxes, and other expenses of US $51 million.
Assume the company begins this year with a zero cash balance. At the end of this year, the company will have a cash deficit of:
- A. US $17 million
- B. US $15 million
- C. US $8 million
- D. US $12 million
Answer: D
Explanation:
The cash inflows from last year's credit sales are estimated to be US $3,000,000$'',C1,0C10,0Ci0 _-: 10%). The cash inflows from this year's sales are expected to be US $36,000,000 x 90%), a total cash inflow of US $39,000,000 for the current year. Ignoring depreciation, which is a noncash expense, cash outflows are estimated at US $51,000.000_ Hence, the net cash outflow is anticipated to be US $12.000,000$39,000,000
-$51,000.000).
NEW QUESTION # 271
Which of the following physical access control is most likely to be based on ''something you have" concept?
- A. A P3M code reader
- B. A fingerprint scanner
- C. A card-key scanner
- D. A retina characteristics reader
Answer: C
Explanation:
Understanding the "Something You Have" Concept:
Access control methods are classified into three main authentication factors:
Something You Know - Passwords, PINs, security questions.
Something You Have - Physical devices like keycards, smart cards, or security tokens.
Something You Are - Biometrics such as fingerprints, retina scans, or voice recognition.
Why a Card-Key Scanner is the Correct Answer:
A card-key scanner verifies access using a physical card, which aligns with the "something you have" authentication factor.
Users must possess the key card to gain entry, making it a classic example of physical token-based security.
Why Other Options Are Incorrect:
A). A retina characteristics reader - Incorrect, as retina scans fall under "something you are" (biometrics), not
"something you have".
B). A PIN code reader - Incorrect, as PIN codes are "something you know", not a physical possession.
D). A fingerprint scanner - Incorrect, as fingerprints are biometric ("something you are"), not a physical object.
IIA's Perspective on Physical Security Controls:
IIA Standard 2110 - Governance emphasizes the importance of using multi-factor authentication to enhance security.
IIA GTAG (Global Technology Audit Guide) on Access Control recommends the use of physical security devices like card-key scanners to prevent unauthorized access.
ISO 27001 Information Security Standard identifies "something you have" authentication methods as critical components of access control.
IIA References:
IIA Standard 2110 - Governance & IT Security
IIA GTAG - Physical Security & Access Controls
ISO 27001 Information Security Standard - Multi-Factor Authentication
Thus, the correct and verified answer is C. A card-key scanner.
NEW QUESTION # 272
An organization's computer help-desk function is usually a responsibility of the:
- A. User departments.
- B. Computer operations unit.
- C. Applications development unit.
- D. Systems programming unit.
Answer: B
Explanation:
Help desks are usually a responsibility of computer operations because of the operational nature of their functions. A help desk logs reported problems, resolves minor problems, and forwards more difficult problems to the appropriate information systems resources, such as a technical support unit or vendor assistance.
NEW QUESTION # 273
In a final audit report, internal auditors drafted the following management action plan with a due date of the last day of the calendar year:
"Plan: A bank reconciliation template has been updated to address issues with formulas incorrectly calculating variances." Which critical element of the action plan is missing?
- A. A referral to the policy or procedure
- B. The responsible personnel
- C. The status of the action plan
- D. The level of risk
Answer: B
Explanation:
A management action plan should include: (1) corrective action, (2) responsible personnel, and (3) implementation timeline. In this case, while the corrective action and due date are included, the responsible personnel is missing, which is critical for accountability.
Option B (status) is tracked later during follow-up. Option C (policy reference) is not mandatory. Option D (risk level) belongs to the observation, not the action plan.
Reference:
IIA Practice Guide - Audit Findings and Recommendations.
NEW QUESTION # 274
......
Exam Engine for IIA-CIA-Part3 Exam Free Demo & 365 Day Updates: https://dumpstorrent.dumpsfree.com/IIA-CIA-Part3-valid-exam.html