Summer Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

IIA IIA-CIA-Part3 Dumps

Internal Audit Function Questions and Answers

Question 1

Which of the following is a sound network configuration practice to enhance information security?

Options:

A.

Change management practices to ensure operating system patch documentation is retained.

B.

User role requirements are documented in accordance with appropriate application-level control needs.

C.

Validation of intrusion prevention controls is performed to ensure intended functionality and data integrity.

D.

Interfaces reinforce segregation of duties between operations administration and database development.

Question 2

Which of the following is on advantage of a decentralized organizational structure, as opposed to a centralized structure?

Options:

A.

Greater cost-effectiveness

B.

Increased economies of scale

C.

Larger talent pool

D.

Strong internal controls

Question 3

Which of the following would most likely serve as a foundation for individual operational goats?

Options:

A.

Individual skills and capabilities.

B.

Alignment with organizational strategy.

C.

Financial and human resources of the unit.

D.

Targets of key performance indicators

Question 4

Which of the following assumptions regarding cost-volume-profit analysis is true?

Options:

A.

Costs are affected by changes in activity only.

B.

The behavior of costs and revenues is inverse.

C.

When more than one type of product is sold, the sales mix changes.

D.

Only variable costs have to be classified accurately.

Question 5

An organization moving its sales conversion rate from 5% to 12% indicates which of the following?

Options:

A.

Worse sales activity.

B.

Better inventory usage.

C.

Better sales activity.

D.

Worse inventory usage.

Question 6

Management decides to accept the risk on a significant audit observation related to the organization ' s exposure to fraud risk. The chief audit executive considers the finding to have a high residual risk. Which of the following steps should be performed last?

Options:

A.

Gather risk appetite data

B.

Inform the internal legal counsel

C.

Inform the board

D.

Consult with the organization ' s regulators

Question 7

Which of the following statements is accurate when planning for an external quality assurance assessment of the internal audit function?

Options:

A.

The external assessment would include the audit function’s compliance with laws and regulations

B.

The selected qualified assessor can be from the organization’s shared services team

C.

The external assessment team members must work for an accounting firm

D.

The frequency of the performance of assessments should be considered by the assessor

Question 8

Which of the following performance measures would be appropriate for evaluating an investment center, which has responsibility for its revenues, costs, and investment base, but would not be appropriate for evaluating cost, revenue, or profit centers?

Options:

A.

A flexible budget.

B.

Variance analysis.

C.

A contribution margin income statement by segment.

D.

Residual income.

Question 9

Which of the following best describes a detective control designed to protect an organization from cyberthreats and attacks?

Options:

A.

A list of trustworthy, good traffic and a list of unauthorized, blocked traffic.

B.

Monitoring for vulnerabilities based on industry intelligence.

C.

Comprehensive service level agreements with vendors.

D.

Firewall and other network perimeter protection tools.

Question 10

Which of the following describes the most appropriate set of tests for auditing a workstation’s logical access controls?

Options:

A.

Review the list of people with access badges to the room containing the workstation and a log of those who accessed the room

B.

Review the password length, frequency of change, and list of users for the workstation’s login process

C.

Review the list of people who attempted to access the workstation and failed, as well as error messages

D.

Review the passwords of those who attempted unsuccessfully to access the workstation and the log of their activity

Question 11

What impact is there to liabilities on the balance sheet when ending inventory is overstated?

Options:

A.

There is no effect on liabilities.

B.

Liabilities are overstated.

C.

Liabilities are understated.

D.

Inventory errors affect income statement only.

Question 12

During an internal audit engagement, numerous deficiencies in the organization ' s management of customer data were discovered, entailing the risk of breaching personal data protection legislation. An improvement plan was approved by senior management. Which of the following conditions observed during the periodic follow-up process best justifies the chief audit executive ' s decision to escalate the issue to the board?

Options:

A.

The organization ' s customer satisfaction index does not show any signs of improvement

B.

No budget or resources have been allocated to implement corrective measures

C.

The board has not been informed about the planned improvements approved by senior management

D.

Employees responsible for improvements are resisting any additional workload

Question 13

Which of the following is the starting point for a chief audit executive to prioritize engagements to be included in the internal audit plan?

Options:

A.

A risk management maturity model

B.

A risk matrix

C.

An annual assurance map

D.

An internal control framework

Question 14

Which of the following represents a basis for consolidation under the International Financial Reporting Standards?

Options:

A.

Variable entity approach.

B.

Control ownership.

C.

Risk and reward.

D.

Voting interest.

Question 15

A technology developer has entered a two-year contract with another organization to design new software. According to IIA guidance, which of the following provisions of this agreement would be the most effective to protect the developer ' s product knowledge and expertise?

Options:

A.

The right to audit.

B.

A performance measurement system.

C.

Defined roles and responsibilities.

D.

Intellectual property rights.

Question 16

Which of the following types of date analytics would be used by a hospital to determine which patients are likely to require remittance for additional treatment?

Options:

A.

Predictive analytics.

B.

Prescriptive analytics.

C.

Descriptive analytics.

D.

Diagnostic analytics.

Question 17

A motivational technique generally used to overcome monotony and job-related boredom is:

Options:

A.

Job specification.

B.

Job objectives.

C.

Job rotation.

D.

Job description.

Question 18

Which of the following accurately describes the proper order of steps for an internal auditor to use when analyzing data?

Options:

A.

Obtain the data, clean and normalize the data, define the question, analyze the data.

B.

Define the question, obtain the data, analyze the data, clean and normalize the data.

C.

Define the question, obtain the data, clean and normalize the data, analyze the data.

D.

Obtain the data, analyze the data, clean and normalize the data, define the question.

Question 19

An organization has a declining inventory turnover but an Increasing gross margin rate, Which of the following statements can best explain this situation?

Options:

A.

The organization ' s operating expenses are increasing.

B.

The organization has adopted just-in-time inventory.

C.

The organization is experiencing Inventory theft

D.

The organization ' s inventory is overstated.

Question 20

According to Herzberg’s Two-Factor Theory of Motivation, which of the following factors are mentioned most often by satisfied employees?

Options:

A.

Salary and status.

B.

Responsibility and advancement.

C.

Work conditions and security.

D.

Peer relationships and personal life.

Question 21

Which of the following controls helps protect externally stored sensitive or confidential data from cyberthreats?

Options:

A.

Secure configurations and access controls.

B.

Strong vendor contracts with control reports provided by service organizations.

C.

Active and frequent monitoring of network traffic activities.

D.

Firewalls to block unauthorized processing of transactions.

Question 22

An internal auditor reviews consolidated financial statements for a group of organizations.

Which of the following risks should the auditor consider?

Options:

A.

The statements may conceal poor performance of a subsidiary within the group.

B.

The statements will not reflect business areas under common control.

C.

The statements will not indicate total wealth controlled by the parent company.

D.

The statements may be misleading due to inclusion of transactions between members of the group.

Question 23

According to IIA guidance, which of the following statements is true regarding analytical procedures?

Options:

A.

Data relationships are assumed to exist and to continue where no known conflicting conditions exist.

B.

Analytical procedures are intended primarily to ensure the accuracy of the information being examined.

C.

Data relationships cannot include comparisons between operational and statistical data

D.

Analytical procedures can be used to identify unexpected differences, but cannot be used to identify the absence of differences

Question 24

Which of the following borrowing options is an unsecured loan?

Options:

A.

Second-mortgage financing from a bank.

B.

An issue of commercial paper.

C.

Pledged accounts receivable.

D.

Asset-based financing.

Question 25

Which of the following statements is true regarding multi-report summaries for members of senior management and the board?

Options:

A.

Multi-report summaries should be used to describe the work performed by the internal audit function

B.

In developing multi-report summaries, internal auditors should use multi-row and multi-column tables

C.

Multi-report summaries are not useful to boards that see every engagement report

D.

Multi-report summaries are readily developed if each finding is rated

Question 26

Which of the following physical access controls is most likely to be based on the " something you have " concept?

Options:

A.

A retina characteristics reader.

B.

A PIN code reader.

C.

A card-key scanner.

D.

A fingerprint scanner.

Question 27

According to IIA guidance on IT auditing, which of the following would not be an area examined by the internal audit activity?

Options:

A.

Access system security.

B.

Policy development.

C.

Change management.

D.

Operations processes.

Question 28

An organization filters data packets from public networks to send to an internal private network.

Which of the following devices would accomplish this?

Options:

A.

A router.

B.

A switch.

C.

A hub.

D.

A proxy gateway.

Question 29

Which of the following management statements illustrates how natural bias can lead to poor decision making?

Options:

A.

" Although we previously agreed that we would launch a new product this year, we changed our minds and decided to terminate the launch. "

B.

" Due to the crisis that arose last week, we are not prepared to provide the board with an estimate of next year ' s revenue. "

C.

" We will continue manufacturing the same products in the same way that we always have, because this tradition has made our organization successful. "

D.

" We decided to postpone expanding into the new market because of high uncertainty at this time. "

Question 30

Which of the following would most likely be found in an organization that uses a decentralized organizational structure?

Options:

A.

There is a higher reliance on organizational culture.

B.

There are clear expectations set for employees.

C.

There are electronic monitoring techniques employed

D.

There is a defined code far employee behavior.

Question 31

Which of the following statements is true regarding outsourced business processes?

Options:

A.

Outsourced business processes should not be considered in the internal audit universe because the controls are owned by the external service provider.

B.

Generally, independence is improved when the internal audit activity reviews outsourced business processes.

C.

The key controls of outsourced business processes typically are more difficult to audit because they are designed and managed externally.

D.

The system of internal controls may be better and more efficient when the business process is outsourced compared to internally sourced.

Question 32

An organization has a declining inventory turnover but an increasing gross margin rate. Which of the following statements can best explain this situation?

Options:

A.

he organization ' s operating expenses are increasing.

B.

The organization has adopted just-in-time inventory.

C.

The organization is experiencing inventory theft.

D.

The organization ' s inventory is overstated.

Question 33

The budgeted cost of work performed is a metric best used to measure which project management activity?

Options:

A.

Resource planning.

B.

Cost estimating

C.

Cost budgeting.

D.

Cost control.

Question 34

Which of the following local area network physical layouts is subject to the greatest risk of failure if one device fails?

Options:

A.

Star network.

B.

Bus network.

C.

Token ring network.

D.

Mesh network.

Question 35

Which of the following differentiates a physical access control from a logical access control?

Options:

A.

Physical access controls secure tangible IT resources, whereas logical access controls secure software and data internal to the IT system.

B.

Physical access controls secure software and data internal to the IT system, whereas logical access controls secure tangible IT resources.

C.

Physical access controls include firewalls, user IDs, and passwords, whereas logical access controls include locks and security guards.

D.

Physical access controls include input processing and output controls, whereas logical access controls include locked doors and security guards.

Question 36

Which of the following should internal auditors be attentive of when reviewing personal data consent and opt-in/opt-out management process?

Options:

A.

Whether customers are asked to renew their consent for their data processing at least quarterly.

B.

Whether private data is processed in accordance with the purpose for which the consent was obtained?

C.

Whether the organization has established explicit and entitywide policies on data transfer to third parties.

D.

Whether customers have an opportunity to opt-out the right to be forgotten from organizational records and systems.

Question 37

Which of the following statements is true regarding the resolution of interpersonal conflict?

Options:

A.

Unrealized expectations can be avoided with open and honest discussion.

B.

Reorganization would probably not help ambiguous or overlapping jurisdictions.

C.

Deferring action should be used until there is sufficient time to fully deal with the issue.

D.

Timely and unambiguous clarification of roles and responsibilities will eliminate most interpersonal conflict.

Question 38

A manager has difficulty motivating staff to improve productivity, despite establishing a lucrative individual reward system. Which of the following is most likely the cause of the difficulty?

Options:

A.

High degree of masculinity.

B.

Low uncertainty avoidance.

C.

High collectivism.

D.

Low long-term orientation.

Question 39

Which of the following statements is true regarding the use of public key encryption to secure data while it is being transmitted across a network?

Options:

A.

Both the key used to encrypt the data and the key used to decrypt the data are made public.

B.

The key used to encrypt the data is kept private but the key used to decrypt the data is made public.

C.

The key used to encrypt the data is made public but the key used to decrypt the data is kept private.

D.

Both the key used to encrypt the data and the key used to decrypt the data are made private.

Question 40

Which of the following statements is true regarding data backup?

Options:

A.

System backups should always be performed in real-time.

B.

Backups should be stored in a secured location onsite for easy access.

C.

The tape rotation schedule affects how long data is retained.

D.

Backup media should be restored only in case of a hardware or software failure.

Question 41

The chief audit executive (CAE) has embraced a total quality management approach to improving the internal audit activity ' s (lAArs) processes. He would like to reduce the time to complete audits and improve client ratings of the IAA. Which of the following staffing approaches is the CAE most likely lo select?

Options:

A.

Assign a team with a trained audit manager to plan each audit and distribute field work tasks to various staff auditors.

B.

Assign a team of personnel who have different specialties to each audit and empower Team members to participate fully in key decisions

C.

Assign a team to each audit, designate a single person to be responsible for each phase of the audit, and limit decision making outside of their area of responsibility.

D.

Assign a team of personnel who have similar specialties to specific engagements that would benefit from those specialties and limit Key decisions to the senior person.

Question 42

According to IIA guidance on IT, which of the following best describes a situation where data backup plans exist to ensure that critical data can be restored at some point in the future, but recovery and restore processes have not been defined?

Options:

A.

Hot recovery plan

B.

Warm recovery plan

C.

Cold recovery plan

D.

Absence of recovery plan

Question 43

Which stage of group development is characterized by a decrease in conflict and hostility among group members and an increase in cohesiveness?

Options:

A.

Forming stage.

B.

Norming stage.

C.

Performing stage.

D.

Storming stage.

Question 44

Which of the following performance measures includes both profits and investment base?

Options:

A.

Residual income

B.

A flexible budget

C.

Variance analysis.

D.

A contribution margin income statement by segment.

Question 45

Which of the following data analytics methods involves analyzing event trends to determine what happened?

Options:

A.

Diagnostic analytics.

B.

Descriptive analytics.

C.

Predictive analytics.

D.

Prescriptive analytics.

Question 46

Internal audit observed an increase in defects of newly installed spare parts. An investigation revealed that vendors delivered spare parts of worse quality than required by contract. Which of the following recommendations would most helpfully mitigate this risk?

Options:

A.

Add higher level managers to invoice approval process

B.

Request quality-related confirmations from vendors

C.

Conduct random inspections and testing of deliveries

D.

Improve technical specifications of procurement documents

Question 47

Which of the following controls is the most effective for ensuring confidentially of transmitted information?

Options:

A.

Firewall.

B.

Antivirus software.

C.

Passwords.

D.

Encryption.

Question 48

Management is designing its disaster recovery plan. In the event that there is significant damage to the organization ' s IT systems this plan should enable the organization to resume operations at a recovery site after some configuration and data restoration. Which of the following is the ideal solution for management in this scenario?

Options:

A.

A warm recovery plan.

B.

A cold recovery plan.

C.

A hot recovery plan.

D.

A manual work processes plan

Question 49

Which of the following statements pertaining to a market skimming pricing strategy is not true?

Options:

A.

The strategy is favored when unit costs fall with the increase in units produced.

B.

The strategy is favored when buyers are relatively insensitive to price increases.

C.

The strategy is favored when there is insufficient market capacity and competitors cannot increase market capacity.

D.

The strategy is favored when high price is perceived as high quality.

Question 50

According to IIA guidance, which of the following is a broad collection of integrated policies, standards, and procedures used to guide the planning and execution of a project?

Options:

A.

Project portfolio.

B.

Project development

C.

Project governance.

D.

Project management methodologies

Question 51

During a review of a web-based application used by customers to check the status of their bank accounts, it would be most important for the internal auditor to ensure that:

Options:

A.

Access to read application logs is restricted to authorized users.

B.

Account balance information is encrypted in the database.

C.

The web server used to host the application is located in a physically secure area.

D.

Sensitive data, such as account numbers, are submitted using encrypted communications.

Question 52

The project charter is an output from which of the following?

Options:

A.

Scope planning.

B.

Scope definition.

C.

Scope verification.

D.

Project initiation.

Question 53

A company that uses the accrual basis of accounting can recognize revenue under which of the following conditions?

Options:

A.

When cash is received as payment for a service.

B.

When the receivable is recognized.

C.

When a check is received as payment for a good that has been ordered.

D.

When a good is provided or a service is performed.

Question 54

A new manager received computations of the internal fate of return regarding the project proposal. What should the manager compare the computation results to in order to determine whether the project is potentially acceptable?

Options:

A.

Compare to the annual cost of capital

B.

Compare to the annual interest data.

C.

Compare to the required rate of return.

D.

Compare to the net present value.

Question 55

Which of the following price adjustment strategies encourages prompt payment?

Options:

A.

Cash discounts.

B.

Quantity discounts.

C.

Functional discounts.

D.

Seasonal discounts.

Question 56

Management has decided to change the organizational structure from one that was previously decentralized to one that is now highly centralized. As such: which of the

following would be a characteristic of the now highly centralized organization?

Options:

A.

Top management does little monitoring of the decisions made at lower levels.

B.

The decisions made at the lower levels of management are considered very important.

C.

Decisions made at lower levels in the organizational structure are few.

D.

Reliance is placed on top management decision making by few of the organization ' s departments.

Question 57

Which of the following statements. Is most accurate concerning the management and audit of a web server?

Options:

A.

The file transfer protocol (FTP) should always be enabled.

B.

The simple mail transfer protocol (SMTP) should be operating under the most privileged accounts.

C.

The number of ports and protocols allowed to access the web server should be maximized.

D.

Secure protocols for confidential pages should be used instead of dear-text protocols such as HTTP or FTP.

Question 58

During an internal audit engagement, it was found that several vendors were on a government sanctions list and must no longer be traded with. Which of the following would most effectively mitigate the risk of noncompliance with sanctions lists that are updated regularly?

Options:

A.

Agreements with sanctioned vendors discovered by internal audit will be placed on hold until further notice from the government

B.

A new procedure of vendor onboarding will be implemented to ensure that all new vendors undergo screenings against the sanctions list

C.

Controls will be embedded in the vendor management processes to ensure that new and existing vendors are compliant with changes to the sanctions list

D.

The legal team will be asked to prepare counter arguments to dispute audit findings and potential inquiries from the governmental authority

Question 59

An organization’s income and retained earnings statement is as follows:

Sales: $3,000

Cost of goods sold: $1,600

Gross profit: $1,400

Operating expenses: $970

Operating income: $430

Interest expense: $30

Income before tax: $400

Income tax: $200

Net income: $200

Plus Jan. 1 retained earnings: $150

Less dividends: $60

Dec. 31 retained earnings: $290

Which of the following is the dividend payout ratio?

Options:

A.

20 percent.

B.

30 percent.

C.

40 percent.

D.

50 percent.

Question 60

Which of the following measures the operating success of a company for a given period of time?

Options:

A.

Liquidity ratios.

B.

Profitability ratios.

C.

Solvency ratios.

D.

Current ratios.

Question 61

A newly established organization wants to use the email service offered by a cloud email provider for its own official email. The organization will use its own domain name for a monthly fee, paid to the cloud provider.

What type of cloud service will fit this organization’s requirements?

Options:

A.

Hardware as a Service (HaaS).

B.

Infrastructure as a Service (IaaS).

C.

Platform as a Service (PaaS).

D.

Software as a Service (SaaS).

Question 62

The management of working capital is most crucial for which of the following aspects of business?

Options:

A.

Liquidity

B.

Profitability

C.

Solvency

D.

Efficiency

Question 63

Which of the following conflict resolution methods should be applied when the intention of the parties is to solve the problem by clarifying differences and attaining everyone ' s objectives?

Options:

A.

Accommodating.

B.

Compromising.

C.

Collaborating.

D.

Competing.

Question 64

An organization ' s chief audit executive scheduled an assurance engagement on the key processes and controls related to organizational culture. Which approach to auditing the organization ' s culture did the CAE use?

Options:

A.

Integrated approach.

B.

Top-down approach.

C.

Targeted approach.

D.

Blended approach.

Question 65

An organization sells 1,000 shares of its treasury stock at $15 per share previously acquired at $10 per share.

Which of the following statements is true?

Options:

A.

The organization should record a $5,000 gain on sale of treasury stock.

B.

The organization should record $15,000 as a debit to treasury stock.

C.

The organization should record $5,000 as a credit to paid-in capital.

D.

The organization should record a $10,000 debit to paid-capital account.

Question 66

Which of the following statements Is true regarding the use of centralized authority to govern an organization?

Options:

A.

Fraud committed through collusion is more likely when authority is centralized.

B.

Centralized managerial authority typically enhances certainty and consistency within an organization.

C.

When authority is centralized, the alignment of activities to achieve business goals typically is decreased.

D.

Using separation of duties to mitigate collusion is reduced only when authority is centralized.

Question 67

Which of the following would be the best indicator that the organization is saving money?

Options:

A.

No duplicate payments occurred during the past quarter.

B.

During the past quarter, 95% of invoices were paid by the due date.

C.

During the past quarter, 85% of invoices eligible for early-pay discounts were paid in time to obtain the discount.

D.

During the past quarter, 100% of payments made matched the invoiced amounts.

Question 68

Which of the following would provide the most relevant assurance that the application under development will provide maximum value to the organization?

Options:

A.

Use of a formal systems development lifecycle.

B.

End-user involvement.

C.

Adequate software documentation.

D.

Formalized non-regression testing phase.

Question 69

Which of the following financial statements provides the best disclosure of how a company ' s money was used during a particular period?

Options:

A.

Income statement.

B.

Owner ' s equity statement.

C.

Balance sheet.

D.

Statement of cash flows.

Question 70

Which of the following is true regarding bonds?

Options:

A.

Bondholders do not have voting rights but obtain corporate control via interest pay-outs.

B.

Debenture bonds are rarely used by organizations with good credit ratings.

C.

Using bonds involves paying interest on a periodic basis and repaying the principal at the due date.

D.

Debenture bonds have specific assets pledged by the organization as collateral for the bonds.

Question 71

Which of the following responsibilities would ordinary fall under the help desk function of an organization?

Options:

A.

Maintenance service items such as production support.

B.

Management of infrastructure services, including network management.

C.

Physical hosting of mainframes and distributed servers

D.

End-to -end security architecture design.

Question 72

Which of the following would an organization execute to effectively mitigate and manage risks created by a crisis or event?

Options:

A.

Only preventive measures.

B.

Alternative and reactive measures.

C.

Preventive and alternative measures.

D.

Preventive and reactive measures.

Question 73

Which of the following serves as a safeguard to protect the confidentiality of information being transmitted from an internal network to an external network?

Options:

A.

A cloud network.

B.

A mobile network.

C.

An intranet.

D.

A virtual private network.

Question 74

With regard to disaster recovery planning, which of the following would most likely involve stakeholders from several departments?

Options:

A.

Determining the frequency with which backups will be performed.

B.

Prioritizing the order in which business systems would be restored.

C.

Assigning who in the IT department would be involved in the recovery procedures.

D.

Assessing the resources needed to meet the data recovery objectives.

Question 75

The internal audit function for a large organization has commenced this year’s scheduled accounts payable audit. The annual external audit for the organization is currently being planned. Can the external auditors place reliance on the work performed by the internal audit function?

Options:

A.

Yes, if an external audit manager is assigned to lead the internal audit team

B.

No, the external auditors should do their own substantive testing on accounts payable

C.

Yes, if they believe that the internal audit is going to be performed with due competence and objectivity

D.

No, the internal audit function should not share information relating to its work with external parties

Question 76

Which of the following actions would senior management need to consider as part of new IT guidelines regarding the organization ' s cybersecurity policies?

Options:

A.

Assigning new roles and responsibilities for senior IT management.

B.

Growing use of bring your own devices for organizational matters.

C.

Expansion of operations into new markets with limited IT access.

D.

Hiring new personnel within the IT department for security purposes.

Question 77

According to Maslow ' s hierarchy of needs theory, which of the following best describes a strategy where a manager offers an assignment to a subordinate specifically to support his professional growth and future advancement?

Options:

A.

Esteem by colleagues.

B.

Self-fulfillment

C.

Series of belonging in the organization

D.

Job security

Question 78

Which of the following statements is true regarding the data dictionary?

Options:

A.

The data dictionary includes system tables and program files of a database.

B.

The data dictionary describes the content of information stored in the database.

C.

The data dictionary specifies objects such as users, permissions, and groups.

D.

The data dictionary includes system backup and encryption keys.

Question 79

An organization has 1,000 units of a defective item in stock. Per unit, market price is $10; production cost is $4; and the defect selling price is $5. What is the carrying amount (inventory value) of defects at year-end?

Options:

A.

$0

B.

$4,000

C.

$5,000

D.

$10,000

Question 80

Which of the following is a cybersecurity monitoring activity intended to deter disruptive codes from being installed on an organizations systems?

Options:

A.

Boundary defense

B.

Malware defense.

C.

Penetration tests

D.

Wireless access controls

Question 81

An internal auditor observed that the organization ' s disaster recovery solution will make use of a cold site in a town several miles away. Which of the following is likely to be a characteristic of this disaster recover/ solution?

Options:

A.

Data is synchronized in real time

B.

Recovery time is expected to be less than one week

C.

Servers are not available and need to be procured

D.

Recovery resources end data restore processes have not been defined.

Question 82

During a visit to an oil production plant, an internal auditor was surprised to see the accounting employees shopping online using work computers. The auditor knew that the company ' s policy did not allow access to certain webpages, including those being used for online shopping.

Which of the following should the auditor study next to explore the observation further?

Options:

A.

The company’s training policy on social media.

B.

The company’s firewall configuration rules.

C.

The company’s access point encryption settings.

D.

The company’s software installation controls.

Question 83

To achieve conformance with the Global Internal Audit Standards, the chief audit executive must include which of the following activities in the quality assurance and improvement program (QAIP)?

Options:

A.

Require board oversight of the QAIP

B.

Assess Standards conformance for each individual assurance engagement

C.

Conduct a self-assessment at least once every five years

D.

Report the results of the QAIP to the board

Question 84

Which of the following statements regarding program change management is not correct?

Options:

A.

The goal of the change management process is to sustain and improve organizational operations.

B.

The degree of risk associated with a proposed change determines if the change request requires authorization.

C.

In order to protect the production environment, changes must be managed in a repeatable, defined, and predictable manner.

D.

All changes should be tested in a non-production environment before migrating to the production environment.

Question 85

An organization created a formalized plan for a large project. Which of the following should be the first step in the project management plan?

Options:

A.

Estimate time required to complete the whole project.

B.

Determine the responses to expected project risks.

C.

Break the project into manageable components.

D.

Identify resources needed to complete the project

Question 86

Which of the following represents an example of a physical security control?

Options:

A.

Access rights are allocated according to the organization’s policy

B.

There is confirmation that data output is accurate and complete

C.

Servers are located in locked rooms to which access is restricted

D.

A record is maintained to track the process from data input to storage

Question 87

An organization is considering mirroring the customer data for one regional center at another center. A disadvantage of such an arrangement would be:

Options:

A.

Lack of awareness of the state of processing.

B.

Increased cost and complexity of network traffic.

C.

Interference of the mirrored data with the original source data.

D.

Confusion about where customer data are stored.

Question 88

A data classification policy would most likely assist in achieving which of the following control objectives?

Options:

A.

Confirming the validity of the data record.

B.

Ensuring the completeness of the data.

C.

Eliminating redundant data records.

D.

Complying with data protection regulations.

Question 89

Which of the following security controls focuses most on prevention of unauthorized access to the power plant?

Options:

A.

An offboarding procedure is initiated monthly to determine redundant physical access rights.

B.

Logs generated by smart locks are automatically scanned to identify anomalies in access patterns.

C.

Requests for additional access rights are sent for approval and validation by direct supervisors.

D.

Automatic notifications are sent to a central security unit when employees enter the premises during nonwork hours

Question 90

A senior payroll accountant was responsible for three business units. When the number of employees increased considerably, another accountant was hired and became responsible for one of the units. However, an access rights attestation from the senior payroll accountant remained the same, despite an internal policy requiring payroll access to be restricted. Which of the following controls most likely failed?

Options:

A.

Reauthorization controls.

B.

Authorization controls.

C.

Authentication controls.

D.

Segregation of duties.

Question 91

What must be monitored in order to manage the risk of consumer product inventory obsolescence?

    Inventory balances.

    Market share forecasts.

    Sales returns.

    Sales trends.

Options:

A.

1 only

B.

4 only

C.

1 and 4 only

D.

1, 2, and 3 only

Question 92

Which of the following communication characteristics is achieved when the internal audit function avoids redundancies and excludes information that is unnecessary, insignificant, or unrelated to the engagement?

Options:

A.

Constructive communications

B.

Complete communications

C.

Concise communications

D.

Clear communications

Question 93

Which of the following analytical techniques would an internal auditor use to verify that none of an organization ' s employees are receiving fraudulent invoice payments?

Options:

A.

Perform gap testing.

B.

Join different data sources.

C.

Perform duplicate testing.

D.

Calculate statistical parameters.

Question 94

If a bank ' s activities are categorized under such departments as community banking, institutional banking, and agricultural banking, what kind of departmentalization is being utilized?

Options:

A.

Product departmentalization.

B.

Process departmentalization.

C.

Functional departmentalization.

D.

Customer departmentalization.

Question 95

Which of the following is most appropriately placed in the financing section of an organization ' s cash budget?

Options:

A.

Collections from customers

B.

Sale of securities.

C.

Purchase of trucks.

D.

Payment of debt, including interest

Question 96

What is the primary risk associated with an organization adopting a decentralized structure?

Options:

A.

Inability to adapt.

B.

Greater costs of control function.

C.

Inconsistency in decision making.

D.

Lack of resilience.

Question 97

Which of the following situations best applies to an organization that uses a project, rather than a process, to accomplish its business activities?

Options:

A.

A clothing company designs, makes, and sells a new item

B.

A commercial construction company is hired to build a warehouse

C.

A city department sets up a new firefighter training program

D.

A manufacturing organization acquires component parts from a contracted vendor

Question 98

Which of the following is true of bond financing, compared to common stock, when alJ other variables are equal?

Options:

A.

Lower shareholder control

B.

lower indebtedness

C.

Higher company earnings per share.

D.

Higher overall company earnings

Question 99

Which of the following should be included in a data privacy poky?

1. Stipulations for deleting certain data after a specified period of time.

2. Guidance on acceptable methods for collecting personal data.

3. A requirement to retain personal data indefinitely to ensure a complete audit trail,

4. A description of what constitutes appropriate use of personal data.

Options:

A.

1 and 2 only

B.

2 and 3 only

C.

1, 2 and 4 only

D.

2, 3, and 4 only

Question 100

Internal audit discovered that several loads of pellets were deleted from the scaling database and consequently had no sales invoices, significantly affecting financial statements. An investigation revealed that technicians had deleted the pellet loads accidentally, with no evidence of fraud. Which of the following actions should management implement first?

Options:

A.

Address root causes by launching a project to understand and revise the methods for granting database access rights

B.

Address the condition by limiting technicians ' access to live database data

C.

Address potential risks by reconciling all sales invoices against scaling data

D.

Address investigation results by dismissing technicians who caused the disruption

Question 101

Which of the following is the primary goal of an effective business impact analysis?

Options:

A.

It includes business continuity program governance and risk management.

B.

It identifies key assets, critical processes, resources, and technology.

C.

It sets testing requirements for the organization wide continuity functions.

D.

It outlines and communicates recovery points and objectives.

Question 102

Organizations use matrix management to accomplish which of the following?

Options:

A.

To improve the chain of command.

B.

To strengthen corporate headquarters.

C.

To focus better on a single market.

D.

To increase lateral communication.

Question 103

Which of the following is an established systems development methodology?

Options:

A.

Waterfall.

B.

Projects in Controlled Environments (PRINCE2).

C.

Information Technology Infrastructure Library (ITIL).

D.

COBIT

Question 104

What would be the most relevant risk related to a bring-your-own-device policy?

Options:

A.

Data leakage due to the devices having access to the network.

B.

Lack of understanding of the technology and concept of the tool.

C.

Missing noncurrent assets capitalization.

D.

Financial losses due to smart device theft.

Question 105

Through meetings with management, an organization ' s chief audit executive (CAE) learns of a risk that exceeds the established risk tolerance. What would be an appropriate next action for the CAE to take?

Options:

A.

Design and recommend an appropriate response to the risk

B.

Discuss the risk and the implications of the risk with management responsible for the risk area

C.

Schedule an audit of the risk area to assess the risk likelihood and impact

D.

Prepare a memo to report the risk to the board

Question 106

An internal auditor conducts a preliminary privacy and data protection risk assessment. Which of the following is the most essential question to start the assessment?

Options:

A.

How does the cybersecurity unit investigate instances of data leakage or allegations?

B.

What are potential fines applicable to the organization for data protection breaches?

C.

What type of private data is collected and maintained by the organization?

D.

In what instances is data pseudonymization is applied in the organization?

Question 107

An organization prepares a statement of privacy to protect customers ' personal information. Which of the following might violate the privacy principles?

Options:

A.

Customers can access and update personal information when needed.

B.

The organization retains customers ' personal information indefinitely.

C.

Customers reserve the right to reject sharing personal information with third parties.

D.

The organization performs regular maintenance on customers ' personal information.

Question 108

A new clerk in the managerial accounting department applied the high-low method and computed the difference between the high and low levels of maintenance costs. Which type of maintenance costs did the clerk determine?

Options:

A.

Fixed maintenance costs.

B.

Variable maintenance costs.

C.

Mixed maintenance costs.

D.

Indirect maintenance costs.

Question 109

An internal audit function has commenced its annual follow-up activity. An internal auditor has been assigned to verify whether the recommendations from an audit engagement completed three months ago were implemented by the business unit. The auditor had not participated in that audit engagement. What should the auditor do first?

Options:

A.

Conduct interviews with senior management of the business unit

B.

Request information from the business unit regarding the corrective actions taken

C.

Review the previous audit findings and management ' s response

D.

Conduct a walkthrough of the business unit

Question 110

Which of the following actions is likely to reduce the risk of violating transfer pricing regulations?

Options:

A.

The organization sells inventory to an overseas subsidiary at fair value.

B.

The local subsidiary purchases inventory at a discounted price.

C.

The organization sells inventory to an overseas subsidiary at the original cost.

D.

The local subsidiary purchases inventory at the depreciated cost.A

Question 111

Which of the following is an example of a physical control?

Options:

A.

Providing fire detection and suppression equipment

B.

Establishing a physical security policy and promoting it throughout the organization

C.

Performing business continuity and disaster recovery planning

D.

Keeping an offsite backup of the organization’s critical data

Question 112

An internal auditor wishes to test why there was a significant drop in accounts payable volume last month and creates several scenarios to help explain the anomaly.

Which of the following best describes this data analysis technique?

Options:

A.

Descriptive.

B.

Diagnostic.

C.

Predictive.

D.

Prescriptive.

Question 113

During disaster recovery planning, the organization established a recovery point objective. Which of the following best describes this concept?

Options:

A.

The maximum tolerable downtime after the occurrence of an incident.

B.

The maximum tolerable data loss after the occurrence of an incident.

C.

The maximum tolerable risk related to the occurrence of an incident

D.

The minimum recovery resources needed after the occurrence of an incident

Question 114

Which of the following scenarios would cause a chief audit executive (CAE) to immediately discontinue using any statements that would indicate conformance with the Global Internal Audit Standards in an audit report?

Options:

A.

The internal audit function used a risk-based approach to create the internal audit plan

B.

The engagement supervisor considered requests from senior management regarding engagements to include in the internal audit plan

C.

The CAE only accepted engagements that the internal audit function collectively had the knowledge to perform

D.

The activity under review restricted the internal audit function ' s ability to access records, impacting the audit results

Question 115

To execute its new strategy of differentiation, based mainly on innovation, flexibility, and responsiveness, while maintaining control on operations and reducing any duplication of resources, an organization has introduced many changes that are relevant to its organizational structure. Which of the following structures would best fit the new strategy?

Options:

A.

The functional structure.

B.

The divisional structure.

C.

The team approach.

D.

The virtual network approach.

Question 116

Which of the following facilitates data extraction from an application?

Options:

A.

Application program code.

B.

Database system.

C.

Operating system.

D.

Networks.

Question 117

For employees, the primary value of implementing job enrichment is which of the following?

Options:

A.

Validation of the achievement of their goals anti objectives

B.

Increased knowledge through the performance of additional tasks

C.

Support for personal growth and a meaningful work experience

D.

An increased opportunity to manage better the work done by their subordinates

Question 118

An internal auditor is completing an access control assessment of a telecommunication organization’s offsite facility.

Which of the following physical security measures would best prevent unauthorized access to the facility?

Options:

A.

Proximity badges.

B.

Key locks.

C.

Combination codes.

D.

Biometric locks.

Question 119

Which of the following budgets must be prepared first?

Options:

A.

Cash budget.

B.

Production budget.

C.

Sales budget.

D.

Selling and administrative expenses budget.

Question 120

Which of the following strategies is most appropriate for an industry that is in decline?

Options:

A.

Invest in marketing.

B.

Invest in research and development.

C.

Control costs.

D.

Shift toward mass production.

Question 121

Listening effectiveness is best increased by:

Options:

A.

Resisting both internal and external distractions.

B.

Waiting to review key concepts until the speaker has finished talking.

C.

Tuning out messages that do not seem to fit the meeting purpose.

D.

Factoring in biases in order to evaluate the information being given.

Question 122

What kind of strategy would be most effective for an organization to adopt in order to Implement a unique advertising campaign for selling identical product lines across all of its markets?

Options:

A.

Export strategy.

B.

Transnational strategy

C.

Multi-domestic strategy

D.

Globalization strategy

Question 123

Which of the following activities best illustrates a user ' s authentication control?

Options:

A.

Identity requests are approved in two steps.

B.

Logs are checked for misaligned identities and access rights.

C.

Users have to validate their identity with a smart card.

D.

Functions can toe performed based on access rights

Question 124

Which type of bond sells at a discount from face value, then increases in value annually until it reaches maturity and provides the owner with the total payoff?

Options:

A.

High-yield bonds

B.

Commodity-backed bonds

C.

Zero-coupon bonds

D.

Junk bonds

Question 125

Which of the following accurately describes a difference between phishing and spear phishing?

Options:

A.

Phishing targets individuals indiscriminately, while spear phishing targets specific individuals.

B.

Phishing uses emails in attacks, while spear phishing uses other methods.

C.

Phishing requires unauthorized access to a system, while spear phishing requires successful social engineering attempts.

D.

Phishing aims to acquire personal information, while spear phishing aims to send unsolicited notifications or advertisements.

Question 126

A manager decided to build his team ' s enthusiasm by giving encouraging talks about employee empowerment, hoping to change the perception that management should make all decisions in the department.

The manager is most likely trying to impact which of the following components of his team ' s attitude?

Options:

A.

Affective component.

B.

Cognition component.

C.

Thinking component.

D.

Behavioral component.

Question 127

An organization buys equity securities for trading purposes and sells them within a short time period. Which of the following is the correct way to value and report those securities at a financial statement date?

Options:

A.

At fair value with changes reported in the shareholders ' equity section.

B.

At fair value with changes reported in net income.

C.

At amortized cost in the income statement.

D.

As current assets in the balance sheet

Question 128

According to UA guidance on IT, at which of the following stages of the project life cycle would the project manager most likely address the need to coordinate project resources?

Options:

A.

Initiation.

B.

Planning.

C.

Execution.

D.

Monitoring.

Question 129

Which of the following would most likely be found in an organization that uses a decentralized organizational structure?

Options:

A.

There is a higher reliance on organizational culture.

B.

There are clear expectations set for employees.

C.

There are electronic monitoring techniques employed.

D.

There is a defined code for employee behavior.

Question 130

Which of the following actions illustrates the use of electronic data interchange?

Options:

A.

Sending an invoice automatically from the supplier to the customer in a standard format.

B.

Using an accounting software hosted on the cloud.

C.

Transferring money using mobile phones.

D.

Updating vendor master files using online real-time.

Question 131

Which of the following statements is true regarding activity-based costing (ABC)?

Options:

A.

An ABC costing system is similar to conventional costing systems in how it treats the allocation of manufacturing overhead.

B.

An ABC costing system uses a single unit-level basis to allocate overhead costs to products.

C.

An ABC costing system may be used with either a job order or a process cost accounting system.

D.

The primary disadvantage of an ABC costing system is less accurate product costing.

Question 132

An organization requires an average of 58 days to convert raw materials into finished products to sell. An additional 42 days is required to collect receivables. If the organization takes an average of 10 days to pay for raw materials, how long is its total cash conversion cycle?

Options:

A.

26 days.

B.

90 days.

C.

100 days.

D.

110 days.

Question 133

The chief audit executive hired a consultant to update the internal audit function’s methodologies. Which of the following would best ensure that the internal audit function will adhere to the updated methodologies?

Options:

A.

Placing the updated methodologies in an easily accessible location for reference

B.

Requiring a signed acknowledgment that each auditor will comply with the updated methodologies

C.

Preparing a recorded training that reviews the updated methodologies

D.

Sharing a one-page summary of the updated methodologies during an internal audit function meeting

Question 134

Which of the following risks is the result of an organization failing to create and establish strategies for the use of social media?

Options:

A.

The organization does not ensure that all employee posts have been vetted by the relevant department.

B.

The organization may be subject to penalties for employee posts.

C.

The organization does not ensure the board ' s tone at the top reaches all employees.

D.

The organization is reactive rather than proactive in the use of social media.

Question 135

An internal auditor found the following information while reviewing the monthly financial siatements for a wholesaler of safety

as

The cost of goods sold was reported at $8,500. Which of the following inventory methods was used to derive this value?

Options:

A.

Average cost method

B.

First-in, first-out (FIFO) method

C.

Specific identification method

D.

Activity-based costing method

Question 136

An organization has limited resources and wants to utilize its current IT physical infrastructure as much as possible. Which of the following technologies would assist the organization?

Options:

A.

Virtualization.

B.

Cloud computing.

C.

Open-source software.

D.

Robotic process automation.

Question 137

Which observations should the chief audit executive include in the executive summary of the final engagement communication?

Options:

A.

All observations

B.

Only observations with an action plan

C.

Only significant observations

D.

Only observations agreed with management

Question 138

What would an internal auditor do to ensure that a process to mitigate risk is in place for the organization ' s change management process?

Options:

A.

Develop and enforce change policies to ensure employees are continually trained.

B.

Apply a risk-based approach and impose segregation of duties related to the change management process.

C.

Conduct a high-level threat analysis and implement a compensating control.

D.

Validate authorization, segregation of duties, testing of changes, and approval to move changes into production.

Question 139

A junk bond issued at a premium will result in which of the following entries in the general ledger?

Options:

A.

A credit to non-current liabilities on the balance sheet.

B.

A debit to expenses on the profit and loss statement.

C.

A credit to revenue on the profit and loss statement.

D.

A debit to current assets on the balance sheet.

Question 140

When examining; an organization ' s strategic plan, an internal auditor should expect to find which of the following components?

Options:

A.

Identification of achievable goals and timelines

B.

Analysis of the competitive environment.

C.

Plan for the procurement of resources

D.

Plan for progress reporting and oversight.

Question 141

At one organization, the specific terms of a contract require both the promisor and promisee to sign the contract in the presence of an independent witness. What is the primary role to the witness to these signatures?

Options:

A.

A witness verifies the quantities of the copies signed.

B.

A witness verifies that the contract was signed with the free consent of the promisor and promisee.

C.

A witness ensures the completeness of the contract between the promisor and promisee.

D.

A witness validates that the signatures on the contract were signed by the promisor and promisee.

Question 142

Which of the following types of accounts must be closed at the end of the period?

Options:

A.

Income statement accounts.

B.

Balance sheet accounts.

C.

Permanent accounts.

D.

Real accounts.

Question 143

Which of the following is a key factor in the development of a production budget for a manufacturing organization?

Options:

A.

Direct materials units required.

B.

Estimated ending unit inventory.

C.

Projected sales revenue.

D.

Variable overhead costs.

Question 144

A small chain of grocery stores made a reporting error and understated its ending inventory. What effect would this have on the income statement for the following year?

Options:

A.

Net income would be understated.

B.

Net income would not be affected.

C.

Net income would be overstated.

D.

Net income would be negative.

Question 145

Which of the following would be most effective in preventing phishing attacks from impacting business systems?

Options:

A.

Training users on security awareness.

B.

Monitoring the usage of IT systems.

C.

Using software to detect malware.

D.

Blocking access to a user ' s accounts.

Question 146

A multinational organization allows its employees to access work email via personal smart devices. However, users are required to consent to the installation of mobile device management (MDM) software that will remotely wipe data in case of theft or other incidents. Which of the following should the organization ensure in exchange for the employees ' consent?

Options:

A.

That those employees who do not consent to MDM software cannot have an email account.

B.

That personal data on the device cannot be accessed and deleted by system administrators.

C.

That monitoring of employees ' online activities is conducted in a covert way to avoid upsetting them.

D.

That employee consent includes appropriate waivers regarding potential breaches to their privacy.

Question 147

Which of the following must be adjusted to index a progressive tax system to inflation?

Options:

A.

Tax deductions, exemptions, and tax filings.

B.

Tax deductions, exemptions, and tax brackets.

C.

Tax brackets, tax deductions, and tax payments.

D.

Tax brackets, exemptions, and nominal tax receipts.

Question 148

A line on a spreadsheet includes an employee ' s name, date of hire, job title, and monthly salary. Which of the following correctly describes this line information?

Options:

A.

Field.

B.

File.

C.

Record.

D.

Database.

Question 149

According to The IIA ' s Three Lines Model, which of the following IT security activities is commonly shared by all three lines?

Options:

A.

Assessments of third parties and suppliers.

B.

Recruitment and retention of certified IT talent.

C.

Classification of data and design of access privileges.

D.

Creation and maintenance of secure network and device configuration.

Question 150

Which of the following statements is true regarding cost-volume-profit analysis?

Options:

A.

Contribution margin is the amount remaining from sales revenue after fixed expenses have been deducted

B.

Breakeven is the amount of units sold to cover variable costs

C.

Breakeven occurs when the contribution margin covers fixed costs

D.

Following breakeven, net operating income will increase by the excess of fixed costs less the variable costs per unit sold

Question 151

Which of the following describes how human resources can best assist in recruitment efforts for the internal audit function?

Options:

A.

Prepare competency-based interview questions and interview potential candidates

B.

Leverage the organization ' s intranet and recruiting agencies to search for potential candidates

C.

Forward all applications to the chief audit executive for review

D.

Select the most qualified candidate for the vacant position

Question 152

What kind of strategy would be most effective for an organization to adopt in order to implement a unique advertising campaign for selling identical products across all of its markets?

Options:

A.

Export strategy.

B.

Transnational strategy.

C.

Multi-domestic strategy.

D.

Globalization strategy.

Question 153

In an analysis of alternative credit-management policies, which of the following components will cause the net present value of receivables on credit sales to increase, if everything else remains constant?

Options:

A.

A tougher collections policy that reduces the bad debt loss ratio.

B.

A higher cost per unit sold.

C.

A longer average collection period.

D.

An increase in the cost of capital.

Question 154

Which of the following statements is true regarding a bring-your-own-device (BYOD) environment?

Options:

A.

There is a greater need for organizations to rely on users to comply with policies and procedures.

B.

With fewer devices owned by the organization, there is reduced need to maintain documented policies and procedures.

C.

Incident response times are less critical in the BYOD environment compared to a traditional environment.

D.

There is greater sharing of operational risk in a BYOD environment.

Question 155

According to IIA guidance, which of the following links computers and enables them to -communicate with each other?

Options:

A.

Application program code

B.

Database system

C.

Operating system

D.

Networks

Question 156

Which of the following is likely to occur when an organization decides to adopt a decentralized organizational structure?

Options:

A.

A slower response to external change.

B.

Less controlled decision making.

C.

More burden on higher-level managers.

D.

Less use of employees ' true skills and abilities.

Question 157

Which of the following statements about assurance maps is true?

Options:

A.

They help identify gaps and duplications in an organization’s assurance coverage

B.

They allow the board to coordinate activities of internal and external assurance providers

C.

They help identify which assurance provider is responsible for performing each audit listed in the annual internal audit plan

D.

They allow internal auditors to map competencies and specialty areas of the assurance providers in an organization

Question 158

During which of the following phases of contracting does the organization analyze whether the market is aligned with organizational objectives?

Options:

A.

Initiation phase

B.

Bidding phase

C.

Development phase

D.

Negotiation phase

Question 159

Which of the following statements is true regarding cost-volume-profit analysis?

Options:

A.

Contribution margin is the amount remaining from sales revenue after fixed expenses have been deducted.

B.

Breakeven point is the amount of units sold to cover variable costs.

C.

Breakeven occurs when the contribution margin covers fixed costs.

D.

Following breakover1, he operating income will increase by the excess of fixed costs less the variable costs per units sold.

Question 160

A manufacturer ss deciding whether to sell or process materials further. Which of the following costs would be relevant to this decision?

Options:

A.

Incremental processing costs, incremental revenue, and variable manufacturing expenses.

B.

Joint costs, incremental processing costs, and variable manufacturing expenses.

C.

Incremental revenue, joint costs, and incremental processing costs.

D.

Variable manufacturing expenses, incremental revenue, and joint costs

Question 161

According to IIA guidance on IT, which of the following best describes a situation where data backup plans exist to ensure that critical data can be restored at some point in the future, but recovery and restore processes have not been defined?

Options:

A.

Hot recovery plan

B.

Warm recovery plan

C.

Cold plan

D.

Absence of recovery plan

Question 162

Which of the following controls would be most efficient to protect business data from corruption and errors?

Options:

A.

Controls to ensure data is unable to be accessed without authorization.

B.

Controls to calculate batch totals to identify an error before approval.

C.

Controls to encrypt the data so that corruption is likely ineffective.

D.

Controls to quickly identify malicious intrusion attempts.

Question 163

How can the concept of relevant cost help management with behavioral analyses?

Options:

A.

It explains the assumption mat both costs and revenues are linear through the relevant range

B.

It enables management to calculate a minimum number of units to produce and sell without having to incur a loss.

C.

It enables management to predict how costs such as the depreciation of equipment will be affected by a change in business decisions

D.

It enables management to make business decisions, as it explains the cost that will be incurred for a given course of action

Question 164

An organization decided to reorganize into a flatter structure. Which of the following changes would be expected with this new structure?

Options:

A.

Lower costs.

B.

Slower decision making at the senior executive level.

C.

Limited creative freedom in lower-level managers.

D.

Senior-level executives more focused on short-term, routine decision making

Question 165

An organization uses the management-by-objectives method whereby employee performance is based on defined goals. Which of the following statements is true regarding this approach?

Options:

A.

It is particularly helpful to management when the organization is facing rapid change.

B.

It is a more successful approach when adopted by mechanistic organizations.

C.

It is mere successful when goal setting is performed not only by management, but by all team members, including lower-level staff.

D.

It is particularly successful in environments that are prone to having poor employer-employee relations.

Question 166

The IT department maintains logs of user identification and authentication for all requests for access to the network. What is the primary purpose of these logs?

Options:

A.

To ensure proper segregation of duties

B.

To create a master repository of user passwords

C.

To enable monitoring for systems efficiencies

D.

To enable tracking of privileges granted to users over time

Question 167

Which of following best demonstrates the application of the cost principle?

Options:

A.

A company reports trading and investment securities at their market cost

B.

A building purchased last year for $1 million is currently worth ©1.2 million, but the company still reports the building at $1 million.

C.

A building purchased last year for ©1 million is currently worth £1,2 million , and the company adjusts the records to reflect the current value

D.

A company reports assets at either historical or fair value, depending which is closer to market value.

Question 168

Which of the following is the best example of a compliance risk that is likely to arise when adopting a bring-your-own-device (BYOD) policy?

Options:

A.

The risk that users try to bypass controls and do not install required software updates

B.

The risk that smart devices can be lost or stolen due to their mobile nature

C.

The risk that an organization intrusively monitors personal information stored on smart devices

D.

The risk that proprietary information is not deleted from the device when an employee leaves

Question 169

Which of the following is a characteristic of big data?

Options:

A.

Big data is often structured.

B.

Big data analytic results often need to be visualized.

C.

Big data is often generated slowly and is highly variable.

D.

Big data comes from internal sources kept in data warehouses.

Question 170

Which of the following is an example of internal auditors applying data mining techniques for exploratory purposes?

Options:

A.

Internal auditors perform reconciliation procedures to support an external audit of financial reporting.

B.

Internal auditors perform a systems-focused analysis to review relevant controls.

C.

Internal auditors perform a risk assessment to identify potential audit subjects as input for the annual internal audit plan

D.

Internal auditors test IT general controls with regard to operating effectiveness versus design

Question 171

An internal auditor identified a database administrator with an incompatible dual role. Which of the following duties should not be performed by the identified administrator?

Options:

A.

Designing and maintaining the database.

B.

Preparing input data and maintaining the database.

C.

Maintaining the database and providing its security,

D.

Designing the database and providing its security

Question 172

International marketing activities often begin with:

Options:

A.

Standardization.

B.

Global marketing.

C.

Limited exporting.

D.

Domestic marketing.

Question 173

Which of the following is true of matrix organizations?

Options:

A.

A unity-of-command concept requires employees to report technically, functionally, and administratively to the same manager.

B.

A combination of product and functional departments allows management to utilize personnel from various Junctions.

C.

Authority, responsibility and accountability of the units Involved may vary based on the project ' s life, or the organization ' s culture

D.

It is best suited for firms with scattered locations or for multi-line, Large-scale firms.

Question 174

Which of the following is the most appropriate way lo record each partner ' s initial Investment in a partnership?

Options:

A.

At the value agreed upon by the partners.

B.

At book value.

C.

At fair value

D.

At the original cost.

Question 175

An organization contracted a third-party service provider to plan, design, and build a new facility. Senior management would like to transfer all of the risk to the builder. Which type of procurement contract would the organization use?

Options:

A.

Cost-plus contract.

B.

Turnkey contract.

C.

Service contract.

D.

Solutions contract.

Question 176

In mergers and acquisitions, which of the following is an example of a horizontal combination?

Options:

A.

Dairy manufacturing company taking over a large dairy farm.

B.

A movie producer acquires movie theaters.

C.

A petroleum processing company acquires an agro-processing firm.

D.

A baker taking over a competitor.

Question 177

At what stage of project integration management would a project manager and project management team typically coordinate the various technical and organizational interfaces that exist in the project?

Options:

A.

Project plan development.

B.

Project plan execution

C.

Integrated change control.

D.

Project quality planning

Question 178

Based on lest results, an IT auditor concluded that the organization would suffer unacceptable loss of data if there was a disaster at its data center. Which of the following test results would likely lead the auditor to this conclusion?

Options:

A.

Requested backup tapes were not returned from the offsite vendor In a timely manner.

B.

Returned backup tapes from the offsite vendor contained empty spaces.

C.

Critical systems have boon backed up more frequently than required.

D.

Critical system backup tapes are taken off site less frequently than required

Question 179

Which of the following security controls would be me most effective in preventing security breaches?

Options:

A.

Approval of identity request

B.

Access logging.

C.

Monitoring privileged accounts

D.

Audit of access rights

Question 180

Which of the following purchasing scenarios would gain the greatest benefit from implementing electronic cate interchange?

Options:

A.

A just-in-time purchasing environment

B.

A Large volume of custom purchases

C.

A variable volume sensitive to material cost

D.

A currently inefficient purchasing process

Question 181

An internal audit team is trialing a data analytics tool. An extract from accounts payable was loaded into the tool and as a result, the tool flagged most of the transactions, thus yielding no meaningful results. After investigating, the audit team determined that the extract contained duplicate entries and spelling issues.

Which of the following should have been performed prior to loading the data into the analytics tool?

Options:

A.

Data segregation.

B.

Data stratification.

C.

Data normalization.

D.

Data quantification.

Question 182

Which of the following functions of access control systems involves keeping logs of a user ' s activity in a system?

Options:

A.

Identification.

B.

Authentication.

C.

Authorization.

D.

Accountability.

Question 183

Which of the following database components stores metadata regarding the database’s own configuration, setup, and objects?

Options:

A.

Database table.

B.

Program files.

C.

Backup system.

D.

Data dictionary.

Question 184

A newly hired chief audit executive (CAE) reviews and will revise the existing internal audit strategy. What should the CAE initially refer to when revising the internal audit strategy?

Options:

A.

Legal and regulatory requirements

B.

Organization-wide risk assessment results

C.

Key internal control activities

D.

Organizational business objectives

Question 185

Which of the following items represents the first thing that should be done with obtained dote in the data analytics process?

Options:

A.

Verify completeness and accuracy.

B.

Verify existence and accuracy.

C.

Verify completeness and integrity.

D.

Verify existence and completeness.

Question 186

Which of the following statements is most accurate concerning the management and audit of a web server?

Options:

A.

The file transfer protocol (FTP) should always be enabled

B.

The simple mail transfer protocol (SMTP) should be operating under the most privileged accounts

C.

The number of ports and protocols allowed to access the web server should be maximized

D.

Secure protocols for confidential pages should be used instead of clear-text protocols such as HTTP or FTP

Question 187

Which of the following is a necessary action for an internal audit function if senior management chooses not to take action to remediate the finding and accepts the risk?

Options:

A.

The chief audit executive (CAE) must discuss this disagreement with senior management and communicate this information to external stakeholders

B.

The CAE must include this disagreement in the final audit report and conclude the engagement

C.

The CAE must make a judgment regarding the prudence of that decision and report to the board if needed

D.

The CAE must establish a follow-up process to monitor the acceptable risk level as part of the engagement

Question 188

Which of the following network types should an organization choose if it wants to allow access only to its own personnel?

Options:

A.

An extranet

B.

A local area network

C.

An Intranet

D.

The internet

Question 189

An investor has acquired an organization that has a dominant position in a mature, slow-growth industry and consistently creates positive financial income. Which of the following terms would the investor most likely label this investment in her portfolio?

Options:

A.

A star

B.

A cash cow

C.

A question mark

D.

A dog

Question 190

According to IIA guidance, which of the following statements is true with regard to workstation computers that access company information stored on the network?

Options:

A.

Individual workstation computer controls are not as important as companywide server controls

B.

Particular attention should be paid to housing workstations away from environmental hazards

C.

Cybersecurity issues can be controlled at an enterprise level, making workstation-level controls redundant

D.

With security risks near an all-time high, workstations should not be connected to the company network

Question 191

Which of the following best illustrates the meaning of fair value?

Options:

A.

Unrealized gains or losses of the investment portfolio.

B.

The difference between the total cost of securities and their market cost.

C.

The price for which a security could be sold at normal market conditions.

D.

The original cost of a security plus revenues it has earned.

Question 192

An internal auditor has completed the fieldwork of an assurance engagement on the organization ' s business continuity. The most significant finding is that business requirements were left up to the IT function to decide and implement. As a result, the time to recovery for some critical systems following a disruption is too long, while recovery time of non-critical systems is needlessly prioritized at a significant cost. Which of the following is the most appropriate recommendation to include in the engagement report?

Options:

A.

Management of business units should review and correct the recovery targets

B.

Conduct an IT function review and correct the recovery targets

C.

Management of the IT function should ensure that the business continuity plan is more realistic

D.

Ensure that in the future business requirements are set by the management of business units

Question 193

Focus An organization has decided to have all employees work from home. Which of the following network types would securely enable this approach?

Options:

A.

A wireless local area network (WLAN ).

B.

A personal area network (PAN).

C.

A wide area network (WAN).

D.

A virtual private network (VPN)

Question 194

Which of the following is an element of effective negotiating?

Options:

A.

Ensuring that the other party has a personal stake in the agreement.

B.

Focusing on interests rather than on obtaining a winning position.

C.

Considering a few select choices during the settlement phase.

D.

Basing the agreement on negotiating power and positioning leverage.

Question 195

In accounting, which of the following statements is true regarding the terms debit and credit?

Options:

A.

Debit indicates the right side of an account and credit the left side

B.

Debit means an increase in an account and credit means a decrease.

C.

Credit indicates the right side of an account and debit the left side.

D.

Credit means an increase in an account and debit means a decrease

Question 196

An organization is considering outsourcing its IT services, and the internal auditor as assessing the related risks. The auditor grouped the related risks into three categories;

- Risks specific to the organization itself.

- Risks specific to the service provider.

- Risks shared by both the organization and the service provider

Which of the following risks should the auditor classify as specific to the service provider?

Options:

A.

Unexpected increases in outsourcing costs.

B.

Loss of data privacy.

C.

Inadequate staffing.

D.

Violation of contractual terms.

Question 197

When should the results of internal quality assessments be communicated to senior management and the board?

Options:

A.

At least once every five years

B.

At least annually

C.

Periodically, at the discretion of the chief audit executive

D.

Only after the results have been validated by an external assessment

Question 198

Which of the following principles are common to both hierarchical and open organizational structures?

    Employees at all levels should be empowered to make decisions.

    A supervisor ' s span of control should not exceed seven subordinates.

    Responsibility should be accompanied by adequate authority.

    A superior cannot delegate the ultimate responsibility for results.

Options:

A.

1 and 2

B.

1 and 4

C.

2 and 3

D.

3 and 4

Question 199

An organization has adopted a bring-your-own-device (BYOD) policy, and employees can access organizational data via their smart devices.

Which of the following authentication policy requirements is the most advisable?

Options:

A.

Require a virtual private network (VPN).

B.

Require at least an eight-digit passcode or a complicated swipe pattern.

C.

Require the remote wipe function and encryption of local data.

D.

Require a passcode followed by a response requiring verification message.

Question 200

Which of the following is an example of a physical control?

Options:

A.

Providing fire detection and suppression equipment

B.

Establishing a physical security policy and promoting it throughout the organization

C.

Performing business continuity and disaster recovery planning

D.

Keeping an offsite backup of the organization ' s critical data

Question 201

Which of the following is a key characteristic of a zero-based budget?

Options:

A.

A zero-based budget provides estimates of costs that would be incurred under different levels of activity.

B.

A zero-based budget maintains focus on the budgeting process.

C.

A zero-based budget is prepared each year and requires each item of expenditure to be justified.

D.

A zero-based budget uses input from lower-level and middle-level managers to formulate budget plans.

Question 202

Which of the following statements is true regarding an investee that received a dividend distribution from an entity and is presumed to have little influence over the entity?

Options:

A.

The cash dividends received increase the investee investment account accordingly.

B.

The investee must adjust the investment account by the ownership interest

C.

The investment account is adjusted downward by the percentage of ownership.

D.

The investee must record the cash dividends as dividend revenue

Question 203

Which of the following backup methodologies would be most efficient in backing up a database in the production environment?

Options:

A.

Disk mirroring of the data being stored on the database.

B.

A differential backup that is performed on a weekly basis.

C.

An array of independent disks used to back up the database.

D.

An incremental backup of the database on a daily basis.

Question 204

Which of the following statements distinguishes a router from a typical switch?

Options:

A.

A router operates at layer two. while a switch operates at layer three of the open systems interconnection model.

B.

A router transmits data through frames, while a switch sends data through packets.

C.

A router connects networks, while a switch connects devices within a network.

D.

A router uses a media access control address during the transmission of data, whie a switch uses an internet protocol address.

Question 205

Which of the following best describes depreciation?

Options:

A.

It is a process of allocating cost of assets between periods.

B.

It is a process of assets valuation.

C.

It is a process of accumulating adequate funds to replace assets.

D.

It is a process of measuring decline in the value of assets because of obsolescence

Question 206

The decision to implement enhanced failure detection and backup systems to improve data integrity is an example of which risk response?

Options:

A.

Risk acceptance.

B.

Risk sharing.

C.

Risk avoidance.

D.

Risk reduction.

Question 207

Which of the following disaster recovery plans includes recovery resources available at the site, but they may need to be configured to support the production system?

Options:

A.

Warm site recovery plan.

B.

Hot site recovery plan.

C.

Cool site recovery plan.

D.

Cold site recovery plan.

Question 208

A small furniture-manufacturing firm with 100 employees is located in a two-story building and does not plan to expand. The furniture manufactured is not special-ordered or custom-made. The most likely structure for this organization would be:

Options:

A.

Functional departmentalization.

B.

Product departmentalization.

C.

Matrix organization.

D.

Divisional organization.

Question 209

Which of the following attributes of data is the most significantly impacted by the internet of things?

Options:

A.

Normalization

B.

Velocity

C.

Structuration

D.

Veracity

Question 210

What is the primary purpose of data and systems backup?

Options:

A.

To restore all data and systems immediately after the occurrence of an incident.

B.

To set the maximum allowable downtime to restore systems and data after the occurrence of an incident.

C.

To set the point in time to which systems and data must be recovered after the occurrence of an incident.

D.

To restore data and systems to a previous point in time after the occurrence of an incident

Question 211

To assess the effectiveness of an organization ' s privacy program, which of the following approaches should an internal auditor take?

Options:

A.

Conduct a series of employee interviews.

B.

Conduct penetration tests.

C.

Review privacy policies and procedures.

D.

Analyze the life cycle of sensitive data.

Question 212

If the chief audit executive (CAE) observes that an international wire was approved to transfer funds to a country embargoed by the government, which of the following would be the most appropriate first step for the CAE to take?

Options:

A.

Track the wire and perform ongoing monitoring

B.

Discuss the issue with management

C.

Immediately report the transaction to the regulatory authorities

D.

Report the transaction to the audit committee

Question 213

Which of the following are likely indicators of ineffective change management?

    IT management is unable to predict how a change will impact interdependent systems or business processes.

    There have been significant increases in trouble calls or in support hours logged by programmers.

    There is a lack of turnover in the systems support and business analyst development groups.

    Emergency changes that bypass the normal control process frequently are deemed necessary.

Options:

A.

1 and 3 only

B.

2 and 4 only

C.

1, 2, and 4 only

D.

1, 2, 3, and 4

Question 214

If legal or regulatory standards prohibit conformance with certain parts of The IIA ' s Standards, the auditor should do which of the following?

Options:

A.

Conform with all other parts of The IIA ' s Standards and provide appropriate disclosures.

B.

Conform with all other parts of The IIA ' s Standards; there is no need to provide appropriate disclosures.

C.

Continue the engagement without conforming with the other parts of The IIA ' s Standards.

D.

Withdraw from the engagement.

Question 215

Which of the following corporate social responsibility strategies is likely to be most effective in minimizing confrontations with influential activists and lobbyists?

Options:

A.

Continually evaluate the needs and opinions of all stakeholder groups.

B.

Ensure strict compliance with applicable laws and regulations to avoid incidents.

C.

Maintain a comprehensive publicity campaign that highlights the organization ' s efforts.

D.

Increase goodwill through philanthropic activities among stakeholder communities.

Question 216

Which of the following statements is true regarding internal audit methodologies?

Options:

A.

One of the main objectives of internal audit methodologies is to enable audit clients to validate audit observations

B.

IIA guidance states that they should be made available to all stakeholders on the organization’s webpage

C.

One of the main objectives of internal audit methodologies is to ensure the execution of organizational strategy and risk management

D.

Although the content of internal audit methodologies is determined by the chief audit executive, alignment with principles of confidentiality and competency must be demonstrated

Question 217

Which of the following can be classified as debt investments?

Options:

A.

Investments in the capital stock of a corporation

B.

Acquisition of government bonds.

C.

Contents of an investment portfolio,

D.

Acquisition of common stock of a corporation

Question 218

Which of the following documents would provide an internal auditor with information on the length of time to maintain documents after the completion of an engagement?

Options:

A.

Internal audit charter

B.

Annual internal audit plan

C.

Internal audit policies

D.

Quality assurance and improvement program

Question 219

Which of the following is the most appropriate way to record each partner’s initial investment in a partnership?

Options:

A.

At the value agreed upon by the partners

B.

At book value

C.

At fair value

D.

At the original cost

Question 220

A chief audit executive (CAE) joined an organization in the middle of the financial year. A risk-based annual audit plan has been approved by the board and is already underway. However, after discussions with key stakeholders, the CAE realizes that some significant key risk areas have not been covered in the original audit plan. How should the CAE respond?

Options:

A.

Commit to delivering the original annual audit plan as it has already been approved by the board

B.

Revise the plan to incorporate the newly identified risks, and communicate significant interim changes to senior management and the board for review and approval

C.

Ensure that the newly identified risks are included in the next year ' s annual audit plan

D.

Assign internal auditors to immediately perform assurance engagements in the areas where the new risks have been identified, due to their significance

Question 221

According to the Standards, the internal audit activity must evaluate risk exposures relating to which of the following when examining an organization ' s risk management process?

    Organizational governance.

    Organizational operations.

    Organizational information systems.

    Organizational structure.

Options:

A.

1 and 3 only

B.

2 and 4 only

C.

1, 2, and 3 only

D.

1, 2, and 4 only

Question 222

Maintenance cost at a hospital was observed to increase as activity level increased. The following data was gathered:

January: 5,600 patient days; maintenance cost $7,900

February: 7,100 patient days; maintenance cost $8,500

March: 5,000 patient days; maintenance cost $7,400

April: 6,500 patient days; maintenance cost $8,200

May: 7,300 patient days; maintenance cost $9,100

June: 8,000 patient days; maintenance cost $9,800

If the cost of maintenance is expressed in an equation, what is the independent variable for this data?

Options:

A.

Fixed cost.

B.

Variable cost.

C.

Total maintenance cost.

D.

Patient days.

Question 223

An Internal auditor is using data analytics to focus on high-risk areas during an engagement. The auditor has obtained data and is working to eliminate redundancies in the data. Which of the following statements is true regarding this scenario?

Options:

A.

The auditor is normalizing data in preparation for analyzing it.

B.

The auditor is analyzing the data in preparation for communicating the results,

C.

The auditor is cleaning the data in preparation for determining which processes may be involves .

D.

The auditor is reviewing trio data prior to defining the question

Question 224

Which of the following items represents a limitation with an impact the chief audit executive should report to the board?

Options:

A.

Audit procedures

B.

Reporting forms

C.

Available skills

D.

Available methods

Question 225

In an organization that produces chocolate, the leadership team decides that the organization will open a milk production facility for its milk chocolate. Which of the following strategies have the organization chosen?

Options:

A.

Vertical integration.

B.

Unrelated diversification.

C.

Differentiation

D.

Focus

Question 226

An internal auditor for a pharmaceutical company as planning a cybersecurity audit and conducting a risk assessment. Which of the following would be considered the most significant cyber threat to the organization?

Options:

A.

Cybercriminals hacking into the organization ' s time and expense system to collect employee personal data.

B.

Hackers breaching the organization ' s network to access research and development reports

C.

A denial-of-service attack that prevents access to the organization ' s website.

D.

A hacker accessing she financial information of the company

Question 227

An organization is projecting sales of 100,000 units, at a unit price of $12. Unit variable costs are $7. If fixed costs are $350,000, what is the projected total contribution margin?

Options:

A.

$350,000

B.

$500,000

C.

$850,000

D.

$1,200,000

Question 228

An internal auditor reviews a data population and calculates the mean, median, and range. What is the most likely purpose of performing this analytic technique?

Options:

A.

To inform the classification of the data population.

B.

To determine the completeness and accuracy of the data.

C.

To identify whether the population contains outliers.

D.

To determine whether duplicates in the data inflate the range.

Question 229

Which of the following factors is considered a disadvantage of vertical integration?

Options:

A.

It may reduce the flexibility to change partners.

B.

It may not reduce the bargaining power of suppliers.

C.

It may limit the organization ' s ability to differentiate the product.

D.

It may lead to limited control of proprietary knowledge.

Question 230

Which of the following would be classified as IT general controls?

Options:

A.

Error listings.

B.

Distribution controls.

C.

Transaction logging.

D.

Systems development controls.

Question 231

Which of the following scenarios best illustrates a spear phishing attack?

Options:

A.

Numerous and consistent attacks on the company ' s website caused the server to crash and service was disrupted.

B.

A person posing as a representative of the company’s IT help desk called several employees and played a generic prerecorded message requesting password data.

C.

A person received a personalized email regarding a golf membership renewal, and he click a hyperlink to enter his credit card data into a fake website

D.

Many users of a social network service received fake notifications of e unique opportunity to invest in a new product.

Question 232

An organization ' s account for office supplies on hand had a balance of $9,000 at the end of year one. During year two. The organization recorded an expense of $45,000 for purchasing office supplies. At the end of year two. a physical count determined that the organization has $11 ,500 in office supplies on hand. Based on this Information, what would he recorded in the adjusting entry an the end of year two?

Options:

A.

A debit to office supplies on hand for S2.500

B.

A debit to office supplies on hand for $11.500

C.

A debit to office supplies on hand for $20,500

D.

A debit to office supplies on hand for $42,500

Question 233

According to IIA guidance, which of the following corporate social responsibility evaluation activities may be performed by the internal audit activity?

    Consult on CSR program design and implementation.

    Serve as an advisor on CSR governance and risk management.

    Review third parties for contractual compliance with CSR terms.

    Identify and mitigate risks to help meet the CSR program objectives.

Options:

A.

1, 2, and 3

B.

1, 2, and 4

C.

1, 3, and 4

D.

2, 3, and 4

Question 234

Which of the following is a characteristic of big data?

Options:

A.

Big data is being generated slowly due to volume.

B.

Big data must be relevant for the purposes of organizations.

C.

Big data comes from a single type of formal.

D.

Big data is always changing

Question 235

When using data analytics during a review of the procurement process, what is the first step in the analysis process?

Options:

A.

Identify data anomalies and outliers

B.

Define questions to be answered

C.

Identify data sources available

D.

Determine the scope of the data extract

Question 236

A software that translates hypertext markup language (HTML) documents and allows a user to view a remote web page is called:

Options:

A.

A transmission control protocol/Internet protocol (TCP/IP).

B.

An operating system.

C.

A web browser.

D.

A web server.

Question 237

According to the waterfall cycle approach to systems development, which of the following sequence of events is correct?

Options:

A.

Program design, system requirements, software design, analysis, coding, testing, operations.

B.

System requirements, software design, analysis, program design, testing, coding, operations.

C.

System requirements, software design, analysis, program design, coding, testing, operations.

D.

System requirements, analysis, coding, software design, program design, testing, operations.

Page: 1 / 79
Total 791 questions