Free IIA IIA-CIA-Part1 Practice Questions 2026 - Page 20
Ready for IIA-CIA-Part1 Exam?
This practice test is your final exam before the REAL exam
Dare to Take It?
Practice Questions
Topic 1: Volume A
Which of the following statements is true regarding the internal audit activity's quality assurance and improvement program (QAIP)?
A. The QAIP scope includes assurance work performed by the internal audit activity but not consulting work.
B. The QAIP verifies conformance with the Definition of Internal Auditing, Code of Ethics, and Standards.
C. QAIP reports are for internal use primarily and typically are not shared with members outside of the internal audit activity.
D. QAIPs make a distinction between fully outsourced internal audit activities and in-house internal audit teams, as a different set of criteria is applied for each.
Which of the following statements is the most appropriate example of the internal audit activity exercising due professional care during an audit of the payroll department?
A. Internal auditors ensure that the work program is appropriately designed in order to identify all of the risks surrounding the payroll process.
B. Internal auditors determine whether the policies, procedures, and practices of the payroll department are operating in accordance with relevant laws.
C. Internal auditors verify whether the board of directors has implemented effective internal controls over the processes used by the payroll department.
D. Internal auditors ask the organization's risk manager to determine whether the degree of work planned is sufficient to determine whether payroll payments were complete and accurate.
Senior management purchased surveillance cameras and installed them over a door that provides entry to an area where according to a recent internal audit report, hazardous materials exist and there is a high risk of explosion Which type of control was implemented in this situation?
A. A corrective control
B. A detective control
C. A preventive control
D. A directive control
In which of the following situations may the internal audit activity report conformance with the Standards?
A. An internal audit activity has been in existence at least five years and has not completed an external assessment,
B. An internal auditor was assigned to an audit engagement but did not meet individual objectivity requirements.
C. The internal audit activity prepared an internal audit plan that was not risk-based.
D. The internal audit activity has been in existence fewer than five years, but periodic selfassessments were conducted.
Which of the following is a strategic risk that internal auditors should consider when performing a third-party risk management engagement?
A. Physical security
B. Loss of intellectual property
C. Cost overruns
D. Conflict of interest
An internal auditor is reviewing employee travel expenses from the previous six months for fraud. Which of the following tests would best detect instances where personal travel has been claimed?
A. Verifying whether claims have been properly authorized for payment
B. Verifying whether claims are properly supported by invoices or other documents.
C. Confirming that all claims are within the limits of the organization's travel policy.
D. Reconciling claims against business the requests that were approved by supervisors
Which data analytics competency is critical for new internal auditors to possess in order to plan and perform internal audit engagements in conformance with the Standards?
A. Describe data analytics and the application of data analytics methods in internal auditing.
B. Apply data analytics methods in internal auditing.
C. Evaluate the use of data analytics in an internal audit.
D. Understand the definition of data analytics only.
A chief audit executive has reported to the board that the internal audit activity is lacking financial accounting knowledge for specific audit projects. Upon approval from the board which of the following hiring approaches is best in this situation?
A. An inbound rotational program
B. A full-time permanent recruitment
C. An outbound rotational program
D. A guest auditor program
Which of the following types of fraud tests would be most effective if an internal auditor was looking for possible fictitious vendors?
A. Checking for invoice amounts that do not match that of the purchase order.
B. Searching for identical invoice numbers and payment amounts.
C. Running checks to uncover post office box addresses matching employee addresses.
D. Comparing prices across vendors to see whether one vendor is unreasonably high.
If an internal auditor suspects fraud during an engagement which of the following is expected of the auditor?
A. Evaluate the suspected activities to determine whether a forma! investigation is warranted,
B. Immediately inform senior management and the board of the suspected fraud.
C. Ascertain the level of resources needed to formally investigate the fraud, and proceed with the investigation if resources permit,
D. Include in the engagement documentation all possible effects and the potential impact of the fraud to the organization
| Page 20 out of 73 Pages |