Free IIA IIA-CIA-Part2 Practice Questions 2026 - Page 14

Timed Practice Test

Ready for IIA-CIA-Part2 Exam?

This practice test is your final exam before the REAL exam
Dare to Take It?




Practice Questions

Which of the following best describes the guideline for preparing audit engagement workpapers?

A. Workpapers should be understandable to the auditor in charge and the chief audit executive

B. Workpapers should be understandable to the audit client and the board.

C. Workpapers should be understandable to another internal auditor who was not involved in the engagement.

D. Workpapers should be understandable to external auditors and regulatory agencies

C.   Workpapers should be understandable to another internal auditor who was not involved in the engagement.

When estimating the impact of an inherent risk, which of the following should internal auditors consider?

A. The probability and frequency of occurrence

B. Financial and nonfinancial factors related to the risk

C. The number of risks identified on the heat map

D. The residual risk following implementation of appropriate controls

B.   Financial and nonfinancial factors related to the risk

Which of the following is more likely to be present in a highly centralized organization?

A. The ability to make rapid changes

B. Micromanagement

C. Empowered employees

D. Authority pushed downward

B.   Micromanagement

An internal auditor has discovered that duplicate payments were made to one vendor Management has recouped the duplicate payments as a corrective action Which of the following describes managements action in this case?

A. A condition-based action plan

B. A cause-based action plan.

C. A root cause-based action plan.

D. An effect-based action plan.

D.   An effect-based action plan.

Which of the following computerized audit tools or techniques should be used if the internal auditor wants to extract specific files and records in the database?

A. An expert or decision support system

B. Generalized audit software

C. A system utility program

D. An integrated test facility

B.   Generalized audit software

An internal auditor finds inconsistencies in a risk area that needs immediate attention. Which of the following actions is most appropriate for the auditor?

A. Prepare an action plan to address the inconsistencies

B. Contact regulatory agencies to report the inconsistencies and recommended corrective actions

C. Assess the risk of the inconsistencies against the organization's mission

D. Issue an interim report to senior management

D.   Issue an interim report to senior management

According to IIA guidance, which of the following factors should the auditor in charge consider when determining the resource requirements for an audit engagement?

A. The number, experience, and availability of audit staff as well as the nature, complexity, and time constraints of the engagement.

B. The appropriateness and sufficiency of resources and the ability to coordinate with external auditors.

C. The number, proficiency, experience, and availability of audit staff as well as the ability to coordinate with external auditors.

D. The appropriateness and sufficiency of resources as well as the nature, complexity, and time constraints of the engagement.

A.   The number, experience, and availability of audit staff as well as the nature, complexity, and time constraints of the engagement.

Management requested internal audit consulting services. During fieldwork significant control issues were identified by the internal audit team. Which of the following is an appropriate response from the chief audit executive?

A. End the consulting engagement and report the results to management as planned

B. Report the significant control issues to senior management and the board and recommend corrective action

C. Mutually agree with the engagement client on corrective actions

D. Focus on the consulting engagement and schedule an assurance engagement next to address the control issues

B.   Report the significant control issues to senior management and the board and recommend corrective action

Which of the following best describes the engagement objective in a banking compliance audit?

A. Assessing the cost-efficiency of business continuity plans

B. Assessing whether the business continuity plans implement regulatory requirements

C. Assessing whether the business continuity plans implement best practice recommendations

D. Assessing the operating effectiveness of the business continuity plans

B.   Assessing whether the business continuity plans implement regulatory requirements

A large retail organization, which sells most of its products online, experiences a computer hacking incident. The chief IT officer immediately investigates the incident and concludes that the attempt was not successful. The chief audit executive (CAE) learns of the attack in a casual conversation with an IT auditor. Which of the following actions should the CAE take?

1. Meet with the chief IT officer to discuss the report and control improvements that will be implemented as a result of the security breach, if any.

2. Immediately inform the chair of the audit committee of the security breach, because thus far only the chief IT officer is aware of the incident.

3. Meet with the IT auditor to develop an appropriate audit program to review the organization's Internet-based sales process and key controls.

4. Include the incident in the next quarterly report to the audit committee.

A. 1 and 2

B. 1 and 3

C. 2 and 4

D. 3 and 4

B.   1 and 3

Page 14 out of 72 Pages