Free IIA IIA-CIA-Part2 Practice Questions 2026 - Page 17

Timed Practice Test

Ready for IIA-CIA-Part2 Exam?

This practice test is your final exam before the REAL exam
Dare to Take It?




Practice Questions

An internal auditor submitted a report containing recommendations for management to enhance internal controls related to investments. To follow up, which of the following is the most appropriate action for the internal auditor to take?

A. Observe corrective measures.

B. Seek a management assurance declaration.

C. Follow up during the next scheduled audit.

D. Conduct appropriate testing to verify management responses.

D.   Conduct appropriate testing to verify management responses.

An internal auditor is planning to audit the organization's payroll function, which was recently outsourced. Which of the following is the most appropriate first step for the auditor?

A. Review management's organ nationwide risk assessment

B. Understand the objectives and strategies of the new arrangement

C. Revise the scope of the audit engagement

D. Form objectives for the audit engagement

B.   Understand the objectives and strategies of the new arrangement

Which of the following is an effective approach for internal auditors to take to improve collaboration with audit clients during an engagement?

1. Obtain control concerns from the client before the audit begins so the internal auditor can tailor the scope accordingly.

2. Discuss the engagement plan with the client so the client can understand the reasoning behind the approach.

3. Review test criteria and procedures where the client expresses concerns about the type of tests to be conducted.

4. Provide all observations at the end of the audit to ensure the client is in agreement with the facts before publishing the report.

A. 1 and 2 only

B. 1 and 4 only

C. 2 and 3 only

D. 3 and 4 only

C.   2 and 3 only

In the following risk control map risks have been categorized based on the level of significance and the associated level of control. Which of the following statements is true regarding Risk C?

A. The level of control is appropriate given the level of risk

B. The level of control is excessive given the level of risk

C. The level of control is inadequate given the level of risk

D. There is not enough of information to determine whether the controls are appropriate or not

C.   The level of control is inadequate given the level of risk

The audit plan of an internal audit function includes an assurance engagement of the organization’s cybersecurity protocols. However, the engagement supervisor assigned to execute the engagement identifies that the internal auditors with competencies in cybersecurity are scheduled for upcoming leave and are involved in other engagements. Those auditors would not be available to participate in the cybersecurity engagement. Which of the following would be the appropriate action for the engagement supervisor?

A. Reassign the competent auditors immediately.

B. Notify the board that the cybersecurity engagement cannot be performed due to a lack of competent resources.

C. Suspend the cybersecurity engagement due to the lack of internal auditors with relevant competencies.

D. Seek advice from the chief audit executive on appropriate actions related to the cybersecurity engagement.

D.   Seek advice from the chief audit executive on appropriate actions related to the cybersecurity engagement.

A manager has allowed a subordinate employee to have greater control and responsibility over the tasks that he performs This is an example of which of the following?

A. Job enlargement

B. Job enrichment

C. Horizontal loading of the job.

D. Job rotation.

B.   Job enrichment

Which of the following would not be a typical activity for the chief audit executive to perform following an audit engagement?

A. Report follow-up activities to senior management.

B. Implement follow-up procedures to evaluate residual risk.

C. Determine the costs of implementing the recommendations.

D. Evaluate the extent of improvements.

C.   Determine the costs of implementing the recommendations.

The chief audit executive can illustrate the value of the internal audit activity by reporting which of the following to the board?

A. The overall performance resulting from the internal audit balanced scorecard

B. The number of outstanding and overdue management actions

C. The experience of the organization's internal auditors

D. The number of audits in the annual audit plan relative to similar organizations

A.   The overall performance resulting from the internal audit balanced scorecard

According to IIA guidance, which of the following statements best justifies a chief audit executive's request for external consultants to complement internal audit activity (IAA) resources?

A. The organization's audit universe is extensive and diverse.

B. There has been an increase in unanticipated requests for advisory work.

C. Previous work provided by the external service provider has been of great quality and value.

D. A recent benchmarking study found that using external service providers is a common practice of similarly-sized IAAs in other organizations.

A.   The organization's audit universe is extensive and diverse.

During planning, the chief audit executive submits a risk-and-control questionnaire to management of the activity under review. Which of the following statements is true regarding the questionnaire?

A. It would be an inefficient way for internal auditors to address multiple controls in the activity under review.

B. It would limit certain members of the internal audit team from being fully involved in the engagement.

C. It would be the most effective way for the internal audit team to obtain a detailed understanding of the processes and controls in the activity to be audited.

D. It would be an efficient way for the internal audit team to determine whether specified control activities are in place.

D.   It would be an efficient way for the internal audit team to determine whether specified control activities are in place.

Page 17 out of 72 Pages