Free IIA IIA-CIA-Part2 Practice Questions 2026 - Page 19
Ready for IIA-CIA-Part2 Exam?
This practice test is your final exam before the REAL exam
Dare to Take It?
Practice Questions
The engagement supervisor would like lo change the audit program's scope poor to beginning fieldwork According to IIA guidance before any change is implemented what is the most important action that should be undertaken?
A. Document in the engagement workpapers the rationale for changing the scope.
B. Confirm that the scope change would align to the organization's objectives and goals
C. Confirm that the internal audit activity continues to have the necessary knowledge and skills
D. Seek approval from the chief audit executive for the proposed scope change
According to IIA guidance, which of the following statements regarding the internal audit charter is true?
A. The nature of consulting services typically is not included in the charter.
B. The chief audit executive must formally review the charter at least once a year
C. The nature of assurances provided to parties outside of the organization typically is not included in the charter.
D. The charter typically defines the internal audit activity’s position within the organization.
An organization does not have a formal risk management function. According to the
Standards, which of the following are conditions where the internal audit activity may
provide risk management consulting?
1.There is a clear strategy and timeline to migrate risk management responsibility back to
management.
2.The internal audit activity has the final approval on any risk management decisions.
3.The internal audit activity gives objective assurance on all parts of the risk management
framework for which it is responsible.
4.The nature of services provided to the organization is documented in the internal audit
charter.
A. 1 and 4 only.
B. 2 and 4 only.
C. 1 and 3 only.
D. 2 and 3 only.
A team of internal auditors is assigned to audit the employee relations process in an organization, which includes employee conduct and disciplinary hearings. Which of the following audit approaches would provide the auditors with the best evidence to determine the degree to which disciplinary decisions are complying with documented policy?
A. Review a random sample of concluded disciplinary reports to assess how the policy was applied in each case.
B. Interview a sample of impacted employees for their opinions on the clarity and fairness of the policy.
C. Observe several disciplinary hearings to determine whether they are in compliance with the policy.
D. Conduct an interview to assess the disciplinary hearing chairman’s understanding of the policy and its appropriate use.
According to IIA guidance, when of the Mowing statements is true regarding an engagement supervisor's use of review notes?
A. The engagement supervisor's review notes should be retained m the final documental or even after they are addressed.
B. The engagement supervisor's review notes cannot be used as evidence of engagement supervision
C. The engagement supervisor's review notes could be cleared from all final documentation after they are addressed
D. The engagement supervisor's review notes must be maintained in a checklist separate from tie final documentation
An internal auditor and engagement client are deadlocked over the auditor's differing opinion with management on the adequacy of access controls for a major system. Which of the following strategies would be the most helpful in resolving this dispute?
A. Conduct a joint brainstorming session with management.
B. Ask the chief audit executive to mediate.
C. Disclose the client's differing opinion in the final report.
D. Escalate the issue to senior management for a decision.
Which of the following is an appropriate responsibility for the internal audit activity with regard to the organization's risk management program?
A. Identifying and managing risks in line with the entity's risk appetite.
B. Ensuring that a proper and effective risk management process exists.
C. Attaining an adequate understanding of the entity's key mitigation strategies.
D. Identifying and ensuring that appropriate controls exist to mitigate risks.
According to IIA guidance, which of the following is a limitation of a heat map?
A. Impact cannot be represented on a heat map unless it is quantified in financial terms.
B. Impact and likelihood at times cannot be differentiated as to which is more important.
C. A heat map cannot be used unless a risk and control matrix has been developed.
D. Qualitative factors cannot be incorporated into a heat map.
According to IIA guidance, which of the following statements is true regarding engagement planning?
A. For both assurance and consulting engagements, planning typically occurs after the engagement objectives and scope have already been determined.
B. The expectations and objectives of an assurance engagement are usually determined by, or in conjunction with, the engagement client.
C. Internal auditors may not need to complete a preliminary risk assessment for a consulting engagement as they would when planning an assurance engagement.
D. For both consulting and assurance engagements, internal auditors usually form the engagement objectives prior to completing the preliminary risk assessment.
Which of the following would best prevent phishing attacks on an organization?
A. An intrusion detection system
B. Use of firewalls
C. Regular security awareness training
D. Application hardening
| Page 19 out of 72 Pages |