Free IIA IIA-CIA-Part2 Practice Questions 2026 - Page 20

Timed Practice Test

Ready for IIA-CIA-Part2 Exam?

This practice test is your final exam before the REAL exam
Dare to Take It?




Practice Questions

A rapidly expanding retail organization continues to be tightly controlled by its original small management team. Which of the following is a potential risk in this vertically centralized organization?

A. Lack of coordination among different business units

B. Operational decisions are inconsistent with organizational goals.

C. Suboptimal decision-making.

D. Duplication of business activities.

C.   Suboptimal decision-making.

What is the purpose of an internal control questionnaire?

A. To gather information from a sample of people who are geographically dispersed

B. To assess risks that could prevent an audited area from achieving its objectives.

C. To evaluate tie level of compliance of remote offices with centrally designed procedures

D. To perform testing of controls more frequently

B.   To assess risks that could prevent an audited area from achieving its objectives.

An internal auditor examined a nostatistical sample of open accounts receivable balances and discovered that 10 out of 60 exceeded the approved unseated credit limit threshold defined by the organization's policy What should the auditor document in the workpapers?

A. Credit limit over drafts are not monitored in accordance with the organizations policy

B. Seventeen percent of customers' open balances in the sample exceed their approved unsecured credit rent

C. The threshold for credit limits defined by the organization's policy is not adequate

D. Management should perform monthly monitoring of open customer balances

B.   Seventeen percent of customers' open balances in the sample exceed their approved unsecured credit rent

Which of the following is an advantage of utilizing an external fraud specialist in a suspected fraud investigation?

A. Increased access to the organization’s employees.

B. Increased ability to preserve evidence and the chain of command.

C. Increased ability to scrutinize the organization's key business processes.

D. Increased access to the organization’s software and proprietary data.

B.   Increased ability to preserve evidence and the chain of command.

To effectively communicate the acceptance of risk in an organization a chief audit executive must first consider which of the following?

A. The organization's view on risk tolerance

B. The organization's principal risk events.

C. The organization's risk response strategies

D. The organization's major control activities

A.   The organization's view on risk tolerance

Which of the following statements is false regarding roles and responsibilities pertaining to risk management and control?

A. Senior management is charged with overseeing the establishment risk management and control processes.

B. The chief audit executive is responsible for overseeing the evaluation risk management and control processes.

C. Operating managers are responsible for assessing risks and controls in their departments.

D. Internal auditors provide assurance about risk management and control process effectiveness.

A.   Senior management is charged with overseeing the establishment risk management and control processes.

The chief audit executive of an international organization is planning an audit of the treasury function located at the organization's headquarters. The current internal audit team at headquarters lacks expertise in the area of financial markets which is needed tor the engagement When of the following would be the most approbate solution considering the time constraint?

A. Outsource the engagement 10 tie organization's external auditor who has expertise in the area of financial markets

B. Hire additional internal auditors who have expertise in the area of financial markets.

C. Invite a guest auditor from one of the organization's affiliates who has expertise m the area of financial markets.

D. Limit the scope of the engagement to the knowledge and skills possessed by the internal audit team.

C.   Invite a guest auditor from one of the organization's affiliates who has expertise m the area of financial markets.

During follow-up, the chief audit executive (CAE) is having a discussion with management about the internal audit team's recommendations related to a significant issue Management accepted the issue but took no remedial action What is the next step for the CAE?

A. The CAE should reassess and validate the risk tolerance policy

B. The CAE should escalate the issue to senior management .

C. The CAE should reiterate the internal audit team's recommendations to management .

D. The CAE should grant management more time to implement the recommendation and check the status of the issue during the next scheduled follow-up.

B.   The CAE should escalate the issue to senior management .

During an organization’s management meetings, employees who report bad news and significant risks are treated as if they were to blame for those circumstances. As a result, employees tend to postpone delivering bad news to management for as long as possible. Which of the following should be addressed to improve this culture?

A. Tone at the top

B. Risk accountability

C. Risk leadership

D. Code of ethics

A.   Tone at the top

An internal auditor reviewed bank reconciliations prepared by management of the area under review. The auditor noted that the bank statements attached did not have the bank heading, logo, or address. Which of the following statements is true regarding this situation?

A. The evidence may not be reliable.

B. The evidence is not relevant.

C. The evidence may not be sufficient.

D. The information missing is not relevant to the audit.

A.   The evidence may not be reliable.

Page 20 out of 72 Pages