Free IIA IIA-CIA-Part3 Practice Questions 2026 - Page 10

Timed Practice Test

Ready for IIA-CIA-Part3 Exam?

This practice test is your final exam before the REAL exam
Dare to Take It?




Practice Questions

Which of the following physical access control is most likely to be based on ’’something you have" concept?

A. A retina characteristics reader

B. A P3M code reader

C. A card-key scanner

D. A fingerprint scanner

C.   A card-key scanner

Explanation:

Physical access controls are categorized based on the three authentication factors:

Something you know (e.g., PIN, password)
Something you have (e.g., card-key, token, smart card, key fob)
Something you are (e.g., fingerprint, retina, voice)

A card-key scanner reads a physical credential (an access card or proximity card) that the user must possess to gain entry. This is the classic example of a "something you have" factor, as the user presents a tangible item that contains encoded identification data. The scanner validates the card's credentials and grants access if authorized.

Why the other options are incorrect:

A. A retina characteristics reader. This is a biometric control based on "something you are"—the unique pattern of blood vessels in the retina. It does not rely on possession.

B. A PIN code reader. This is based on "something you know"—a numeric secret that the user must memorize and enter. It is a knowledge-based factor, not possession-based.

D. A fingerprint scanner. This is another biometric control based on "something you are"—the unique ridge pattern of a fingerprint. It is not based on possession.

References:

IIA GTAG – Information Security Governance: Defines the three authentication factors—knowledge, possession, and inherence—and categorizes card-key readers as possession-based controls.

What is the primary purpose of an Integrity control?

A. To ensure data processing is complete, accurate, and authorized.

B. To ensure data being processed remains consistent and intact.

C. To ensure data being processed remains consistent and intact.

D. To ensure the output aligns with the intended result.

B.   To ensure data being processed remains consistent and intact.

Explanation:

An integrity control is designed to protect data from unauthorized modification, corruption, or loss during processing, storage, or transmission. Its primary purpose is to ensure that data remains consistent, accurate, and intact throughout its lifecycle. Integrity controls include mechanisms such as checksums, hashing, parity checks, reconciliation, and edit checks to detect and prevent data alteration or errors. In the context of the CIA Triad (Confidentiality, Integrity, Availability), integrity is specifically about preserving the trustworthiness and completeness of data.

Why the other options are incorrect:

A. To ensure data processing is complete, accurate, and authorized. This is a broader description of application controls in general (encompassing completeness, accuracy, and authorization), not specifically the primary purpose of integrity controls. Integrity controls focus on maintaining data consistency, not all three objectives.

C. To ensure data being processed remains consistent and intact. (This is identical to B.) Since B is the correct answer, C is a duplicate and not a separate valid option.

D. To ensure the output aligns with the intended result. This describes validation or output controls (verifying that outputs are correct), not the specific purpose of integrity controls. Integrity focuses on the data itself during processing, not just final outputs.

References:

IIA GTAG – Information Security Governance: Defines integrity controls as mechanisms to ensure data is not altered or destroyed and remains complete and accurate throughout processing.

IIA CIA Part 3 Syllabus – IT / Security Controls: Tests the candidate's understanding of the CIA Triad, where integrity is specifically about maintaining data consistency and intactness.

Which of the following situations best illustrates a "false positive" in the performance of a spam filter?

A. The spam filter removed Incoming communication that included certain keywords and domains.

B. The spam filter deleted commercial ads automatically, as they were recognized as unwanted.

C. The spam filter routed to the "junk|r folder a newsletter that appeared to include links to fake websites.

D. The spam filter blocked a fitness club gift card that coworkers sent to an employee for her birthday.

D.   The spam filter blocked a fitness club gift card that coworkers sent to an employee for her birthday.

Explanation:

A "false positive" occurs when a security control (like a spam filter) incorrectly identifies a legitimate item as malicious or unwanted and takes action against it (e.g., blocks it or routes it to junk). In this scenario, the spam filter blocked a legitimate email—a gift card sent by coworkers for a birthday—mistakenly classifying it as spam. This is a classic false positive because the email was genuine and desired, yet it was incorrectly flagged and blocked.

Why the other options are incorrect:

A. The spam filter removed incoming communication that included certain keywords and domains.
This is a correct action based on predefined rules. If the keywords/domains are known spam indicators, this is a true positive (correctly identified spam), not a false positive.

B. The spam filter deleted commercial ads automatically, as they were recognized as unwanted.
This is also a true positive—commercial ads are typically unwanted and correctly classified as spam. The filter performed as intended.

C. The spam filter routed to the 'junk' folder a newsletter that appeared to include links to fake websites.
If the links were indeed suspicious or fake, this is a true positive—the filter correctly identified a potentially harmful newsletter. Even if the newsletter was legitimate but contained compromised links, the filter acted correctly.

References:

IIA GTAG – Information Security Governance: Defines false positives as instances where a security control incorrectly flags legitimate activity as a threat, leading to unnecessary disruptions and reduced user trust.

Which of the following risks would Involve individuals attacking an oil company's IT system as a sign of solidarity against drilling in a local area?

A. Tampering

B. Hacking

C. Phishing

D. Piracy

B.   Hacking

Explanation:

Hacking refers to unauthorized access, intrusion, or attacks on computer systems, networks, or digital infrastructure with the intent to disrupt, damage, steal information, or make a political or ideological statement. In this scenario, individuals attack the oil company's IT system as a sign of solidarity against drilling—this is a classic example of hacktivism (a form of hacking driven by political, social, or environmental motives). The attackers are deliberately breaching or disrupting the company's systems to advance their cause, which falls squarely under the definition of hacking.

Why the other options are incorrect:

A. Tampering. This involves unauthorized alteration or manipulation of data, systems, or physical assets (e.g., modifying records, damaging equipment). While hacking may include tampering, the scenario describes the act of attacking the IT system itself as a political statement, which is hacking—not specifically tampering.

C. Phishing. This is a social engineering attack where attackers deceive individuals into revealing sensitive information (e.g., passwords, credit card numbers) via fraudulent emails or messages. The scenario does not involve deception or credential theft; it involves a direct attack on the IT system as an act of solidarity.

D. Piracy. This typically refers to unauthorized copying, distribution, or use of copyrighted software, media, or intellectual property. It does not involve attacking IT systems for political or environmental protest.

References:

IIA GTAG – Information Security Governance: Defines hacking as unauthorized access or intrusion into systems, often motivated by financial gain, espionage, or activism (hacktivism).

CIA Part 3 Syllabus – IT / Cybersecurity Threats: Tests the candidate's understanding of different threat types, including hacking, phishing, malware, and social engineering, and their distinguishing characteristics.

How do data analysis technologies affect internal audit testing?

A. They improve the effectiveness of spot check testing techniques.

B. They allow greater insight into high risk areas.

C. They reduce the overall scope of the audit engagement,

D. They increase the internal auditor's objectivity.

B.   They allow greater insight into high risk areas.

Explanation:

Data analysis technologies (e.g., data mining, continuous monitoring, visualization, and predictive analytics) enable internal auditors to analyze entire populations of data rather than relying solely on small samples. This provides greater insight into high-risk areas by identifying anomalies, patterns, outliers, and correlations that may not be visible through traditional sampling techniques. Auditors can stratify data, perform trend analysis, and focus their testing on the transactions or processes that pose the highest risk, thereby enhancing both the effectiveness and efficiency of the audit. The primary value of data analytics is its ability to uncover deeper, risk-relevant insights that drive audit focus and improve assurance quality.

Why the other options are incorrect:

A. They improve the effectiveness of spot check testing techniques.
Data analytics reduces reliance on spot checks and sampling by allowing full-population testing. Spot checks are a traditional, less effective technique that analytics often supplements or replaces.

C. They reduce the overall scope of the audit engagement.
Data analytics does not reduce the audit scope; rather, it may expand or refocus the scope by identifying new risk areas that warrant investigation. It improves coverage, not scope reduction.

D. They increase the internal auditor's objectivity.
Objectivity is a matter of auditor independence and mindset, not a direct result of using data analysis tools. While analytics may reduce bias in sample selection, objectivity is governed by professional standards and personal conduct, not technology.

References:

IIA GTAG – Data Analysis Technologies: Emphasizes that data analytics enables auditors to analyze entire datasets, identify high-risk transactions, and focus audit procedures on areas with the greatest risk exposure.

IIA Standard 1220.A2 – Due Professional Care: Auditors are expected to use analytical techniques to improve audit effectiveness and efficiency. Data analytics provides deeper risk insights.

Which of the following is a likely result of outsourcing?

A. Increased dependence on suppliers.

B. Increased importance of market strategy.

C. Decreased sensitivity to government regulation

D. Decreased focus on costs

A.   Increased dependence on suppliers.

Explanation:

Outsourcing involves transferring specific business functions, processes, or services to external third-party providers. A primary and direct consequence of outsourcing is that the organization becomes more dependent on its suppliers for the delivery of critical goods, services, or capabilities. This dependence introduces risks such as loss of internal expertise, reduced control over quality and timelines, potential vendor lock-in, and supply chain vulnerabilities. The organization must rely on the supplier's performance, security, and financial stability, which creates a strategic dependency that requires robust vendor management and oversight.

Why the other options are incorrect:

B. Increased importance of market strategy.
Outsourcing may affect operations, but it does not inherently increase the importance of market strategy (i.e., product positioning, branding, customer segmentation). Market strategy remains important regardless of outsourcing decisions.

C. Decreased sensitivity to government regulation.
Outsourcing increases sensitivity to regulations—especially data privacy (GDPR, CCPA), labor laws, and industry-specific compliance—because the organization remains accountable for the supplier's actions. It does not decrease regulatory exposure.

D. Decreased focus on costs.
Outsourcing is often driven by a desire to reduce or control costs (e.g., labor arbitrage, economies of scale). Therefore, it typically increases focus on costs, not decreases it.

References:

IIA GTAG – Auditing Outsourced Services and Third-Party Relationships: Identifies increased dependency on third parties as a key risk of outsourcing, requiring enhanced vendor oversight, contract management, and contingency planning.

IIA CIA Part 3 Syllabus – Operations / Outsourcing: Tests the candidate's understanding of the strategic and operational implications of outsourcing, including the risks of supplier dependency.

During disaster recovery planning, the organization established a recovery point objective. Which of the following best describes this concept?

A. The maximum tolerable downtime after the occurrence of an incident.

B. The maximum tolerable data loss after the occurrence of an incident.

C. The maximum tolerable risk related to the occurrence of an incident

D. The minimum recovery resources needed after the occurrence of an incident

B.   The maximum tolerable data loss after the occurrence of an incident.

Explanation:

The Recovery Point Objective (RPO) is a key metric in business continuity and disaster recovery planning. It defines the maximum acceptable amount of data loss measured in time—specifically, the point in time to which systems and data must be restored after an incident. For example, an RPO of 4 hours means the organization can tolerate losing up to 4 hours' worth of data (from the last backup to the incident time), and backups must be taken at least every 4 hours to meet this objective. RPO directly drives backup frequency and data replication strategies.

Why the other options are incorrect:

A. The maximum tolerable downtime after the occurrence of an incident. This describes the Recovery Time Objective (RTO)—the maximum acceptable time to restore systems and resume operations, not the data loss metric.

C. The maximum tolerable risk related to the occurrence of an incident. Risk tolerance is a broader strategic concept related to the organization's overall risk appetite, not a specific disaster recovery metric.

D. The minimum recovery resources needed after the occurrence of an incident. This refers to resource requirements (e.g., staffing, hardware, facilities) for recovery, not the data loss tolerance.

References:

IIA GTAG – Business Continuity Management: Defines RPO as the maximum acceptable period of data loss, determining backup frequency and replication strategies.

IIA CIA Part 3 Syllabus – IT / Business Continuity & Disaster Recovery: Tests the candidate's ability to distinguish between RPO (data loss) and RTO (downtime).

Which type of bond sells at & discount from face value, then increases in value annually until it reaches maturity and provides the owner with the total payoff?

A. High-yield bonds

B. Commodity-backed bonds

C. Zero coupon bonds

D. Junk bonds

C.   Zero coupon bonds

Explanation:

A zero coupon bond is a debt security that is issued at a discount from its face (par) value and does not pay periodic interest (coupon) payments. Instead, the bondholder receives the full face value at maturity. The difference between the purchase price (discounted) and the face value represents the investor's return, which accrues annually as the bond's value increases (accretes) toward par over its life. This gradual increase in value is often referred to as "imputed interest" or original issue discount (OID), and the bondholder is taxed on this annual accretion in some jurisdictions. The description in the question—"sells at a discount from face value, then increases in value annually until it reaches maturity"—is the textbook definition of a zero coupon bond.

Why the other options are incorrect:

A. High-yield bonds.
These are bonds issued by companies with lower credit ratings, offering higher interest rates to compensate for higher risk. They pay regular coupons (interest) and are not issued at a significant discount solely for capital appreciation.

B. Commodity-backed bonds.
These are bonds whose principal or interest payments are linked to the price of a commodity (e.g., gold, oil). They pay periodic interest and are not characterized by discount issuance and annual accretion.

D. Junk bonds.
This is another term for high-yield bonds (option A)—they pay regular interest and are not structured as discount-to-par appreciation bonds.

References:

Corporate Finance / Fixed Income Securities: Zero coupon bonds are defined as bonds issued at a deep discount to face value, with no periodic interest, and the investor's return is the full face value at maturity.

CIA Part 3 Syllabus – Financial Management / Debt Instruments: Tests the candidate's understanding of bond types, including zero coupon bonds, and their distinguishing features.

Which of the following can be classified as debt investments?

A. Investments in the capital stock of a corporation

B. Acquisition of government bonds.

C. Contents of an investment portfolio,

D. Acquisition of common stock of a corporation

B.   Acquisition of government bonds.

Explanation:

Debt investments (also called fixed-income securities) are financial instruments where the investor lends money to an issuer (government, corporation, or other entity) in exchange for the promise of periodic interest payments and the return of principal at maturity. Government bonds (e.g., Treasury bonds, municipal bonds) are classic examples of debt investments because they represent a loan to the government, with specified interest rates and maturity dates. The investor is a creditor, not an owner.

Why the other options are incorrect:

A. Investments in the capital stock of a corporation. Capital stock (common or preferred shares) represents equity ownership in a corporation, not a creditor relationship. Equity investments entitle the holder to residual claims on assets and dividends, but they are not debt.

C. Contents of an investment portfolio. This is a generic and vague term—an investment portfolio may contain both debt and equity securities. It is not a specific classification of debt investments on its own.

D. Acquisition of common stock of a corporation. Common stock is equity—it represents ownership in the company, with voting rights and residual claims. It is not a debt investment, as there is no fixed interest or maturity.

References:

GAAP / IFRS – Financial Instruments (ASC 320 / IFRS 9): Classifies debt investments as financial assets that represent a creditor relationship (e.g., bonds, notes, commercial paper). Equity investments represent ownership interests.

CIA Part 3 Syllabus – Financial Management / Investments: Tests the candidate's ability to distinguish between debt investments (bonds, notes) and equity investments (common and preferred stock).

An investor has acquired an organization that has a dominant position in a mature. slewgrowth Industry and consistently creates positive financial income.
Which of the following terms would the investor most likely label this investment in her portfolio?

A. A star

B. A cash cow

C. A question mark

D. A dog

B.   A cash cow

Explanation:

The question describes an organization with a dominant position in a mature, slow-growth industry that consistently generates positive financial income. This is the textbook definition of a cash cow in the Boston Consulting Group (BCG) Growth-Share Matrix. A cash cow has a high market share in a low-growth market, allowing it to generate strong, stable cash flows with minimal investment. These businesses are mature, profitable, and provide the financial resources to fund other ventures (stars, question marks) in the portfolio. The investor would label it a cash cow because it requires little capital expenditure and produces reliable income.

Why the other options are incorrect:

A. A star.
A star has a high market share in a high-growth market. It generates revenue but requires significant investment to maintain growth and fend off competitors. The scenario describes a mature, slow-growth industry—not a high-growth one.

C. A question mark.
A question mark has a low market share in a high-growth market. These are risky, cash-consuming businesses that require heavy investment to gain market share. The scenario describes a dominant position with positive income, not a low-share, uncertain position.

D. A dog.
A dog has a low market share in a low-growth market. These businesses generate low or negative returns and are often candidates for divestiture. The scenario explicitly states a dominant position and positive income, ruling out a dog.

References:

BCG Growth-Share Matrix (Boston Consulting Group): Classifies business units into four categories: Stars (high growth, high share), Cash Cows (low growth, high share), Question Marks (high growth, low share), and Dogs (low growth, low share).

Page 10 out of 61 Pages