Free IIA IIA-CIA-Part3 Practice Questions 2026 - Page 11
Ready for IIA-CIA-Part3 Exam?
This practice test is your final exam before the REAL exam
Dare to Take It?
Practice Questions
Which type of bond sells at & discount from face value, then increases in value annually until it reaches maturity and provides the owner with the total payoff?
A. High-yield bonds
B. Commodity-backed bonds
C. Zero coupon bonds
D. Junk bonds
Explanation:
A zero coupon bond is a debt security that is issued at a discount from its face (par) value and does not pay periodic interest (coupon) payments. Instead, the bondholder receives the full face value at maturity. The difference between the purchase price (discounted) and the face value represents the investor's return, which accrues annually as the bond's value increases (accretes) toward par over its life. This gradual increase in value is often referred to as "imputed interest" or original issue discount (OID), and the bondholder is taxed on this annual accretion in some jurisdictions. The description in the question—"sells at a discount from face value, then increases in value annually until it reaches maturity"—is the textbook definition of a zero coupon bond.
Why the other options are incorrect:
A. High-yield bonds.
These are bonds issued by companies with lower credit ratings, offering higher interest rates to compensate for higher risk. They pay regular coupons (interest) and are not issued at a significant discount solely for capital appreciation.
B. Commodity-backed bonds.
These are bonds whose principal or interest payments are linked to the price of a commodity (e.g., gold, oil). They pay periodic interest and are not characterized by discount issuance and annual accretion.
D. Junk bonds.
This is another term for high-yield bonds (option A)—they pay regular interest and are not structured as discount-to-par appreciation bonds.
References:
Corporate Finance / Fixed Income Securities: Zero coupon bonds are defined as bonds issued at a deep discount to face value, with no periodic interest, and the investor's return is the full face value at maturity.
CIA Part 3 Syllabus – Financial Management / Debt Instruments: Tests the candidate's understanding of bond types, including zero coupon bonds, and their distinguishing features.
Which of the following can be classified as debt investments?
A. Investments in the capital stock of a corporation
B. Acquisition of government bonds.
C. Contents of an investment portfolio,
D. Acquisition of common stock of a corporation
Explanation:
Debt investments (also called fixed-income securities) are financial instruments where the investor lends money to an issuer (government, corporation, or other entity) in exchange for the promise of periodic interest payments and the return of principal at maturity. Government bonds (e.g., Treasury bonds, municipal bonds) are classic examples of debt investments because they represent a loan to the government, with specified interest rates and maturity dates. The investor is a creditor, not an owner.
Why the other options are incorrect:
A. Investments in the capital stock of a corporation. Capital stock (common or preferred shares) represents equity ownership in a corporation, not a creditor relationship. Equity investments entitle the holder to residual claims on assets and dividends, but they are not debt.
C. Contents of an investment portfolio. This is a generic and vague term—an investment portfolio may contain both debt and equity securities. It is not a specific classification of debt investments on its own.
D. Acquisition of common stock of a corporation. Common stock is equity—it represents ownership in the company, with voting rights and residual claims. It is not a debt investment, as there is no fixed interest or maturity.
References:
GAAP / IFRS – Financial Instruments (ASC 320 / IFRS 9): Classifies debt investments as financial assets that represent a creditor relationship (e.g., bonds, notes, commercial paper). Equity investments represent ownership interests.
CIA Part 3 Syllabus – Financial Management / Investments: Tests the candidate's ability to distinguish between debt investments (bonds, notes) and equity investments (common and preferred stock).
An investor has acquired an organization that has a dominant position in a mature. slewgrowth
Industry and consistently creates positive financial income.
Which of the following terms would the investor most likely label this investment in her
portfolio?
A. A star
B. A cash cow
C. A question mark
D. A dog
Explanation:
The question describes an organization with a dominant position in a mature, slow-growth industry that consistently generates positive financial income. This is the textbook definition of a cash cow in the Boston Consulting Group (BCG) Growth-Share Matrix. A cash cow has a high market share in a low-growth market, allowing it to generate strong, stable cash flows with minimal investment. These businesses are mature, profitable, and provide the financial resources to fund other ventures (stars, question marks) in the portfolio. The investor would label it a cash cow because it requires little capital expenditure and produces reliable income.
Why the other options are incorrect:
A. A star.
A star has a high market share in a high-growth market. It generates revenue but requires significant investment to maintain growth and fend off competitors. The scenario describes a mature, slow-growth industry—not a high-growth one.
C. A question mark.
A question mark has a low market share in a high-growth market. These are risky, cash-consuming businesses that require heavy investment to gain market share. The scenario describes a dominant position with positive income, not a low-share, uncertain position.
D. A dog.
A dog has a low market share in a low-growth market. These businesses generate low or negative returns and are often candidates for divestiture. The scenario explicitly states a dominant position and positive income, ruling out a dog.
References:
BCG Growth-Share Matrix (Boston Consulting Group): Classifies business units into four categories: Stars (high growth, high share), Cash Cows (low growth, high share), Question Marks (high growth, low share), and Dogs (low growth, low share).
According to IIA guidance on IT, which of the following would be considered a primary control for a spreadsheet to help ensure accurate financial reporting?
A. Formulas and static data are locked or protected.
B. The spreadsheet is stored on a network server that is backed up daily.
C. The purpose and use of the spreadsheet are documented.
D. Check-in and check-out software is used to control versions.
Explanation:
Spreadsheets are a common form of user-developed application (UDA) that present significant risks to data integrity, especially when used for financial reporting. A primary control to mitigate these risks is to lock or protect formulas and static data, which prevents end-users from inadvertently altering critical logic or source data.
Why the Other Options Are Incorrect
While the other options are important controls, they are not the primary control for ensuring accurate financial reporting:
B. The spreadsheet is stored on a network server that is backed up daily. Storage and backup address availability of the file, not its accuracy. They help recover the file after an incident but do not prevent calculation errors or data corruption.
C. The purpose and use of the spreadsheet are documented. Documentation is an essential administrative control, but it is a detective or directive control that does not actively prevent formula errors or user modifications.
D. Check-in and check-out software is used to control versions.
Version control is a critical change management control that helps track revisions and roll back errors, but it is more of a detective or corrective control. Unlike locking formulas, it does not prevent the error from being introduced in the first place.
References
IIA GTAG 14:Auditing User-Developed Applications emphasizes that to ensure data integrity, controls must be implemented to mitigate risks. Locking cells to prevent changes to formulas and static data is a key preventive control.
The IIA's Global Technology Audit Guide (GTAG) series highlights that spreadsheets used in financial reporting are subject to risks such as data integrity, availability, and confidentiality, and must be appropriately controlled to ensure compliance and accurate reporting.
Which of the following disaster recovery plans includes recovery resources available at the site, but they may need to be configured to support the production system?
A. Warm site recovery plan.
B. Hot site recovery plan.
C. Hot site recovery plan.
D. Cold site recovery plan.
Explanation:
A warm site is a partially equipped recovery facility that has pre-installed hardware, network connectivity, and basic infrastructure (power, cooling), but the systems are not fully configured and do not contain current production data. To resume operations, the organization must perform some configuration (e.g., installing software, restoring data from backups, applying settings) and testing before the site becomes fully operational. This matches the description: "recovery resources available at the site, but they may need to be configured to support the production system." A warm site offers a balance between recovery time and cost—faster than a cold site, but more expensive and slower than a hot site.
Why the other options are incorrect:
B. Hot site recovery plan.
A hot site is a fully operational duplicate of the production environment with real-time data synchronization, fully configured hardware and software, and is ready to take over operations immediately (within minutes or hours). It requires no configuration—it is already configured.
C. Hot site recovery plan.
(This is a duplicate of option B.) It is incorrect for the same reason: a hot site does not require configuration; it is already operational.
D. Cold site recovery plan.
A cold site provides the physical facility (building, power, cooling) but no pre-installed hardware, software, or data. It requires significant time (weeks or more) to procure, install, configure, and restore systems. It is not "resources available at the site that may need configuration"—it is essentially an empty shell.
References:
IIA GTAG – Business Continuity Management: Defines warm sites as having hardware and connectivity in place but requiring configuration and data restoration, with recovery times typically ranging from 1 to 7 days.
IIA CIA Part 3 Syllabus – IT / Business Continuity & Disaster Recovery: Tests the candidate's ability to distinguish between cold, warm, and hot sites based on pre-configuration, data readiness, and recovery time.
Which of the following would be the strongest control to prevent unauthorized wireless network access?
A. Allowing access to the organization's network only through a virtual private network.
B. Logging devices that access the network, including the date. time, and identity of the user.
C. Tracking all mobile device physical locations and banning access from non-designated areas.
D. Permitting only authorized IT personnel to have administrative control of mobile devices.
Explanation:
Requiring all wireless access to the organization's network to go through a Virtual Private Network (VPN) is the strongest preventive control against unauthorized access. A VPN creates an encrypted tunnel over public or untrusted networks, ensuring that even if the wireless signal is intercepted or an unauthorized user discovers the network SSID, they cannot access internal resources without valid VPN credentials and authentication. This adds a critical layer of security beyond the wireless access point itself, effectively enforcing authentication, encryption, and access control at the network perimeter, regardless of the physical location or wireless network being used.
Why the other options are incorrect:
B. Logging devices that access the network, including the date, time, and identity of the user. Logging is a detective control—it records activity after it occurs. While useful for forensic investigations and monitoring, it does not prevent unauthorized access from happening in the first place.
C. Tracking all mobile device physical locations and banning access from non-designated areas. This is a restrictive physical/logical control, but it is often impractical, can be bypassed via spoofing, and does not secure the wireless transmission itself. It is weaker than a VPN, which provides cryptographic protection regardless of location.
D. Permitting only authorized IT personnel to have administrative control of mobile devices. This is a strong administrative control for managing devices (e.g., MDM), but it limits who can configure devices—it does not directly prevent unauthorized wireless network access from external or untrusted devices.
References:
IIA GTAG – Information Security Governance: Identifies VPNs as a critical control for securing remote and wireless access, providing encryption and authentication to prevent unauthorized network access.
NIST SP 800-53 – AC-17 (Remote Access): Requires that remote access to organizational networks be controlled and encrypted, typically through VPNs or equivalent secure gateways.
Which of the following principles s shared by both hierarchies and open organizational
structures?
1. A superior can delegate the authority to make decisions but cannot delegate the ultimate
responsibility for the results of those decisions.
2. A supervisor's span of control should not exceed seven subordinates.
3. Responsibility should be accompanied by adequate authority.
4. Employees at all levels should be empowered to make decisions.
A. 1 and 3 only
B. 1 and 4 only
C. 2 and 3 only
D. 3 and 4 only
Explanation:
Both hierarchical (tall, centralized) and open (flat, decentralized, networked) organizational structures share universal management principles concerning authority and accountability:
Statement 1: "A superior can delegate the authority to make decisions but cannot delegate the ultimate responsibility for the results of those decisions." – This is a core principle of accountability. Even when a manager delegates tasks and the authority to complete them, they remain ultimately responsible for the outcomes. This applies equally in a strict hierarchy and a flexible open structure.
Statement 3: "Responsibility should be accompanied by adequate authority." – Known as the parity principle, this states that to be held accountable for achieving objectives, a manager must be given sufficient authority to make decisions and command the necessary resources. Without authority, responsibility is meaningless—this is a fundamental tenet in both classical and modern organizational models.
Why the other options are incorrect:
Statement 2:"A supervisor's span of control should not exceed seven subordinates." – This is an overly rigid, outdated claim. The ideal span of control depends on the complexity of work, employee competence, and available technology. It is not a universal principle shared by all organizational structures.
Statement 4: "Employees at all levels should be empowered to make decisions." – This is characteristic of open, decentralized structures, not hierarchical ones. In a traditional hierarchy, decision-making authority is concentrated at the top, and empowerment is more limited and controlled.
References:
Management Theory (Fayol, Urwick, Weber): The principles of delegation without abdication of responsibility, and the parity of authority and responsibility, are foundational to all organizational design.
IIA CIA Part 3 Syllabus – Organizational Structure / Management: Tests the understanding that accountability and authority-responsibility alignment are universal principles, while span of control and empowerment vary by structure.
An internal auditor reviewed Finance Department records to obtain a list of current vendor addresses. The auditor then compared the vendor addresses to a record of employee addresses maintained by the Payroll Department Which of the following types of data analysis did the auditor perform?
A. Duplicate testing.
B. Joining data sources.
C. Gap analysis.
D. Classification
Explanation:
The auditor performed a join operation—a fundamental data analysis technique where two or more datasets are combined based on a common field to identify matches, discrepancies, or relationships. In this scenario, the auditor took the Finance Department's vendor addresses and compared them to the Payroll Department's employee addresses to see if any vendors shared the same address as employees (a potential red flag for fraud or conflicts of interest). This is a classic example of joining data sources to enable cross-dataset analysis that would not be possible by examining each dataset in isolation.
Why the other options are incorrect:
A. Duplicate testing.
This involves searching for duplicate records within a single dataset (e.g., duplicate vendor IDs, duplicate invoice numbers). The auditor did not search for duplicates within one file; they compared two different datasets.
C. Gap analysis.
This refers to comparing a current state to a desired future state to identify deficiencies or missing elements. The auditor did not assess gaps or missing requirements; they performed a matching comparison.
D. Classification.
This involves assigning items into predefined categories or groups based on characteristics (e.g., categorizing vendors by risk level). The auditor did not classify data; they cross-referenced two sources.
References:
IIA GTAG – Data Analysis Technologies: Defines "joining" as combining datasets based on a common key field to enable cross-dataset analysis, such as matching vendor and employee addresses to detect fraud.
IIA CIA Part 3 Syllabus – Data Analytics: Tests the candidate's ability to identify common data analysis techniques, including joining, duplicate testing, summarization, and stratification.
An IT auditor is evaluating IT controls of a newly purchased information system. The
auditor discovers that logging is not configured al database and application levels.
Operational management explains that they do not have enough personnel to manage the
logs and they see no benefit in keeping logs. Which of the fallowing responses best
explains risks associated with insufficient or absent logging practices?
A. The organization will be unable to develop preventative actions based on analytics.
B. The organization will not be able to trace and monitor the activities of database administers.
C. The organization will be unable to determine why intrusions and cyber incidents took place.
D. The organization will be unable to upgrade the system to newer versions.
Explanation:
Logging is a fundamental detective control that records user activities, system events, transactions, and errors at the database and application levels. Without proper logging, the organization loses its ability to conduct post-incident forensic analysis. When an intrusion, data breach, or system compromise occurs, logs are the primary source of evidence to reconstruct what happened, identify how the attacker gained entry, determine which data was accessed or exfiltrated, and understand the root cause. Without logs, the organization operates in the dark—unable to determine the "who, what, when, and why" of security incidents, which severely impairs incident response, remediation, and legal/regulatory reporting.
Why the other options are incorrect:
A. The organization will be unable to develop preventative actions based on analytics. While logs can inform preventive analytics (e.g., anomaly detection), this is a secondary benefit. The primary risk of absent logging is the inability to investigate incidents, not the inability to develop predictive analytics.
B. The organization will not be able to trace and monitor the activities of database administrators. This is a specific example of a logging use case (privileged user monitoring), but the broader and more critical risk is the inability to investigate all incidents, not just DBA activities. This option is too narrow.
D. The organization will be unable to upgrade the system to newer versions.
System upgrades are independent of logging configurations. Absence of logs does not prevent version upgrades; it only affects monitoring and forensic capabilities.
References:
IIA GTAG – Information Security Governance: Emphasizes that logging is critical for incident detection, forensic investigation, and root cause analysis. Without logs, organizations cannot determine the scope or cause of security breaches.
NIST SP 800-53 – AU-2 (Audit Events) & AU-6 (Audit Review): Requires organizations to generate audit records and review them to detect and investigate incidents.
Which of the following statements is true regarding cost-volume-profit analysis?
A. Contribution margin is the amount remaining from sales revenue after fixed expenses have been deducted.
B. Breakeven point is the amount of units sold to cover variable costs.
C. Breakeven occurs when the contribution margin covers fixed costs.
D. Following breakover1, he operating income will increase by the excess of fixed costs less the variable costs per units sold.
Explanation:
In cost-volume-profit (CVP) analysis, the breakeven point is the level of sales (in units or dollars) at which total revenues equal total costs, resulting in zero profit or loss. At breakeven, the total contribution margin (sales revenue minus variable costs) is exactly sufficient to cover total fixed costs. Once fixed costs are covered, any additional contribution margin contributes directly to operating income. This is the fundamental relationship in CVP analysis.
Why the other options are incorrect:
A. Contribution margin is the amount remaining from sales revenue after fixed expenses have been deducted. This is incorrect. Contribution margin is sales revenue minus variable costs—not fixed costs. The amount remaining after deducting fixed costs is operating income (or net income).
B. Breakeven point is the amount of units sold to cover variable costs. This is incorrect. Breakeven covers total costs (both fixed and variable), not just variable costs. Covering variable costs alone would leave fixed costs uncovered, resulting in a loss.
D. Following breakeven, operating income will increase by the excess of fixed costs less the variable costs per unit sold. This is nonsensical. After breakeven, operating income increases by the contribution margin per unit (selling price per unit minus variable cost per unit), not by "fixed costs less variable costs."
References:
CIA Part 3 Syllabus – Financial Management / Cost-Volume-Profit Analysis: Tests the candidate's understanding of CVP fundamentals: contribution margin (sales - variable costs), breakeven point (where contribution margin = fixed costs), and operating leverage.
Managerial Accounting Textbooks (Horngren, Garrison): Define contribution margin as sales minus variable costs, and breakeven as the point where total contribution margin equals total fixed costs.
| Page 11 out of 49 Pages |