Free IIA IIA-CIA-Part3 Practice Questions 2026 - Page 11

Timed Practice Test

Ready for IIA-CIA-Part3 Exam?

This practice test is your final exam before the REAL exam
Dare to Take It?




Practice Questions

According to IIA guidance on IT, which of the following would be considered a primary control for a spreadsheet to help ensure accurate financial reporting?

A. Formulas and static data are locked or protected.

B. The spreadsheet is stored on a network server that is backed up daily.

C. The purpose and use of the spreadsheet are documented.

D. Check-in and check-out software is used to control versions.

A.   Formulas and static data are locked or protected.

Explanation:

Spreadsheets are a common form of user-developed application (UDA) that present significant risks to data integrity, especially when used for financial reporting. A primary control to mitigate these risks is to lock or protect formulas and static data, which prevents end-users from inadvertently altering critical logic or source data.

Why the Other Options Are Incorrect

While the other options are important controls, they are not the primary control for ensuring accurate financial reporting:

B. The spreadsheet is stored on a network server that is backed up daily. Storage and backup address availability of the file, not its accuracy. They help recover the file after an incident but do not prevent calculation errors or data corruption.

C. The purpose and use of the spreadsheet are documented. Documentation is an essential administrative control, but it is a detective or directive control that does not actively prevent formula errors or user modifications.

D. Check-in and check-out software is used to control versions.
Version control is a critical change management control that helps track revisions and roll back errors, but it is more of a detective or corrective control. Unlike locking formulas, it does not prevent the error from being introduced in the first place.

References

IIA GTAG 14:Auditing User-Developed Applications emphasizes that to ensure data integrity, controls must be implemented to mitigate risks. Locking cells to prevent changes to formulas and static data is a key preventive control.

The IIA's Global Technology Audit Guide (GTAG) series highlights that spreadsheets used in financial reporting are subject to risks such as data integrity, availability, and confidentiality, and must be appropriately controlled to ensure compliance and accurate reporting.

Which of the following disaster recovery plans includes recovery resources available at the site, but they may need to be configured to support the production system?

A. Warm site recovery plan.

B. Hot site recovery plan.

C. Hot site recovery plan.

D. Cold site recovery plan.

A.   Warm site recovery plan.

Explanation:

A warm site is a partially equipped recovery facility that has pre-installed hardware, network connectivity, and basic infrastructure (power, cooling), but the systems are not fully configured and do not contain current production data. To resume operations, the organization must perform some configuration (e.g., installing software, restoring data from backups, applying settings) and testing before the site becomes fully operational. This matches the description: "recovery resources available at the site, but they may need to be configured to support the production system." A warm site offers a balance between recovery time and cost—faster than a cold site, but more expensive and slower than a hot site.

Why the other options are incorrect:

B. Hot site recovery plan.
A hot site is a fully operational duplicate of the production environment with real-time data synchronization, fully configured hardware and software, and is ready to take over operations immediately (within minutes or hours). It requires no configuration—it is already configured.

C. Hot site recovery plan.
(This is a duplicate of option B.) It is incorrect for the same reason: a hot site does not require configuration; it is already operational.

D. Cold site recovery plan.
A cold site provides the physical facility (building, power, cooling) but no pre-installed hardware, software, or data. It requires significant time (weeks or more) to procure, install, configure, and restore systems. It is not "resources available at the site that may need configuration"—it is essentially an empty shell.

References:

IIA GTAG – Business Continuity Management: Defines warm sites as having hardware and connectivity in place but requiring configuration and data restoration, with recovery times typically ranging from 1 to 7 days.

IIA CIA Part 3 Syllabus – IT / Business Continuity & Disaster Recovery: Tests the candidate's ability to distinguish between cold, warm, and hot sites based on pre-configuration, data readiness, and recovery time.

Which of the following would be the strongest control to prevent unauthorized wireless network access?

A. Allowing access to the organization's network only through a virtual private network.

B. Logging devices that access the network, including the date. time, and identity of the user.

C. Tracking all mobile device physical locations and banning access from non-designated areas.

D. Permitting only authorized IT personnel to have administrative control of mobile devices.

A.   Allowing access to the organization's network only through a virtual private network.

Explanation:

Requiring all wireless access to the organization's network to go through a Virtual Private Network (VPN) is the strongest preventive control against unauthorized access. A VPN creates an encrypted tunnel over public or untrusted networks, ensuring that even if the wireless signal is intercepted or an unauthorized user discovers the network SSID, they cannot access internal resources without valid VPN credentials and authentication. This adds a critical layer of security beyond the wireless access point itself, effectively enforcing authentication, encryption, and access control at the network perimeter, regardless of the physical location or wireless network being used.

Why the other options are incorrect:

B. Logging devices that access the network, including the date, time, and identity of the user. Logging is a detective control—it records activity after it occurs. While useful for forensic investigations and monitoring, it does not prevent unauthorized access from happening in the first place.

C. Tracking all mobile device physical locations and banning access from non-designated areas. This is a restrictive physical/logical control, but it is often impractical, can be bypassed via spoofing, and does not secure the wireless transmission itself. It is weaker than a VPN, which provides cryptographic protection regardless of location.

D. Permitting only authorized IT personnel to have administrative control of mobile devices. This is a strong administrative control for managing devices (e.g., MDM), but it limits who can configure devices—it does not directly prevent unauthorized wireless network access from external or untrusted devices.

References:

IIA GTAG – Information Security Governance: Identifies VPNs as a critical control for securing remote and wireless access, providing encryption and authentication to prevent unauthorized network access.

NIST SP 800-53 – AC-17 (Remote Access): Requires that remote access to organizational networks be controlled and encrypted, typically through VPNs or equivalent secure gateways.

Which of the following principles s shared by both hierarchies and open organizational structures?
1. A superior can delegate the authority to make decisions but cannot delegate the ultimate responsibility for the results of those decisions.
2. A supervisor's span of control should not exceed seven subordinates.
3. Responsibility should be accompanied by adequate authority.
4. Employees at all levels should be empowered to make decisions.

A. 1 and 3 only

B. 1 and 4 only

C. 2 and 3 only

D. 3 and 4 only

A.   1 and 3 only

Explanation:

Both hierarchical (tall, centralized) and open (flat, decentralized, networked) organizational structures share universal management principles concerning authority and accountability:

Statement 1: "A superior can delegate the authority to make decisions but cannot delegate the ultimate responsibility for the results of those decisions." – This is a core principle of accountability. Even when a manager delegates tasks and the authority to complete them, they remain ultimately responsible for the outcomes. This applies equally in a strict hierarchy and a flexible open structure.

Statement 3: "Responsibility should be accompanied by adequate authority." – Known as the parity principle, this states that to be held accountable for achieving objectives, a manager must be given sufficient authority to make decisions and command the necessary resources. Without authority, responsibility is meaningless—this is a fundamental tenet in both classical and modern organizational models.

Why the other options are incorrect:

Statement 2:"A supervisor's span of control should not exceed seven subordinates." – This is an overly rigid, outdated claim. The ideal span of control depends on the complexity of work, employee competence, and available technology. It is not a universal principle shared by all organizational structures.

Statement 4: "Employees at all levels should be empowered to make decisions." – This is characteristic of open, decentralized structures, not hierarchical ones. In a traditional hierarchy, decision-making authority is concentrated at the top, and empowerment is more limited and controlled.

References:

Management Theory (Fayol, Urwick, Weber): The principles of delegation without abdication of responsibility, and the parity of authority and responsibility, are foundational to all organizational design.

IIA CIA Part 3 Syllabus – Organizational Structure / Management: Tests the understanding that accountability and authority-responsibility alignment are universal principles, while span of control and empowerment vary by structure.

An internal auditor reviewed Finance Department records to obtain a list of current vendor addresses. The auditor then compared the vendor addresses to a record of employee addresses maintained by the Payroll Department Which of the following types of data analysis did the auditor perform?

A. Duplicate testing.

B. Joining data sources.

C. Gap analysis.

D. Classification

A.   Duplicate testing.

Explanation:

The auditor performed a join operation—a fundamental data analysis technique where two or more datasets are combined based on a common field to identify matches, discrepancies, or relationships. In this scenario, the auditor took the Finance Department's vendor addresses and compared them to the Payroll Department's employee addresses to see if any vendors shared the same address as employees (a potential red flag for fraud or conflicts of interest). This is a classic example of joining data sources to enable cross-dataset analysis that would not be possible by examining each dataset in isolation.

Why the other options are incorrect:

A. Duplicate testing.
This involves searching for duplicate records within a single dataset (e.g., duplicate vendor IDs, duplicate invoice numbers). The auditor did not search for duplicates within one file; they compared two different datasets.

C. Gap analysis.
This refers to comparing a current state to a desired future state to identify deficiencies or missing elements. The auditor did not assess gaps or missing requirements; they performed a matching comparison.

D. Classification.
This involves assigning items into predefined categories or groups based on characteristics (e.g., categorizing vendors by risk level). The auditor did not classify data; they cross-referenced two sources.

References:

IIA GTAG – Data Analysis Technologies: Defines "joining" as combining datasets based on a common key field to enable cross-dataset analysis, such as matching vendor and employee addresses to detect fraud.

IIA CIA Part 3 Syllabus – Data Analytics: Tests the candidate's ability to identify common data analysis techniques, including joining, duplicate testing, summarization, and stratification.

An IT auditor is evaluating IT controls of a newly purchased information system. The auditor discovers that logging is not configured al database and application levels.
Operational management explains that they do not have enough personnel to manage the logs and they see no benefit in keeping logs. Which of the fallowing responses best explains risks associated with insufficient or absent logging practices?

A. The organization will be unable to develop preventative actions based on analytics.

B. The organization will not be able to trace and monitor the activities of database administers.

C. The organization will be unable to determine why intrusions and cyber incidents took place.

D. The organization will be unable to upgrade the system to newer versions.

C.   The organization will be unable to determine why intrusions and cyber incidents took place.

Explanation:

Logging is a fundamental detective control that records user activities, system events, transactions, and errors at the database and application levels. Without proper logging, the organization loses its ability to conduct post-incident forensic analysis. When an intrusion, data breach, or system compromise occurs, logs are the primary source of evidence to reconstruct what happened, identify how the attacker gained entry, determine which data was accessed or exfiltrated, and understand the root cause. Without logs, the organization operates in the dark—unable to determine the "who, what, when, and why" of security incidents, which severely impairs incident response, remediation, and legal/regulatory reporting.

Why the other options are incorrect:

A. The organization will be unable to develop preventative actions based on analytics. While logs can inform preventive analytics (e.g., anomaly detection), this is a secondary benefit. The primary risk of absent logging is the inability to investigate incidents, not the inability to develop predictive analytics.

B. The organization will not be able to trace and monitor the activities of database administrators. This is a specific example of a logging use case (privileged user monitoring), but the broader and more critical risk is the inability to investigate all incidents, not just DBA activities. This option is too narrow.

D. The organization will be unable to upgrade the system to newer versions.
System upgrades are independent of logging configurations. Absence of logs does not prevent version upgrades; it only affects monitoring and forensic capabilities.

References:

IIA GTAG – Information Security Governance: Emphasizes that logging is critical for incident detection, forensic investigation, and root cause analysis. Without logs, organizations cannot determine the scope or cause of security breaches.

NIST SP 800-53 – AU-2 (Audit Events) & AU-6 (Audit Review): Requires organizations to generate audit records and review them to detect and investigate incidents.

Which of the following statements is true regarding cost-volume-profit analysis?

A. Contribution margin is the amount remaining from sales revenue after fixed expenses have been deducted.

B. Breakeven point is the amount of units sold to cover variable costs.

C. Breakeven occurs when the contribution margin covers fixed costs.

D. Following breakover1, he operating income will increase by the excess of fixed costs less the variable costs per units sold.

C.   Breakeven occurs when the contribution margin covers fixed costs.

Explanation:

In cost-volume-profit (CVP) analysis, the breakeven point is the level of sales (in units or dollars) at which total revenues equal total costs, resulting in zero profit or loss. At breakeven, the total contribution margin (sales revenue minus variable costs) is exactly sufficient to cover total fixed costs. Once fixed costs are covered, any additional contribution margin contributes directly to operating income. This is the fundamental relationship in CVP analysis.

Why the other options are incorrect:

A. Contribution margin is the amount remaining from sales revenue after fixed expenses have been deducted. This is incorrect. Contribution margin is sales revenue minus variable costs—not fixed costs. The amount remaining after deducting fixed costs is operating income (or net income).

B. Breakeven point is the amount of units sold to cover variable costs. This is incorrect. Breakeven covers total costs (both fixed and variable), not just variable costs. Covering variable costs alone would leave fixed costs uncovered, resulting in a loss.

D. Following breakeven, operating income will increase by the excess of fixed costs less the variable costs per unit sold. This is nonsensical. After breakeven, operating income increases by the contribution margin per unit (selling price per unit minus variable cost per unit), not by "fixed costs less variable costs."

References:

CIA Part 3 Syllabus – Financial Management / Cost-Volume-Profit Analysis: Tests the candidate's understanding of CVP fundamentals: contribution margin (sales - variable costs), breakeven point (where contribution margin = fixed costs), and operating leverage.

Managerial Accounting Textbooks (Horngren, Garrison): Define contribution margin as sales minus variable costs, and breakeven as the point where total contribution margin equals total fixed costs.

Which of the following is the best example of IT governance controls?

A. Controls that focus on segregation of duties, financial, and change management,

B. Personnel policies that define and enforce conditions for staff in sensitive IT areas.

C. Standards that support IT policies by more specifically defining required actions

D. Controls that focus on data structures and the minimum level of documentation required

C.   Standards that support IT policies by more specifically defining required actions

Explanation:

IT governance is the framework of leadership, structures, and processes that ensures IT supports organizational objectives. It establishes accountability and decision rights to steer IT activities toward value delivery and compliance. Its primary outcome is strategic alignment—creating consistent, high-level rules for managing IT as a strategic asset.

Option C fits this definition perfectly. Standards are governance mechanisms that translate high-level policies into specific, enforceable actions. For instance, an IT policy might state "all changes must be approved"; a standard would specify exactly how that approval is obtained (e.g., via Change Advisory Board). This focuses on "directing" behavior and ensuring consistency across the organization—the core of governance.

Why the other options are incorrect:

A. Controls that focus on segregation of duties, financial, and change management: This describes IT General Controls (ITGCs)—the day-to-day controls that implement governance. ITGCs are the mechanisms governed by the framework, not the governance itself.

B. Personnel policies that define and enforce conditions for staff in sensitive IT areas: This is too narrow. Governance covers enterprise-wide strategic alignment and risk management, not just HR-related administration.

D. Controls that focus on data structures and documentation: This is an operational detail or an IT General Control (e.g., an application control), not a broad governance directive.

References:

IIA GTAG – Auditing IT Governance and IT Management, 3rd Edition: Defines IT governance as "leadership, organizational structures, policies, and processes that ensure that the organization’s IT supports its strategies and objectives." It also highlights mechanisms like standards as components to direct IT performance.

A bond that matures after one year has a face value of S250,000 and a coupon of $30,000. if the market price of the bond is 5265,000, which of the following would be the market interest rate?

A. Less than 12 percent.

B. 12 percent

C. Between 12.01 percent and 12.50 percent.

D. More than 12 50 percent.

A.   Less than 12 percent.

Explanation:

The bond has a coupon payment of $30,000** on a **face value of $250,000, which gives a coupon rate of:

$30,000 ÷ $250,000 = 12%

The bond is currently selling at a market price of $265,000**, which is **above its face value ($250,000). This means the bond is trading at a premium.

In bond valuation, there is an inverse relationship between bond prices and market interest rates (yields). When a bond trades at a premium, the market interest rate (yield to maturity) is lower than the coupon rate. This happens because investors are willing to pay more than par value for the bond's stated interest payments, which are higher than what the current market offers. The premium effectively reduces the overall yield to maturity because the investor pays more upfront but still receives the same fixed coupon payments and the face value at maturity. Therefore, since the coupon rate is 12% and the bond is at a premium, the market interest rate must be less than 12%.

Why the other options are incorrect:

B. 12 percent.
This would occur only if the bond traded at par (face value)—i.e., market price = $250,000. At par, the coupon rate equals the market rate. Since the bond is above par, the market rate cannot equal 12%.

C. Between 12.01% and 12.50%.
This would imply the market rate is higher than the coupon rate, which happens when a bond trades at a discount (below par). At a discount, investors require a higher yield than the coupon rate to compensate for paying less than face value. Since the bond is at a premium, this scenario does not apply.

D. More than 12.50%.
This is also a discount scenario—market rate significantly higher than coupon rate—which does not apply to a premium-priced bond. A market rate above 12.50% would drive the bond price well below par, not above it.

References:

Bond Valuation / Fixed Income Fundamentals: Bond prices and market interest rates have an inverse relationship. Premium bonds (price > face value) have market rates lower than the coupon rate; discount bonds (price < face value) have market rates higher than the coupon rate.

CIA Part 3 Syllabus – Financial Management / Debt Instruments: Tests the candidate's understanding of bond pricing dynamics, including the relationship between coupon rate, market price, and yield to maturity.

Which of the following attributes of data analytics relates to the growing number of sources from which data is being generated?

A. Volume.

B. Velocity.

C. Velocity.

D. Velocity.

A.   Volume.

Explanation:

In the context of data analytics and the "Five V's of Big Data," Volume refers to the scale or quantity of data being generated, collected, and stored. It directly relates to the growing number of sources from which data originates—such as IoT devices, social media, transaction systems, sensors, mobile apps, and web logs. As organizations adopt more digital touchpoints, the sheer amount of data (volume) expands exponentially. This attribute addresses the challenge of managing, storing, and processing massive datasets from diverse sources.

Why the other options are incorrect:

B. Velocity.
Velocity refers to the speed at which data is generated, processed, and analyzed in real-time or near-real-time (e.g., streaming data from sensors or social media feeds). It does not relate to the number of sources—it relates to the speed of generation.

C. Velocity.
(This is a duplicate of option B.) It is incorrect for the same reason—velocity is about speed, not the growing number of sources.

D. Velocity.
(Another duplicate.) Again, incorrect—velocity is not about source quantity; it is about data generation speed.

References:

IIA GTAG – Data Analysis Technologies: Defines the Five V's of Big Data: Volume (scale/data quantity), Velocity (speed of generation), Variety (different types/formats), Veracity (quality/accuracy), and Value (business impact).

Page 11 out of 61 Pages