Free IIA IIA-CIA-Part3 Practice Questions 2026 - Page 4

Timed Practice Test

Ready for IIA-CIA-Part3 Exam?

This practice test is your final exam before the REAL exam
Dare to Take It?




Practice Questions

Which of the following network types should an organization choose if it wants to allow access only to its own personnel?

A. An extranet

B. A local area network

C. An Intranet

D. The internet

C.   An Intranet

Explanation:

An intranet is a private, internal network that uses Internet Protocol (IP) technology but is accessible only to an organization's own employees or personnel. It is securely firewalled from the public internet and is designed to host internal communications, documents, HR portals, and business applications exclusively for internal staff use. Access is granted through authentication mechanisms (e.g., corporate credentials), ensuring that only authorized personnel can view or interact with the content.

Why the other options are incorrect:

A. An extranet.
This is a controlled private network that allows limited, external access to specific third parties such as suppliers, vendors, or strategic customers. It extends beyond the organization's own personnel, making it incorrect for a network restricted only to internal staff.

B. A local area network (LAN).
While a LAN is a private network within a physical location (e.g., an office building), it is defined by geographic scope and connectivity, not by access policy. A LAN can be used by employees, but it also physically connects any device within range—it does not inherently restrict access only to personnel across the entire enterprise, nor does it differentiate between employees and visitors on-site.

D. The internet.
This is a global, public network accessible by anyone with a connection. It is inherently open and does not restrict access to an organization's own personnel; it is the opposite of what the question requires.

References:

IIA GTAG – Information Security Governance: Defines intranets as internal networks restricted to employees, extranets as extended to trusted business partners, and the internet as public. Emphasizes that network classification determines the appropriate security controls.

Which of the following is an example of a contingent liability that a company should record?

A. A potential assessment of additional income tax.

B. Possible product warranty costs.

C. The threat of a lawsuit by a competitor.

D. The remote possibility of a contract breach.

B.   Possible product warranty costs.

Explanation:

Under accounting standards (e.g., GAAP and IFRS), a contingent liability must be recorded (accrued) in the financial statements if it meets both of the following criteria: (1) it is probable (likely to occur), and (2) the amount can be reasonably estimated. Product warranty costs are the classic example of a recorded contingent liability because past historical data allows companies to reliably estimate future warranty claims, and it is virtually certain that some claims will occur. Companies accrue this estimated cost at the time of sale to match the expense with the related revenue (matching principle).

Why the other options are incorrect:

A. A potential assessment of additional income tax.
This is typically disclosed as a contingent liability only if the tax authority has already raised an issue and the outcome is probable and estimable. However, a potential assessment is often uncertain; unless it meets the "probable and estimable" threshold, it is usually disclosed in footnotes rather than recorded as a liability.

C. The threat of a lawsuit by a competitor.
A mere threat is a possible contingent liability, but it is not recorded unless it is probable that a loss will occur and the amount can be reasonably estimated. Most lawsuit threats are disclosed in footnotes rather than accrued until the outcome becomes clear.

D. The remote possibility of a contract breach.
This is not recorded and generally not even disclosed. Contingencies that are only remotely possible (low probability) do not meet the threshold for recognition or disclosure under both GAAP (ASC 450) and IFRS (IAS 37). Only remote possibilities are ignored entirely.

References:

GAAP – ASC 450 (Contingencies): Requires accrual when a loss is probable and reasonably estimable; otherwise, disclosure is required for reasonably possible contingencies, and no action is required for remote ones. Warranty costs are explicitly cited as a typical accrued liability.

A company that supplies medications to large hospitals relies heavily on subcontractors to replenish any shortages within 24 hours. Where should internal auditors look for evidence that subcontractors are held responsible for this obligation?

A. The company's code of ethics.

B. The third-party management risk register.

C. The signed service-level agreement.

D. The subcontractors' annual satisfaction survey.

C.   The signed service-level agreement.

Explanation:

A Service-Level Agreement (SLA) is a formal, legally binding contract between a company and a subcontractor (or third-party vendor) that explicitly defines the expected performance standards, delivery timelines, penalties for non-compliance, and remedies for failure. Since the company relies on subcontractors to replenish shortages within a strict 24-hour window, the SLA is the authoritative document where this specific obligation, including response times, performance metrics, and accountability mechanisms, is formally codified. Internal auditors should examine the signed SLA to verify that the obligation exists, is clearly defined, and includes enforceable consequences for non-performance.

Why the other options are incorrect:

A. The company's code of ethics.
This outlines general principles of integrity, honesty, and professional conduct for employees and business partners. It does not contain specific, measurable operational obligations like replenishment timelines or performance penalties.

B. The third-party management risk register.
This is a risk management tool that identifies, assesses, and tracks risks associated with third-party relationships (e.g., supply chain disruption risk). It does not establish contractual obligations or hold subcontractors legally accountable for specific performance metrics.

D. The subcontractors' annual satisfaction survey.
This is a feedback mechanism used to gauge subcontractor sentiment or relationship quality. It has no legal or contractual weight and does not define performance obligations or consequences for failure.

References:

IIA GTAG – Auditing Third-Party Risk Management: Emphasizes that SLAs are the primary control mechanism for governing vendor performance, and auditors must verify that SLAs contain measurable metrics, reporting requirements, and remedies for non-compliance.

Which of the following is classified as a product cost using the variable costing method?
1. Direct labor costs.
2. Insurance on a factory.
3. Manufacturing supplies.
4. Packaging and shipping costa.

A. 1 and 2

B. 1 and 3

C. 2 and 4

D. 3 and 4

B.   1 and 3

Explanation:

Under the variable costing method (also known as direct costing), only variable manufacturing costs are classified as product costs (inventoriable costs). These costs fluctuate with production volume and are capitalized as inventory until the goods are sold.

Item 1 (Direct labor costs) – If direct labor is truly variable (paid per unit produced or hourly with no fixed guarantee), it is a variable product cost. In most standard costing problems, direct labor is treated as a variable manufacturing cost.

Item 3 (Manufacturing supplies) – These are indirect materials (e.g., lubricants, cleaning agents, small tools) that vary with production output. They are part of variable manufacturing overhead and thus a product cost under variable costing.

Fixed manufacturing costs (like factory insurance) and period costs (like shipping) are expensed immediately under variable costing.

Why the other options are incorrect:

A. 1 and 2 (Direct labor costs and Insurance on a factory) – Insurance on a factory is a fixed manufacturing overhead cost. Under variable costing, fixed overhead is treated as a period cost (expensed immediately), not a product cost. Only direct labor qualifies from this pair.

C. 2 and 4 (Insurance on a factory and Packaging and shipping costs) – Both are incorrect. Insurance is fixed overhead (period cost under variable costing). Packaging and shipping costs are typically period costs (selling/distribution expenses), not manufacturing costs, unless they are packaging required to get the product ready for sale (which is rare and usually considered a selling expense).

D. 3 and 4 (Manufacturing supplies and Packaging and shipping costs) – Manufacturing supplies (Item 3) is correct as a variable product cost. However, packaging and shipping costs (Item 4) are generally classified as period costs (outbound freight and selling expenses), not product costs, under both variable and absorption costing.

References:

CIA Part 3 Syllabus – Financial Management / Cost Accounting: Explicitly tests the distinction between variable costing and absorption costing. Under variable costing, product costs include only direct materials, direct labor, and variable manufacturing overhead. Fixed manufacturing overhead is expensed as a period cost.

After purchasing shoes from an online retailer, a customer continued to receive additional unsolicited offers from the retailer and other retailers who offer similar products.
Which of the following is the most likely control weakness demonstrated by the seller?

A. Excessive collecting of information

B. Application of social engineering

C. Retention of incomplete information.

D. Undue disclosure of information

D.   Undue disclosure of information

Explanation:

The customer purchased shoes from an online retailer and subsequently received unsolicited offers not only from that same retailer but also from other unrelated retailers offering similar products. This scenario indicates that the customer's personal data (purchase history, preferences, contact details) was improperly shared or sold to third-party entities without their explicit consent. This is a classic example of undue disclosure of information—a control weakness where sensitive customer data is disclosed to unauthorized external parties, violating privacy policies, data protection regulations (e.g., GDPR, CCPA), and the principle of data minimization. Strong data governance controls should restrict data sharing to only what is necessary and only with explicit customer consent.

Why the other options are incorrect:

A. Excessive collecting of information.
While collecting more data than necessary is a privacy concern, it does not explain why other retailers received the customer's data. The core issue here is the sharing of that data, not the volume collected. Excessive collection alone would not result in third parties sending offers unless the data was also disclosed.

B. Application of social engineering.
Social engineering is a manipulation technique used by attackers to trick individuals into revealing confidential information (e.g., phishing). This is an external threat vector, not a control weakness by the seller. The seller did not use social engineering; they improperly shared data.

C. Retention of incomplete information.
This refers to storing inaccurate or missing data (e.g., wrong address, missing consent records), which could lead to poor decision-making or compliance failures. However, the scenario involves accurate data being shared too broadly—the issue is disclosure, not completeness or accuracy.

References:

IIA GTAG – Privacy and Data Protection:Emphasizes that organizations must implement controls over data disclosure, including consent management, data sharing agreements, and vendor risk assessments to prevent unauthorized third-party access to personal information.

At an organization that uses a periodic inventory system, the accountant accidentally understated the organization s beginning inventory. How would the accountant's accident impact the income statement?

A. Cost of goods sold will be understated and net income will be overstated.

B. Cost of goods sold will be overstated and net income will be understated

C. Cost of goods sold will be understated and there Wi-Fi be no impact on net income.

D. There will be no impact on cost of goods sold and net income will be overstated

A.   Cost of goods sold will be understated and net income will be overstated.

Explanation:

In a periodic inventory system, Cost of Goods Sold (COGS) is calculated using the formula: COGS = Beginning Inventory + Purchases – Ending Inventory.

If the beginning inventory is understated, this directly reduces the COGS calculation (because you are starting with a smaller number). Since COGS is an expense, a lower expense means higher gross profit and higher net income.

The impact flows through as follows:
Understated Beginning Inventory → Understated COGS → Overstated Gross Profit → Overstated Net Income.
This is a standard cause-and-effect relationship tested frequently in accounting and internal audit exams.

Why the other options are incorrect:

B. Cost of goods sold will be overstated and net income will be understated. This is the opposite effect. That would occur if beginning inventory were overstated, not understated.

C. Cost of goods sold will be understated and there will be no impact on net income. This is incorrect because any change in COGS directly impacts gross profit and net income. COGS and net income have an inverse relationship; they do not move independently.

D. There will be no impact on cost of goods sold and net income will be overstated. This is incorrect because COGS is impacted (understated). Net income is overstated, but the impact on COGS cannot be ignored, as the two are mathematically linked through the COGS formula.

References:

CIA Part 3 Syllabus – Financial Management / Accounting: Tests the candidate's understanding of inventory accounting, the periodic system, and the impact of inventory errors on financial statements.

GAAP – Inventory Measurement (ASC 330): Requires proper inventory valuation. Errors in beginning inventory have a direct reversing effect on COGS and net income, which auditors must understand to assess financial statement accuracy.

What relationship exists between decentralization and the degree, importance, and range of lower-level decision making?

A. Mutually exclusive relationship.

B. Direct relationship.

C. Intrinsic relationship.

D. Inverse relationship.

B.   Direct relationship.

Explanation:

Decentralization refers to the delegation of decision-making authority from top management to lower-level managers and employees. As an organization becomes more decentralized, it directly increases the degree (how much authority is given), importance (significance of decisions made), and range (breadth of issues covered) of decision-making at lower levels. This is a direct (positive) relationship: the more decentralized the structure, the greater the decision-making power, scope, and impact entrusted to frontline and middle managers. Conversely, in a centralized structure, decision-making authority is concentrated at the top, limiting lower-level input.

Why the other options are incorrect:

A. Mutually exclusive relationship. This is incorrect because decentralization and lower-level decision-making are not opposites that cannot coexist; they are inherently linked. They are complementary, not mutually exclusive.

C. Intrinsic relationship. While decentralization does inherently involve lower-level decisions, "intrinsic" is a vague and imprecise term in management theory. The exam expects the precise, measurable term "direct relationship" to describe this positive correlation.

D. Inverse relationship. An inverse relationship would mean that as decentralization increases, lower-level decision-making decreases—which is the opposite of reality. That describes a centralized structure, not decentralization.

References:

IIA CIA Part 3 Syllabus – Organizational Structure & Management: Tests the candidate's understanding of centralization vs. decentralization and how organizational design impacts authority, responsibility, and decision-making at all levels.

Management has established a performance measurement focused on the accuracy of disbursements. The disbursement statistics, provided daily to ail accounts payable and audit staff, include details of payments stratified by amount and frequency. Which of the following is likely to be the greatest concern regarding this performance measurement?

A. Articulation of the data

B. Availability of the data.

C. Measurability of the data

D. Relevance of the data.

D.   Relevance of the data.

Explanation:

The performance measurement focuses on the accuracy of disbursements—a control objective related to ensuring payments are correct, authorized, and properly recorded. However, the statistics provided daily include details of payments stratified by amount and frequency. While this data may be useful for monitoring cash flow or vendor concentration, it does not directly measure accuracy (e.g., whether payments match approved invoices, were properly authorized, or were mathematically correct). Providing data that does not align with the stated performance goal creates a relevance issue—management and staff receive information that does not help them assess or improve the actual accuracy of disbursements. Relevant data should directly correlate with the performance metric being measured; otherwise, it becomes noise that wastes time and obscures true performance.

Why the other options are incorrect:

A. Articulation of the data. This refers to how clearly the data is presented or communicated. The question states the data is provided daily with stratified details, implying it is organized and articulated. Even if articulation were poor, the greater concern is that the data itself does not measure what it is supposed to measure.

B. Availability of the data. The data is explicitly provided daily to all accounts payable and audit staff, so availability is not a concern. It is readily accessible.

C. Measurability of the data. Payment amounts and frequencies are easily quantifiable and measurable. The concern is not whether the data can be measured, but whether the data should be used for this specific performance goal.

References:

IIA CIA Part 3 Syllabus – Performance Management / Operations: Tests the candidate's understanding that performance measures must be relevant, reliable, and aligned with strategic objectives. Irrelevant metrics lead to misdirected efforts and poor decision-making.

Which of the following practices impacts copyright issues related to the manufacturer of a smart device?

A. Session hijacking

B. Jailbreaking

C. Eavesdropping,

D. Authentication.

B.   Jailbreaking

Explanation:

Jailbreaking is the practice of removing software restrictions imposed by the manufacturer on a smart device (such as smartphones, tablets, or smart TVs) to gain root access and install unauthorized applications or modify the operating system. This practice directly impacts copyright issues because it bypasses the manufacturer's digital rights management (DRM) protections, allows the installation of pirated or unlicensed software, and violates the end-user license agreement (EULA). Manufacturers often argue that jailbreaking constitutes copyright infringement under laws like the Digital Millennium Copyright Act (DMCA), as it circumvents technological protection measures (TPMs) designed to protect proprietary software and content.

Why the other options are incorrect:

A. Session hijacking.
This is a network security attack where an attacker steals a user's active session token to gain unauthorized access to a web application or system. It is a security threat, not a practice that impacts copyright issues related to device manufacturing.

C. Eavesdropping.
This refers to the passive interception of communications (e.g., sniffing network traffic to capture sensitive data). It is a privacy and confidentiality breach, not related to copyright, software restrictions, or manufacturer intellectual property.

D. Authentication.
This is a security control process used to verify the identity of a user or device (e.g., passwords, biometrics, multi-factor authentication). It is a protective measure, not a practice that infringes or impacts copyright. In fact, manufacturers use authentication to prevent unauthorized access and protect their intellectual property.

References:

IIA GTAG – Auditing Smart Devices and the Internet of Things: Discusses risks associated with jailbreaking and rooting, including voiding warranties, security vulnerabilities, and intellectual property/copyright violations.

According to IIA guidance, which of the following best describes an adequate management (audit.) trail application control for the general ledger?

A. Report identifying data that is outside of system parameters

B. Report identifying general ledger transactions by time and individual.

C. Report comparing processing results with original Input

D. Report confirming that the general ledger data was processed without error

B.   Report identifying general ledger transactions by time and individual.

Explanation:

An adequate management (audit) trail provides a chronological record that allows a transaction to be traced from its source to the final financial statements and vice versa . The fundamental elements of an audit trail are knowing who made a change and when it was made (the timestamp), along with what data was altered . Therefore, a report identifying general ledger transactions by time and individual provides the most comprehensive evidence for accountability and is widely cited by authoritative sources as the primary control for this purpose . This ensures transparency and allows management to effectively track the history of all transactions .

Why the other options are incorrect:

A. Report identifying data that is outside of system parameters. This describes an exception report, which is useful for identifying errors or anomalies. However, it does not provide a history of all transactions, nor does it trace changes back to the responsible user, making it insufficient for a comprehensive audit trail .

C. Report comparing processing results with original input. This describes a data validation or reconciliation control. While it helps ensure accuracy, it does not provide a chronological log of who processed a transaction and when, which is central to the definition of an audit trail .

D. Report confirming that the general ledger data was processed without error. This is a confirmation of processing integrity, not a historical record of activity. It offers no information on user identification or the timing of entries, which are essential for accountability and fraud detection .

Reference:

IIA GTAG & Application Controls: The concept of a management (audit) trail is a key application control. It enables management to track transactions from their source to their output .

General Ledger Controls: An audit trail is a fundamental internal control for the general ledger, ensuring transparency and accountability by recording who made changes and when .

Page 4 out of 49 Pages