Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

An internal auditor discusses user-defined default passwords with the database administrator. Such passwords will be reset as soon as the user logs in for the first time, but the initial value of the password is set as " 123456. " Which of the following are the auditor and the database administrator most likely discussing in this situation?

A.

Whether it would be more secure to replace numeric values with characters.

B.

What happens in the situations where users continue using the initial password.

C.

What happens in the period between the creation of the account and the password change.

D.

Whether users should be trained on password management features and requirements.

Which of the following is an element of effective negotiating?

A.

Ensuring that the other party has a personal stake in the agreement.

B.

Focusing on interests rather than on obtaining a winning position.

C.

Considering a few select choices during the settlement phase.

D.

Basing the agreement on negotiating power and positioning leverage.

In an effort to increase business efficiencies and improve customer service offered to its major trading partners, management of a manufacturing and distribution company established a secure network, which provides a secure channel for electronic data interchange between the company and its partners. Which of the following network types is illustrated by this scenario?

A.

A value-added network.

B.

A local area network.

C.

A metropolitan area network.

D.

A wide area network.

The internal audit activity has identified accounting errors that resulted in the organization overstating its net income for the fiscal year. Which of the following is the most likely cause of this overstatement?

A.

Beginning inventory was overstated for the year.

B.

Cost of goods sold was understated for the year.

C.

Ending inventory was understated for the year.

D.

Cost of goods sold was overstated for the year.

Which of the following describes the most effective control that restricts access to secure areas?

A.

Employee security policy.

B.

Access log reviews.

C.

Biometric authorization.

D.

Security cameras.

Which of the following intangible assets is considered to have an indefinite life?

A.

Underground oil deposits

B.

Copyright

C.

Trademark

D.

Land

Which of the following is required in effective IT change management?

A.

The sole responsibility for change management is assigned to an experienced and competent IT team

B.

Change management follows a consistent process and is done in a controlled environment.

C.

Internal audit participates in the implementation of change management throughout the organisation.

D.

All changes to systems must be approved by the highest level of authority within an organization.

Which of the following describes the primary advantage of using data analytics in internal auditing?

A.

It helps support the internal audit conclusions with factual evidence.

B.

It reduces the time and effort needed to prepare the audit report.

C.

It helps prevent internal auditors from unknowingly disregarding key process risks.

D.

It enables internal auditors to meet their responsibility for monitoring controls.

An organization ' s financial statements indicate a note that the financial statements have been prepared on the basis of the organization continuing operations for the foreseeable future. Which of the following accounting principles has been applied based on this note?

A.

Monetary unit assumption.

B.

Going concern assumption.

C.

Time period assumption.

D.

Economic entity assumption.

Which of the following principles are common to both hierarchical and open organizational structures?

    Employees at all levels should be empowered to make decisions.

    A supervisor ' s span of control should not exceed seven subordinates.

    Responsibility should be accompanied by adequate authority.

    A superior cannot delegate the ultimate responsibility for results.

A.

1 and 2

B.

1 and 4

C.

2 and 3

D.

3 and 4

An organization suffered significant damage to its local: file and application servers as a result of a hurricane. Fortunately, the organization was able to recover all information backed up by its overseas third-party contractor. Which of the following approaches has been used by the organization?

A.

Application management

B.

Data center management

C.

Managed security services

D.

Systems integration

Which of the following activities most significantly increases the risk that a bank will make poor-quality loans to its customers?

A.

Borrowers may not sign all required mortgage loan documentation.

B.

Fees paid by the borrower at the time of the loan may not be deposited in a timely manner.

C.

The bank ' s loan documentation may not meet the government ' s disclosure requirements.

D.

Loan officers may override the lending criteria established by senior management.

Which of the following statements regarding organizational governance is not correct?

A.

An effective internal audit function is one of the four cornerstones of good governance.

B.

Those performing governance activities are accountable to the customer.

C.

Accountability is one of the key elements of organizational governance.

D.

Governance principles and the need for an internal audit function are applicable to governmental and not-for-profit activities.

An organization has adopted a bring-your-own-device (BYOD) policy, and employees can access organizational data via their smart devices.

Which of the following authentication policy requirements is the most advisable?

A.

Require a virtual private network (VPN).

B.

Require at least an eight-digit passcode or a complicated swipe pattern.

C.

Require the remote wipe function and encryption of local data.

D.

Require a passcode followed by a response requiring verification message.

Internal audit discovered that several loads of pellets were deleted from the scaling database and consequently had no sales invoices, significantly affecting financial statements. An investigation revealed that technicians had deleted the pellet loads accidentally, with no evidence of fraud. Which of the following actions should management implement first?

A.

Address root causes by launching a project to understand and revise the methods for granting database access rights

B.

Address the condition by limiting technicians ' access to live database data

C.

Address potential risks by reconciling all sales invoices against scaling data

D.

Address investigation results by dismissing technicians who caused the disruption