Halloween Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

Which of the following is a necessary action for an internal audit function if senior management chooses not to take action to remediate the finding and accepts the risk?

A.

The chief audit executive (CAE) must discuss this disagreement with senior management and communicate this information to external stakeholders

B.

The CAE must include this disagreement in the final audit report and conclude the engagement

C.

The CAE must make a judgment regarding the prudence of that decision and report to the board if needed

D.

The CAE must establish a follow-up process to monitor the acceptable risk level as part of the engagement

Which statement is true regarding the development of a risk-based internal audit plan?

A.

It requires a previously conducted assurance engagement on the organization’s risk management maturity

B.

It requires an assessment by the internal audit function of key risks identified within the organization's risk management system

C.

It requires that at least 90% of planned engagements address areas critical to the organization's strategy

D.

It requires that an organization adheres to a well-recognized risk management framework in order to identify and manage its risks

Which of the following statements is accurate when planning for an external quality assurance assessment of the internal audit function?

A.

The external assessment would include the audit function’s compliance with laws and regulations

B.

The selected qualified assessor can be from the organization’s shared services team

C.

The external assessment team members must work for an accounting firm

D.

The frequency of the performance of assessments should be considered by the assessor

Which of the following measures the operating success of a company for a given period of time?

A.

Liquidity ratios.

B.

Profitability ratios.

C.

Solvency ratios.

D.

Current ratios.

Which of the following best describes depreciation?

A.

It is a process of allocating cost of assets between periods.

B.

It is a process of assets valuation.

C.

It is a process of accumulating adequate funds to replace assets.

D.

It is a process of measuring decline in the value of assets because of obsolescence

Which of the following statements regarding the necessary resources to achieve the internal audit plan is true?

A.

Ultimate oversight and responsibility for the internal audit function can be outsourced

B.

Relying upon the work of other assurance providers decreases the efficiency with which to retain auditors with high knowledge and experience

C.

Internal audit resources can be obtained entirely from outside the organization

D.

Co-sourcing, where experts from outside the organization perform specialized work, must be used by chief audit executives instead of outsourcing

The internal audit function conducted an engagement on maintenance operations of a construction organization and identified several issues of medium importance. The head of maintenance proposed an improvement plan with deadlines and personnel responsible. The internal audit function issued the final report to senior management. Senior management was dissatisfied with the report as they believed that improvement plan deadlines should be considerably shorter. Which of the following should the internal audit function change in the reporting process?

A.

Discontinue discussing draft reports with responsible employees, as their input is needed during fieldwork only

B.

Involve senior management at the draft report stage and in the development of action plans

C.

Request senior management to issue a separate memo regarding their changes to deadlines

D.

Invite senior management to the board meeting regarding engagement results so that they can express their concerns

After auditing the treasury function, the internal audit team issued a final report, which included an action plan agreed with management. When the audit team returned three months later to follow up on the action plan, management indicated that the plan had not been implemented because the old treasury system was being replaced with a new system. Which of the following is the most appropriate audit response?

A.

The internal audit team should propose a new, relevant action plan that takes into account the new treasury system

B.

The internal audit team should disregard the original action plan and follow up next year, after management determines whether the new system poses any new risks

C.

The internal audit team should report this issue to the chief audit executive, who should communicate management's noncompliance directly to the board

D.

The internal audit team should report this issue to the chief audit executive, who should discuss the issue with senior management

Which of the following is a sound network configuration practice to enhance information security?

A.

Change management practices to ensure operating system patch documentation is retained.

B.

User role requirements are documented in accordance with appropriate application-level control needs.

C.

Validation of intrusion prevention controls is performed to ensure intended functionality and data integrity.

D.

Interfaces reinforce segregation of duties between operations administration and database development.

Which of the following controls would an internal auditor consider the most relevant to reduce risks of project cost overruns?

A.

Scope change requests are reviewed and approved by a manager with a proper level of authority.

B.

Cost overruns are reviewed and approved by a control committee led by the project manager.

C.

There is a formal quality assurance process to review scope change requests before they are implemented

D.

There is a formal process to monitor the status of the project and compare it to the cost baseline

Which approach should a chief audit executive take when preparing the internal audit plan?

A.

Organize the auditable units within the organization into an audit universe to facilitate risk assessment

B.

Select auditable units within the organization based on monetary values

C.

Evaluate auditable units based on senior management's information about risks

D.

Eliminate auditable units not mandated to be audited by laws and regulations applicable to the organization

The chief audit executive hired a consultant to update the internal audit function’s methodologies. Which of the following would best ensure that the internal audit function will adhere to the updated methodologies?

A.

Placing the updated methodologies in an easily accessible location for reference

B.

Requiring a signed acknowledgment that each auditor will comply with the updated methodologies

C.

Preparing a recorded training that reviews the updated methodologies

D.

Sharing a one-page summary of the updated methodologies during an internal audit function meeting

During the second half of the audit year, the chief audit executive (CAE) identified significant negative variances to the approved audit budget required to complete the internal audit plan. Which of the following actions should the CAE take?

A.

Revise the internal audit plan to reduce coverage of new strategic critical areas so that the approved budget can be met

B.

Reduce the scope of the remainder of the engagements in the internal audit plan to reduce overall costs

C.

Communicate to senior management and the board the risk of not being able to complete the audit plan

D.

Continue to complete the plan regardless of the budget variances, as the audit function is invaluable to sound corporate governance

What security feature would Identity a legitimate employee using her own smart device to gam access to an application run by the organization?

A.

Using a jailbroken or rooted smart device feature.

B.

Using only smart devices previously approved by the organization.

C.

Obtaining written assurance from the employee that security policies and procedures are followed.

D.

Introducing a security question known only by the employee.

An organization suffered significant damage to its local: file and application servers as a result of a hurricane. Fortunately, the organization was able to recover all information backed up by its overseas third-party contractor. Which of the following approaches has been used by the organization?

A.

Application management

B.

Data center management

C.

Managed security services

D.

Systems integration