Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

An IT auditor is evaluating IT controls of a newly purchased information system. The auditor discovers that logging is not configured al database and application levels. Operational management explains that they do not have enough personnel to manage the logs and they see no benefit in keeping logs. Which of the fallowing responses best explains risks associated with insufficient or absent logging practices?

A.

The organization will be unable to develop preventative actions based on analytics.

B.

The organization will not be able to trace and monitor the activities of database administers.

C.

The organization will be unable to determine why intrusions and cyber incidents took place.

D.

The organization will be unable to upgrade the system to newer versions.

Which of the following is the primary goal of an effective business impact analysis?

A.

It includes business continuity program governance and risk management.

B.

It identifies key assets, critical processes, resources, and technology.

C.

It sets testing requirements for the organization wide continuity functions.

D.

It outlines and communicates recovery points and objectives.

In a final audit report, internal auditors drafted the following management action plan with a due date of the last day of the calendar year:

" Plan: A bank reconciliation template has been updated to address issues with formulas incorrectly calculating variances. "

Which critical element of the action plan is missing?

A.

The responsible personnel

B.

The status of the action plan

C.

A referral to the policy or procedure

D.

The level of risk

Through meetings with management, an organization ' s chief audit executive (CAE) learns of a risk that exceeds the established risk tolerance. What would be an appropriate next action for the CAE to take?

A.

Design and recommend an appropriate response to the risk

B.

Discuss the risk and the implications of the risk with management responsible for the risk area

C.

Schedule an audit of the risk area to assess the risk likelihood and impact

D.

Prepare a memo to report the risk to the board

In response to a question posed by an internal auditor, management indicated that there is an agreement in place to quickly rent servers and desktop workstations to restore operations from tapes stored at an off-site location. Which of the following plans would the auditor most likely conclude is currently in place for the organization?

A.

A hot recovery plan.

B.

No recovery plan.

C.

A cold recovery plan.

D.

A warm recovery plan.

Data analysis indicates that a hospital pharmacy disbursed higher levels of controlled drugs than similar pharmacies in the area. The hospital ' s internal auditor discusses the risk with the head of the hospital pharmacy, who believes that the risk is appropriately mitigated by controls and feels comfortable with the number of prescriptions written.

What should the auditor do next?

A.

Document that the head of the pharmacy has accepted the risk and believes it is sufficiently mitigated, and conclude the risk assessment.

B.

Request that an independent third party re-perform the data analysis to verify the accuracy of the initial findings.

C.

Investigate the risk by requesting pharmacy policies, procedures, and detailed reports.

D.

Add an audit of the hospital pharmacy to the annual audit plan to fully investigate the risk later in the year.

Which of the following is true of bond financing, compared to common stock, when alJ other variables are equal?

A.

Lower shareholder control

B.

lower indebtedness

C.

Higher company earnings per share.

D.

Higher overall company earnings

An organization produces finished lumber for the construction industry.

Which of the following inventory valuation methods will lead to the highest profit, assuming all other variables remain the same in a period of rising material costs?

A.

Average-cost method.

B.

Weighted cost method.

C.

First-in, first-out (FIFO).

D.

Specific identification.

On the last day of the year, a total cost of S 150.000 was incurred in indirect labor related to one of the key products an organization makes. How should the expense be reported on that year ' s financial statements?

A.

It should be reported as an administrative expense on the income statement.

B.

It should be reported as period cost other than a product cost on the management accounts

C.

It should be reported as cost of goods sold on the income statement.

D.

It should be reported on the balance sheet as part of inventory.

According to IIA guidance, which of the following is a broad collection of integrated policies, standards, and procedures used to guide the planning and execution of a project?

A.

Project portfolio.

B.

Project development

C.

Project governance.

D.

Project management methodologies

Which of the following authentication controls combines what a user knows with the unique characteristics of the user, respectively?

A.

Voice recognition and token

B.

Password and fingerprint

C.

Fingerprint and voice recognition

D.

Password and token

An internal audit uncovered high-risk issues that needed to be addressed by the organization. During the exit conference, the audit team discussed the high-risk issues with the manager responsible for addressing them. How should the chief audit executive respond if the manager agrees to correct the issues identified during the audit?

A.

Include in the report that management has agreed to address the issue and set a date for follow-up

B.

Include an assignment in the annual internal audit plan to perform a follow-up audit

C.

Discuss the audit observation with senior management

D.

Solicit input from management and create the action plan

Which of the following are the most common characteristics of big data?

A.

Visibility, validity, vulnerability

B.

Velocity, variety, volume

C.

Complexity, completeness, constancy

D.

Continuity, control, convenience

Which of the following is true of matrix organizations?

A.

A unity-of-command concept requires employees to report technically, functionally, and administratively to the same manager.

B.

A combination of product and functional departments allows management to utilize personnel from various functions.

C.

Authority, responsibility, and accountability of the units involved may vary based on the project ' s life or the organization ' s culture.

D.

It is best suited for firms with scattered locations or for multi-line, large-scale firms.

Which of the following can be viewed as a potential benefit of an enterprisewide resource planning system?

A.

Real-time processing of transactions and elimination of data redundancies.

B.

Fewer data processing errors and more efficient data exchange with trading partners.

C.

Exploitation of opportunities and mitigation of risks associated with e-business.

D.

Integration of business processes into multiple operating environments and databases.