
New TestkingPass IIA-CIA-Part3-3P Exam Questions| Real IIA-CIA-Part3-3P Dumps Updated on Nov 20, 2022
IIA-CIA-Part3-3P Braindumps – IIA-CIA-Part3-3P Questions to Get Better Grades
IIA IIA-CIA-Part3-3P Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
| Topic 10 |
|
| Topic 11 |
|
| Topic 12 |
|
NEW QUESTION 140
Which of me following responsibilities would ordinary fall under the help desk function of an organization?
- A. Physical hosting of mainframes and distributed servers
- B. Maintenance service items such as production support
- C. End-to-end security architecture design
- D. Management of infrastructure services including network management
Answer: A
NEW QUESTION 141
During a review of a web-based application used by customers to check the status of their bank accounts, it would be most important for the internal auditor to ensure that:
- A. Sensitive data, such as account numbers, are submitted using encrypted communications.
- B. The web server used to host the application is located in a physically secure area.
- C. Access to read application logs is restricted to authorized users.
- D. Account balance information is encrypted in the database.
Answer: A
NEW QUESTION 142
An internal auditor is trying to assess control risk and the effectiveness of an organization's internal controls.
Which of the following audit procedures would not provide assurance to the auditor on this matter?
- A. Inspecting manuals and documents.
- B. Interviewing the organization's employees.
- C. Reading the board's minutes.
- D. Observing the organization's operations.
Answer: C
NEW QUESTION 143
Which of the following IT-related activities is most commonly performed by the second line of defense?
- A. Encrypt data.
- B. Review disaster recovery test results.
- C. Block unauthorized traffic.
- D. Provide independent assessment of IT security.
Answer: B
NEW QUESTION 144
Which of the following statements is true regarding the resolution of interpersonal conflict?
- A. Reorganization would probably not help ambiguous or overlapping jurisdictions.
- B. Deferring action should be used until there is sufficient time to fully deal with the issue.
- C. Timely and unambiguous clarification of roles and responsibilities will eliminate most interpersonal conflict.
- D. Unrealized expectations can be avoided with open and honest discussion.
Answer: D
NEW QUESTION 145
Under a value-added taxing system:
- A. Consumer savings are discouraged.
- B. The amount of value added is the difference between an organization's sales and its cost of goods sold.
- C. The consumer ultimately bears the cost of the tax through higher prices.
- D. Businesses must pay a tax only if they make a profit.
Answer: C
NEW QUESTION 146
Which of the following is a primary driver behind the creation and prioritization of new strategic initiatives established by an organization?
- A. Risk tolerance
- B. Governance
- C. Performance.
- D. Threats and opportunities.
Answer: D
NEW QUESTION 147
In an organization's established accounts payable department employees perform highly structured activities follow clearly defined procedures and have strict deadlines for performing their tasks The head of the department recently retired, and a new department head was hired To achieve the greatest benefit for this department and avoid redundancy the new leader should adopt which of the following leadership styles?
- A. Achievement-oriented style
- B. Goal-oriented style
- C. People-oriented style
- D. Task-oriented style
Answer: B
NEW QUESTION 148
Which of the following is the best example of a compliance risk that is likely to arise when adopting a bring-your-own-device (BYOD) policy?
- A. The risk that smart devices can be lost or stolen due to their mobile nature.
- B. The risk that users try to bypass controls and do not install required software updates.
- C. The risk that proprietary information is not deleted from the device when an employee leaves.
- D. The risk that an organization intrusively monitors personal information stored on smart devices.
Answer: D
NEW QUESTION 149
Maintenance cost at a hospital was observed to increase as activity level increased. The following data was gathered:
Activity Level -
Maintenance Cost
Month
Patient Days
January
5,600
$7,900
February
7,100
$8,500
March
5,000
$7,400
April
6,500
$8,200
May
7,300
$9,100
June
8,000
$9,800
If the cost of maintenance is expressed in an equation, what is the independent variable for this data?
- A. Total maintenance cost.
- B. Patient days.
- C. Variable cost.
- D. Fixed cost.
Answer: B
NEW QUESTION 150
Which of the following is an example of a nonfinancial internal failure quality cost?
- A. Excessive time to convert raw materials into finished goods.
- B. Defective units shipped to customers.
- C. Decreasing gross profit margins over time.
- D. Foregone contribution margin on lost sales.
Answer: A
NEW QUESTION 151
Which of the following statements is true regarding cost-volume-profit analysis?
- A. Contribution margin is the amount remaining from sales revenue after fixed expenses have been deducted.
- B. Following breakeven, net operating income will increase by the excess of fixed costs less the variable costs per units sold
- C. Breakeven point is the amount of units sold to cover variable costs.
- D. Breakeven occurs when the contribution margin covers fixed costs
Answer: D
NEW QUESTION 152
Which of the following is the first step an internal audit activity should undertake when executing a data analytics process?
- A. Define the purpose and the anticipated value
- B. Select data for cleaning and normalization procedures.
- C. Analyze possible and available sources of raw data
- D. Conduct a risk assessment regarding the effectiveness of the data analytics process.
Answer: C
NEW QUESTION 153
Which of the following is an example of a physical control designed to prevent security breaches?
- A. Preventing database administrators from initiating program changes.
- B. Using encryption for data transmitted over the public internet.
- C. Blocking technicians from getting into the network room.
- D. Restricting system programmers' access to database facilities.
Answer: D
NEW QUESTION 154
The board has requested that the internal audit activity be involved in all phases of the organization's outsourcing of its network management. During which of the following stages is the internal auditor most likely to verify that the organization's right-to-audit clause is drafted effectively?
- A. Monitoring and reporting phase
- B. Implementation and transition phase.
- C. Decision-making and business-case phase.
- D. Tendering and contracting phase.
Answer: D
NEW QUESTION 155
Which of the following describes the most appropriate set of tests for auditing a workstation's logical access controls?
- A. Review the list of people who attempted to access the workstation and failed, as well as error messages.
- B. Review the password length, frequency of change, and list of users for the workstation's login process.
- C. Review the passwords of those who attempted unsuccessfully to access the workstation and the log of their activity.
- D. Review the list of people with access badges to the room containing the workstation and a log of those who accessed the room.
Answer: B
NEW QUESTION 156
An organization has a complex systems infrastructure consisting of multiple internally developed, off the shelf, and purchased but significantly customized applications. Some of these applications share databases or process data that is used by another stand-alone application, and interfaces have been written to move data between these applications as needed through batch processing Which of the following situations presents the greatest risk exposure given this environment?
- A. The implementation of a major update for a key application is delayed until any potential interdependencies are identified and analyzed.
- B. The job scheduling tool frequently malfunctions, causing scheduled jobs not to run. An error message is sent to IT personnel when a job fails.
- C. Batch processing jobs include key financial data that is not posted to the accounting system until the next day. preventing real-time queries.
- D. Documentation of each system and its interactions, interfaces, and dependencies with other systems and databases is not gathered and maintained.
Answer: D
NEW QUESTION 157
According to IIA guidance, which of the following is a primary component of a network security strategy?
- A. Transmission encryption controls
- B. Firewall controls.
- C. Application input controls
- D. Change management controls
Answer: B
NEW QUESTION 158
An internal auditor is trying to assess control risk and the effectiveness of an organization's internal controls. Which of the following audit procedures would not provide assurance to the auditor on this matter?
- A. Inspecting manuals and documents.
- B. Interviewing the organization's employees.
- C. Reading the board's minutes.
- D. Observing the organization's operations.
Answer: C
NEW QUESTION 159
Which of the following should be established by management during implementation of big data systems to enable ongoing production monitoring?
- A. Master data management
- B. Key performance indicators
- C. Change and patch management
- D. Reports of software customization
Answer: B
NEW QUESTION 160
According to the waterfall cycle approach to systems development, which of the following sequence of events is correct?
- A. System requirements, analysis, coding, software design, program design, testing, operations.
- B. System requirements, software design, analysis, program design, testing, coding, operations.
- C. System requirements, software design, analysis, program design, coding, testing, operations.
- D. Program design, system requirements, software design, analysis, coding, testing, operations.
Answer: C
NEW QUESTION 161
An internal auditor for a pharmaceutical company is planning a cybersecurity audit and conducting a risk assessment.
Which of the following would be considered the most significant cyber threat to the organization?
- A. A denial-of-service attack that prevents access to the organization's website.
- B. Cybercriminals hacking into the organization's time and expense system to collect employee personal data.
- C. A hacker accessing the financial information of the company.
- D. Hackers breaching the organization's network to access research and development reports.
Answer: C
NEW QUESTION 162
Which of the following IT controls includes protection for mainframe computers and workstations?
- A. Organization and management controls
- B. Physical and environmental controls.
- C. Change management controls
- D. System software controls
Answer: B
NEW QUESTION 163
For employees, the primary value of implementing job enrichment is which of the following?
- A. An increased opportunity to manage better the work done by their subordinates.
- B. Increased knowledge through the performance of additional tasks.
- C. Validation of the achievement of their goals and objectives.
- D. Support for personal growth and a meaningful work experience.
Answer: D
NEW QUESTION 164
......
IIA-CIA-Part3-3P Exam Dumps - Try Best IIA-CIA-Part3-3P Exam Questions: https://www.testkingpass.com/IIA-CIA-Part3-3P-testking-dumps.html
Get New IIA-CIA-Part3-3P Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1bmN_1SAl3KyY6YxbLR1XkzeKkOAg7o0s