View Full IIA IIA-CIA-Part2 Exam Dumps and Practice Test Dumps
Question 121.
What is the primary purpose of reviewing segregation of duties during an internal audit engagement?
- Reduce the risk that one individual can initiate, authorize, record, and conceal inappropriate activity
- Eliminate all management review
- Ensure every department has the same staffing structure
- Replace system access controls
Correct Answer: 1. Reduce the risk that one individual can initiate, authorize, record, and conceal inappropriate activity
Explanation:
Segregation of duties helps reduce the opportunity for error or fraud by distributing incompatible responsibilities among different individuals. Commonly separated activities include authorization, custody, recording, and reconciliation. Where complete segregation is impractical, compensating controls such as independent review may be necessary. Internal audit should evaluate both formal role assignments and actual system access or operating practices.
Question 122.
Which situation MOST clearly indicates a segregation-of-duties weakness?
- One employee prepares a payment and another approves it
- One employee can create a vendor, approve an invoice, and release payment without independent review
- Management reviews exception reports monthly
- System access is based on job responsibilities
Correct Answer: 2. One employee can create a vendor, approve an invoice, and release payment without independent review
Explanation:
Combining vendor creation, invoice approval, and payment release gives one person the ability to initiate and complete a transaction with limited oversight. This creates a significant opportunity for error or fraud. Internal audit should determine whether duties are appropriately separated and whether any compensating controls exist where staffing or system constraints prevent ideal segregation.
Question 123.
What is the primary purpose of reviewing privileged access during an engagement?
- Determine whether powerful system permissions are limited to authorized users and appropriately monitored
- Ensure every user has administrator rights
- Replace user authentication controls
- Eliminate the need for logging
Correct Answer: 1. Determine whether powerful system permissions are limited to authorized users and appropriately monitored
Explanation:
Privileged accounts can create elevated risk because they may allow users to modify configurations, data, security settings, or logs. Internal audit should evaluate whether such access is justified, approved, periodically reviewed, and independently monitored. Strong controls over privileged access are particularly important because ordinary application controls may be bypassed by users with broad administrative permissions.
Question 124.
Which control BEST reduces the risk associated with emergency access to sensitive systems?
- Permanent administrator rights for all support staff
- No logging of emergency sessions
- Automatic approval of all emergency access requests
- Time-limited access that is approved, logged, and reviewed after use**
Correct Answer: 4. Time-limited access that is approved, logged, and reviewed after use
Explanation:
Emergency access may be necessary during outages or critical incidents, but it should remain controlled. Limiting access duration, requiring appropriate approval, recording activity, and performing retrospective review reduces the risk of misuse. Internal audit may examine whether emergency access is granted only when justified and whether monitoring is sufficient to identify inappropriate actions.
Question 125.
What is the primary purpose of reviewing master-data changes during an internal audit?
- Determine whether sensitive changes are authorized, accurate, and appropriately controlled
- Replace transaction testing
- Increase the number of master records
- Eliminate the need for user access controls
Correct Answer: 1. Determine whether sensitive changes are authorized, accurate, and appropriately controlled
Explanation:
Master data such as vendor bank details, customer records, employee information, and pricing can affect large numbers of transactions. Unauthorized or inaccurate changes may create significant fraud or operational risk. Internal audit may review approval, access, audit trails, independent verification, and monitoring of sensitive master-data changes.
Question 126.
Which factor is MOST important when testing changes to vendor bank information?
- Whether the vendor has been used for many years
- Whether the change was independently verified using trusted contact information
- Whether the change request was received by email
- Whether the vendor is domestic
Correct Answer: 2. Whether the change was independently verified using trusted contact information
Explanation:
Fraudsters may impersonate vendors and request changes to payment details. Independent verification using known and trusted contact information can help confirm that the request is legitimate. Relying only on contact details included in the request can weaken the control. Additional approval and audit trails can further reduce the risk of payment diversion.
Question 127.
What is the primary purpose of reviewing duplicate-payment controls?
- Identify whether the organization can detect and prevent repeated payment of the same obligation
- Ensure vendors submit invoices more than once
- Replace invoice approval controls
- Eliminate the need for reconciliations
Correct Answer: 1. Identify whether the organization can detect and prevent repeated payment of the same obligation
Explanation:
Duplicate payments can result from repeated invoices, data-entry errors, system weaknesses, or intentional misconduct. Internal audit may review automated duplicate checks, invoice numbering, exception reports, vendor data, and recovery procedures. Potential duplicates should be investigated because some similar transactions may be legitimate rather than actual overpayments.
Question 128.
Which analytical test would BEST help identify potential duplicate payments?
- Reviewing only annual totals by vendor
- Comparing employee headcount with payroll expense
- Searching for transactions with matching vendor, invoice number, amount, and date characteristics
- Examining only low-value invoices
Correct Answer: 3. Searching for transactions with matching vendor, invoice number, amount, and date characteristics
Explanation:
Duplicate-payment analysis typically looks for transactions sharing key fields such as vendor, invoice number, amount, date, or purchase order. Exact or near matches can highlight transactions that deserve further investigation. Internal audit should confirm whether flagged items represent true duplicates before concluding that an error or control failure occurred.
Question 129.
What is the primary purpose of reviewing purchase-order approval controls?
- Determine whether purchases are authorized in accordance with established approval limits
- Guarantee that the lowest-priced vendor is always selected
- Replace vendor due diligence
- Eliminate all emergency purchases
Correct Answer: 1. Determine whether purchases are authorized in accordance with established approval limits
Explanation:
Purchase approval controls help ensure that expenditures are legitimate, within authority limits, and consistent with organizational needs. Internal audit may test whether approvals match delegation-of-authority requirements, whether purchases are split to avoid thresholds, and whether system controls appropriately enforce authorization rules.
Question 130.
What is the main risk associated with split purchases just below approval thresholds?
- Purchases will always cost less
- Employees may be attempting to circumvent required higher-level authorization
- Vendor master data will become incomplete
- Accounts payable will stop processing invoices
Correct Answer: 2. Employees may be attempting to circumvent required higher-level authorization
Explanation:
A requester may divide one purchase into multiple smaller transactions to stay below an approval threshold. This can undermine delegated authority and procurement controls. Internal audit may use analytics to identify related transactions by vendor, requester, timing, or amount and then investigate whether the purchases were legitimately separate.
Question 131.
What is the primary purpose of testing three-way matching in accounts payable?
- Determine whether invoices are appropriately compared with purchase orders and evidence of receipt before payment
- Replace vendor approval
- Eliminate payment authorization
- Ensure all purchases are prepaid
Correct Answer: 1. Determine whether invoices are appropriately compared with purchase orders and evidence of receipt before payment
Explanation:
Three-way matching helps ensure that the organization pays only for goods or services that were ordered and received and that invoice details agree with approved terms. Internal audit may test how exceptions are handled and whether override authority is appropriately controlled. The control can reduce the risk of overpayment, unauthorized purchases, and fictitious invoices.
Question 132.
Which circumstance would MOST likely require additional audit attention in accounts payable?
- A routine invoice matched automatically without exception
- A properly approved recurring utility payment
- A large manual payment processed outside normal procedures with limited supporting documentation
- A vendor invoice paid according to established terms
Correct Answer: 3. A large manual payment processed outside normal procedures with limited supporting documentation
Explanation:
Manual transactions outside normal workflows can create elevated risk, especially when they are significant and poorly documented. Internal audit should examine business purpose, authorization, supporting evidence, related parties, and whether the transaction bypassed established controls. Unusual processing does not automatically mean misconduct, but it generally warrants greater scrutiny.
Question 133.
What is the primary purpose of payroll master-file controls?
- Ensure employee records and compensation changes are authorized, accurate, and appropriately maintained
- Replace payroll reconciliation
- Allow payroll staff to approve their own salary changes
- Eliminate human resources involvement
Correct Answer: 1. Ensure employee records and compensation changes are authorized, accurate, and appropriately maintained
Explanation:
Payroll master data directly affects employee payments. Weak controls can permit fictitious employees, unauthorized salary changes, or incorrect bank information. Internal audit may review access restrictions, approval of changes, reconciliation with human resources records, and independent monitoring of sensitive updates.
Question 134.
Which control BEST reduces the risk of payments to fictitious employees?
- Allowing payroll personnel to create and approve employees independently
- Paying all employees in cash
- Eliminating employee identification numbers
- Reconciling payroll records with independently maintained human resources records**
Correct Answer: 4. Reconciling payroll records with independently maintained human resources records
Explanation:
Comparing payroll records with independent HR records can identify names that do not correspond to valid employees. Other useful controls include segregation of duties, approval of employee additions, analysis of duplicate bank accounts, and prompt removal of terminated employees. Internal audit may test these controls and investigate unusual payroll records.
Question 135.
What is the primary purpose of reviewing terminated-user access?
- Confirm that system and physical access is removed promptly after employment ends
- Ensure former employees retain access for convenience
- Replace offboarding procedures
- Reduce the need for identity management
Correct Answer: 1. Confirm that system and physical access is removed promptly after employment ends
Explanation:
Former employees may retain unnecessary access if offboarding processes are incomplete or delayed. This creates risks of unauthorized transactions, data access, or security breaches. Internal audit may compare termination dates with account disablement records and investigate delays. Effective offboarding requires coordination among human resources, information technology, security, and business management.
Question 136.
What is the primary purpose of reviewing journal-entry controls?
- Eliminate all manual journal entries
- Ensure entries are appropriately authorized, supported, and reviewed
- Replace account reconciliations
- Allow senior managers unrestricted posting rights
Correct Answer: 2. Ensure entries are appropriately authorized, supported, and reviewed
Explanation:
Manual journal entries can create risk because they directly affect accounting records and may be used to bypass normal transaction processes. Internal audit may examine access, approval, supporting documentation, unusual accounts, timing, and privileged-user activity. Particular attention may be given to large or unusual entries posted near period-end.
Question 137.
Which journal entry would generally warrant the GREATEST additional audit attention?
- A routine automated depreciation entry
- A recurring payroll accrual supported by established calculations
- A large manual period-end entry posted by a privileged user with minimal support
- A system-generated inventory entry consistent with normal activity
Correct Answer: 3. A large manual period-end entry posted by a privileged user with minimal support
Explanation:
Large, unusual, manual entries posted near period-end can present elevated risk of error or management override, especially when supporting documentation is weak. Internal audit should investigate the business rationale, authorization, accounts affected, user access, and supporting evidence. Risk-focused analytics can help identify similar entries across the population.
Question 138.
What is the primary purpose of reviewing account reconciliations during an engagement?
- Increase the number of adjustment entries
- Replace transaction authorization controls
- Eliminate the need for supporting records
- Determine whether recorded balances are compared with supporting information and differences are appropriately resolved**
Correct Answer: 4. Determine whether recorded balances are compared with supporting information and differences are appropriately resolved
Explanation:
Reconciliations help detect missing, duplicate, inaccurate, or unexplained transactions. Internal audit should evaluate whether reconciliations are timely, complete, independently reviewed where appropriate, and followed by resolution of significant differences. Long-outstanding reconciling items may indicate weak follow-up or underlying accounting and process problems.
Question 139.
What is the primary purpose of aging reconciling items?
- Identify unresolved differences that may require additional investigation or corrective action
- Eliminate account ownership
- Replace management review
- Guarantee that every difference is fraudulent
Correct Answer: 1. Identify unresolved differences that may require additional investigation or corrective action
Explanation:
Aging helps distinguish newly identified differences from items that have remained unresolved for extended periods. Older reconciling items may indicate errors, unsupported balances, weak follow-up, or process deficiencies. Internal audit may focus on significant, recurring, or long-outstanding items and evaluate whether management has appropriate procedures for resolution.
Question 140.
Which approach BEST supports effective internal audit testing of transaction-processing controls?
- Review policies without examining transactions
- Test only transactions selected by management
- Evaluate authorization, segregation of duties, master data, system access, reconciliations, unusual transactions, and exception handling using reliable evidence
- Assume automated transactions require no audit testing
Correct Answer: 3. Evaluate authorization, segregation of duties, master data, system access, reconciliations, unusual transactions, and exception handling using reliable evidence
Explanation:
Transaction-processing assurance requires an integrated assessment of how transactions are initiated, authorized, processed, recorded, safeguarded, and reviewed. Internal audit should consider both manual and automated controls, identify unusual transactions, evaluate access and segregation, and investigate significant exceptions. Reliable evidence and risk-based testing support conclusions about whether the process operates effectively.