{"id":20550,"date":"2026-09-24T06:03:27","date_gmt":"2026-09-24T06:03:27","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=20550"},"modified":"2026-09-24T06:03:27","modified_gmt":"2026-09-24T06:03:27","slug":"iia-iia-cia-part2-practice-test-questions-and-exam-dumps-part10-q181-200","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/iia-iia-cia-part2-practice-test-questions-and-exam-dumps-part10-q181-200\/","title":{"rendered":"IIA IIA-CIA-Part2 Practice Test Questions and Exam Dumps Part10 Q181-200"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/iia-cia-part2-exam-dumps\"><b>IIA IIA-CIA-Part2 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 181.<\/b><\/p>\n<p><b>What is the primary purpose of evaluating business continuity controls during an internal audit engagement?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether critical operations can continue or be restored within acceptable timeframes following disruption<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate the possibility of operational interruption<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace disaster recovery planning<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transfer continuity responsibility to internal audit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether critical operations can continue or be restored within acceptable timeframes following disruption<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Business continuity controls are designed to help an organization maintain or restore critical activities after events such as system failures, natural disasters, cyber incidents, facility outages, or supplier disruptions. Internal audit may assess whether critical processes have been identified, recovery requirements are defined, plans are current, responsibilities are clear, and testing demonstrates that arrangements are practical. The objective is reasonable resilience rather than a guarantee that disruptions will never occur.<\/span><\/p>\n<p><b>Question 182.<\/b><\/p>\n<p><b>Which document is MOST useful for identifying which business processes should receive recovery priority?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Annual employee evaluation report<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Information security awareness plan<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> General ledger chart of accounts<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Business impact analysis<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Business impact analysis<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A business impact analysis identifies critical processes and evaluates the consequences of their disruption over time. It can consider financial, operational, customer, regulatory, safety, and reputational impacts. The results help management establish recovery priorities and determine how quickly important activities should be restored. Internal audit may assess whether the analysis is current, comprehensive, and appropriately linked to continuity and recovery strategies.<\/span><\/p>\n<p><b>Question 183.<\/b><\/p>\n<p><b>What does a recovery time objective primarily establish?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The acceptable amount of data loss<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The target time within which a disrupted process or system should be restored<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The number of backup copies required<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The period between internal audit engagements<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The target time within which a disrupted process or system should be restored<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A recovery time objective defines how quickly a critical service, process, or system should be restored after disruption. Shorter recovery targets usually require stronger technology, infrastructure, staffing, or alternate processing capabilities. Internal audit may evaluate whether recovery strategies and testing results are consistent with approved recovery objectives and whether those objectives reflect the business impact of prolonged downtime.<\/span><\/p>\n<p><b>Question 184.<\/b><\/p>\n<p><b>What does a recovery point objective primarily address?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> How long employees may work remotely<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> How quickly damaged hardware must be replaced<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The maximum acceptable amount of data loss measured in time<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The time required to complete an audit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The maximum acceptable amount of data loss measured in time<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A recovery point objective defines how much recent data the organization can afford to lose following an interruption. It influences backup, replication, and data-protection strategies. For example, a shorter recovery point objective may require more frequent backups or near-real-time replication. Internal audit may compare backup and restoration capabilities with approved recovery requirements to determine whether data-loss risk is adequately controlled.<\/span><\/p>\n<p><b>Question 185.<\/b><\/p>\n<p><b>What is the primary purpose of testing a business continuity plan periodically?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether procedures, responsibilities, resources, and assumptions work in practice<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Guarantee that the organization will never experience an outage<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate the need to update the plan<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace risk assessment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether procedures, responsibilities, resources, and assumptions work in practice<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Continuity plans can become outdated as systems, personnel, suppliers, locations, and business processes change. Periodic testing through simulations, tabletop exercises, or operational tests can reveal weaknesses before an actual disruption occurs. Internal audit may review whether identified deficiencies are documented, assigned to responsible owners, and corrected in a timely manner.<\/span><\/p>\n<p><b>Question 186.<\/b><\/p>\n<p><b>Which finding would be MOST significant when reviewing disaster recovery testing?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Test documentation uses an outdated template<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Critical systems consistently fail to meet approved recovery objectives during tests<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> One participant arrives late to a tabletop exercise<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The recovery team changes meeting rooms<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Critical systems consistently fail to meet approved recovery objectives during tests<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Repeated failure to meet recovery objectives indicates that actual recovery capability may not satisfy business requirements. This could expose the organization to significant operational, financial, customer, or regulatory consequences during a real disruption. Internal audit should evaluate the root cause, management response, interim safeguards, and whether senior management understands the residual exposure.<\/span><\/p>\n<p><b>Question 187.<\/b><\/p>\n<p><b>What is the primary purpose of reviewing backup restoration tests?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether backed-up data can actually be recovered when needed<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Increase storage capacity<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace system-access controls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Guarantee that backups contain no sensitive data<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether backed-up data can actually be recovered when needed<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Creating backups does not provide meaningful protection if the information cannot be restored successfully. Internal audit may examine whether restoration tests are performed periodically, whether failures are investigated, and whether backup frequency and retention align with recovery requirements. Backup media should also be appropriately protected from unauthorized access, alteration, or ransomware.<\/span><\/p>\n<p><b>Question 188.<\/b><\/p>\n<p><b>Which control BEST reduces the risk that ransomware affects both production data and backup copies?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Keeping all backups permanently connected to production systems<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Allowing ordinary users to modify backup files<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Storing protected backup copies using appropriately isolated or restricted environments<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disabling backup monitoring<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Storing protected backup copies using appropriately isolated or restricted environments<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Backups can be compromised if attackers can access them using the same credentials or network paths as production systems. Isolated, immutable, offline, or otherwise strongly protected backup arrangements can reduce this risk. Internal audit should consider access rights, retention, restoration testing, monitoring, and whether backup protection is proportionate to the criticality of the underlying information.<\/span><\/p>\n<p><b>Question 189.<\/b><\/p>\n<p><b>What is the primary purpose of third-party risk assessment before outsourcing a critical business process?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Evaluate whether the provider can meet relevant operational, security, compliance, and continuity requirements<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transfer all organizational risk to the provider<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate the need for contractual controls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Prevent management from using external service providers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Evaluate whether the provider can meet relevant operational, security, compliance, and continuity requirements<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Outsourcing can introduce dependency, cybersecurity, privacy, compliance, operational, and concentration risks. Due diligence helps management assess whether a provider has appropriate capabilities and controls before entering the relationship. Internal audit may evaluate whether due diligence was proportionate to the service\u2019s criticality and whether identified risks were considered before contract approval.<\/span><\/p>\n<p><b>Question 190.<\/b><\/p>\n<p><b>Which contract provision is MOST useful for evaluating and managing critical service-provider performance?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> A statement that performance is entirely at the provider\u2019s discretion<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Clearly defined service levels, responsibilities, reporting expectations, and remedies<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Removal of all audit rights<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> An agreement with no measurable performance standards<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Clearly defined service levels, responsibilities, reporting expectations, and remedies<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Measurable contractual expectations help management monitor whether a service provider delivers required performance and controls. Agreements may address service availability, response times, security responsibilities, incident notification, recovery requirements, reporting, audit rights, and remedies. Internal audit may examine whether contract provisions are aligned with the importance and risk of the outsourced activity.<\/span><\/p>\n<p><b>Question 191.<\/b><\/p>\n<p><b>What is the primary purpose of ongoing monitoring of a critical third-party provider?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether the provider\u2019s performance and risk profile remain acceptable throughout the relationship<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace initial due diligence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate the need for contract management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Guarantee that the provider cannot fail<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether the provider\u2019s performance and risk profile remain acceptable throughout the relationship<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A provider\u2019s financial condition, cybersecurity posture, performance, ownership, subcontractors, or regulatory environment can change after the contract begins. Ongoing monitoring helps management identify deterioration or emerging risks. Internal audit may review service-level results, incidents, assurance reports, financial indicators, unresolved issues, and management oversight of significant third parties.<\/span><\/p>\n<p><b>Question 192.<\/b><\/p>\n<p><b>Which situation would MOST strongly indicate third-party concentration risk?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Different business units use unrelated local suppliers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The organization has multiple backup providers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Several critical business processes depend on the same external service provider<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> A noncritical vendor supplies office stationery<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Several critical business processes depend on the same external service provider<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Concentration risk arises when several important services depend on a single provider, location, platform, or other common resource. A failure affecting that provider could therefore disrupt multiple business activities simultaneously. Internal audit may assess whether management understands this dependency and whether alternative suppliers, contingency arrangements, or other mitigating controls are available.<\/span><\/p>\n<p><b>Question 193.<\/b><\/p>\n<p><b>What is the primary purpose of reviewing a critical vendor\u2019s exit strategy?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether the organization can transition or terminate the service without unacceptable disruption or data loss<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Prevent the organization from ever changing providers<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate the need for continuity planning<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transfer ownership of organizational data to the provider<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether the organization can transition or terminate the service without unacceptable disruption or data loss<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Critical outsourcing arrangements can create dependency and vendor lock-in. An exit strategy should address data return or destruction, transition responsibilities, system access, intellectual property, knowledge transfer, alternative providers, and continuity during the change. Internal audit may evaluate whether the exit arrangements are realistic and whether management has considered scenarios such as provider failure or contract termination.<\/span><\/p>\n<p><b>Question 194.<\/b><\/p>\n<p><b>Which factor is MOST important when reviewing a vendor\u2019s independent assurance report?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the report is lengthy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether its scope, period, controls, findings, and user responsibilities are relevant to the organization\u2019s risks<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the vendor advertises the report publicly<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the report contains no technical terminology<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Whether its scope, period, controls, findings, and user responsibilities are relevant to the organization\u2019s risks<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An assurance report is useful only if it covers the services, controls, and time period relevant to the organization. Internal audit should also consider exceptions, complementary user controls, subservice organizations, and any limitations. Simply obtaining the report does not demonstrate that third-party risk is adequately managed if significant services or responsibilities fall outside its scope.<\/span><\/p>\n<p><b>Question 195.<\/b><\/p>\n<p><b>What is the primary purpose of evaluating complementary user controls identified in a service-provider assurance report?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether the organization has implemented controls that the provider assumes customers will perform<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Transfer provider responsibilities to internal audit<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace contract monitoring<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate the need to review service-provider controls<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether the organization has implemented controls that the provider assumes customers will perform<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Third-party assurance often assumes that customer organizations operate certain controls themselves, such as user-access reviews, data validation, or timely notification of employee changes. If these complementary controls are missing, the provider\u2019s controls may not be sufficient to address the risk. Internal audit should identify relevant customer responsibilities and evaluate whether they operate effectively.<\/span><\/p>\n<p><b>Question 196.<\/b><\/p>\n<p><b>What is the primary purpose of reviewing cloud-service access controls?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Ensure every employee can access cloud resources<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate local authentication controls<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether access is authorized, appropriately restricted, and monitored<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace data classification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Determine whether access is authorized, appropriately restricted, and monitored<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud environments can contain sensitive data and powerful administrative functions. Internal audit may assess identity management, privileged access, multifactor authentication, role design, logging, access recertification, and termination processes. The control objective is to ensure users receive only the permissions necessary for legitimate responsibilities and that elevated activity is appropriately monitored.<\/span><\/p>\n<p><b>Question 197.<\/b><\/p>\n<p><b>What is the primary purpose of reviewing data encryption controls for sensitive information?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether information is protected against unauthorized disclosure during storage or transmission<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Guarantee that authorized users cannot access information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace access management<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate the need for data classification<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether information is protected against unauthorized disclosure during storage or transmission<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Encryption can reduce the risk that sensitive information is exposed if systems, devices, or communications are compromised. Internal audit may evaluate whether encryption requirements reflect data sensitivity, whether appropriate technologies and key-management controls are used, and whether exceptions are authorized. Encryption complements rather than replaces access control, monitoring, and other information-protection measures.<\/span><\/p>\n<p><b>Question 198.<\/b><\/p>\n<p><b>Which factor is MOST important when reviewing encryption key management?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether users can share keys freely<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether keys are securely generated, stored, accessed, rotated, and retired<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether encrypted files are larger than unencrypted files<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Whether the organization uses one key for every system indefinitely<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Whether keys are securely generated, stored, accessed, rotated, and retired<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Encryption can be undermined if the cryptographic keys are poorly protected. Effective key management addresses generation, storage, access restrictions, backup, rotation, revocation, and destruction. Internal audit may evaluate whether key-management responsibilities are appropriately segregated and whether unauthorized access to keys could compromise protected information.<\/span><\/p>\n<p><b>Question 199.<\/b><\/p>\n<p><b>What is the primary purpose of reviewing vulnerability-management processes?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Determine whether security weaknesses are identified, prioritized, remediated, and monitored according to risk<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Guarantee that software contains no vulnerabilities<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Replace incident response<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eliminate system patching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Determine whether security weaknesses are identified, prioritized, remediated, and monitored according to risk<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Vulnerability management helps reduce exposure by identifying weaknesses in systems and software and addressing them according to severity and business impact. Internal audit may review scanning coverage, risk classification, remediation timelines, exceptions, compensating controls, and overdue vulnerabilities. High-risk weaknesses affecting critical systems generally require stronger management attention and monitoring.<\/span><\/p>\n<p><b>Question 200.<\/b><\/p>\n<p><b>Which approach BEST supports effective internal audit assurance over resilience, third-party, and technology risks?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Review written policies without testing implementation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Rely entirely on vendor representations<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Evaluate business impact and recovery capability, third-party due diligence and monitoring, cloud and access controls, data protection, vulnerabilities, and supporting evidence<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Assume outsourced activities create no internal organizational risk<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Evaluate business impact and recovery capability, third-party due diligence and monitoring, cloud and access controls, data protection, vulnerabilities, and supporting evidence<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Resilience and technology risks are interconnected. Internal audit should evaluate whether critical activities can recover from disruption, whether third-party dependencies are identified and monitored, and whether technology controls protect systems and data. Assurance should be based on reliable evidence, including testing, monitoring results, contracts, system information, and independent reports where appropriate. Outsourcing transfers certain activities, but accountability for managing organizational risk remains with management.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full IIA IIA-CIA-Part2 Exam Dumps and Practice Test Dumps &nbsp; Question 181. What is the primary purpose of evaluating business continuity controls during an internal audit engagement? Determine whether critical operations can continue or be restored within acceptable timeframes following disruption Eliminate the possibility of operational interruption Replace disaster recovery planning Transfer continuity responsibility [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20550"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=20550"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20550\/revisions"}],"predecessor-version":[{"id":20551,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/20550\/revisions\/20551"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=20550"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=20550"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=20550"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}