1 / 5 Exam : CIA-Part1-2025 Title : https://www.passcert.com/CIA-Part1-2025.html CIA Part 1 - Internal Audit Fundamentals 2 / 5 1.During the planning stage of an assurance engagement, the engagement supervisor initially reviews the control environment to identify and examine possible fraud risks. Which finding should be considered a potential red flag? A. Senior management reinforces the code of ethics. B. Senior management sets unattainable business targets. C. Senior management reiterates the whistleblowing policy. D. Senior management does not have a succession plan. Answer: B 2.An organization is considering the acquisition of a target organization. Senior management asks the internal audit function to advise on the target organization ’ s information security practices. What type of internal audit service is this? A. System development. B. Process reengineering. C. Due diligence. D. Benchmarking. Answer: C 3.What should the internal audit function promote to most effectively deter fraud? A. Fraud data mining. B. Fraud risk assessments. C. Whistleblowing mechanisms. D. Ethical culture. Answer: D 4.Which control is meant to prevent fraud? A. A whistleblower hotline for reporting fraud anonymously. B. A periodic presentation to the entire organization to elevate fraud resilience culture. C. A year-end reconciliation of significant accounts and general ledgers. D. A review of exceptions approved by management for alignment with delegated authority. Answer: B 5.Which of the following options would include the policies and procedures that help ensure management ’ s risk responses are accomplished? A. Information and communication. B. Control activities. C. Risk assessment. D. Monitoring. Answer: B 6.Which of the following is the appropriate next step after management identifies and implements risk responses? A. Prioritize risks. B. Assess the severity of risks. 3 / 5 C. Develop a portfolio view of risks. D. Measure the velocity of risks. Answer: C 7.Which responsibility is most appropriate for the internal audit function, according to the Global Internal Audit Standards? A. Reporting internal audit engagement findings to regulatory agencies. B. Providing risk-based advice to the organization ’ s stakeholders. C. Conducting accounting audit engagements as requested by the chief financial officer. D. Designing and implementing new organizational policies. Answer: B 8.Which of the following statements is true regarding assurance and advisory services provided by an internal audit function? A. When internal auditors are performing an advisory engagement, they always focus on the organization as a whole. B. When internal auditors are performing advisory engagements, they focus only on areas not covered by assurance engagements. C. Advisory services are mainly applicable during the planning stages of projects to assess relevant risks. D. The type of information required depends on whether the engagement is assurance or advisory. Answer: D 9.What should an internal audit function do when performing an advisory engagement for an organization? A. Document an understanding with management of the area under review regarding objectives, scope, respective responsibilities, and other expectations for all engagements. B. Agree with management of the area under review regarding the nature and scope of the engagement. C. Assume managerial responsibility when performing the advisory engagement. D. Develop an annual advisory plan per the results of a risk assessment by internal audit function. Answer: B 10.The organization discusses the need to change its accounting software In which of the following stages would an internal auditor ’ s advisory review most benefit the organization? A. Pre-release stage. B. Implementation stage. C. Post-release stage. D. Conceptual stage. Answer: D 11.What must a chief audit executive do if significant changes to regulations may affect the nature of internal audit services? A. Discuss the changes with the external auditors. 4 / 5 B. Discuss the changes with the CEO, who is responsible for escalating to the board. C. Discuss the changes with the board and senior management. D. No action is needed because the changes are unlikely to affect the work of internal auditors. Answer: C 12.Who is responsible for the design and implementation of the processes and structures for organizational governance? A. The board. B. The CEO. C. The chief financial officer D. Operational management. Answer: A 13.Which of the following is the primary reason that the quality assurance and improvement program should be detailed in the internal audit charter? A. To justify training costs in the internal audit function ’ s annual budget. B. To demonstrate the intent to fulfill responsibilities with proficiency and due professional care. C. To conform with mandatory IIA guidance regarding internal audit charters. D. To describe the significance of internal audit independence and the activities promoting it. Answer: B 14.Which of the following statements related to organization wide risk management and control is true? A. Organizationwide risk management is a function or department. B. Organizationwide risk management addresses more than internal control. C. Organizationwide risk management sets adequate controls to ensure all risks are avoided. D. Organizationwide risk management is the checklist used during the risk and control self-assessment exercise. Answer: B 15.An internal auditor is working on an audit engagement of the inventory management process. There have been difficulties getting explanations from stakeholders regarding discrepancies between physical and system inventory records. Recently, the engagement supervisor informed the internal auditor that there was a whistleblowing report alleging that inventory theft was occurring. Which of the following skills and competencies would be most helpful for the internal auditor to fulfill the responsibilities of this audit engagement? A. The ability to investigate fraud, pursue litigation, and recover assets. B. The ability to understand the characteristics of fraud and the techniques used to commit fraud, and the various fraud schemes and scenarios. C. The ability to remain objective, calm, and rational during the audit engagement and the whistleblowing investigation. D. The ability to be agile and incorporate new risks when they are identified. Answer: B 16.Which of the following audit types will be most applicable if senior management believes that the 5 / 5 ongoing enterprise wide resource planning system development project is not progressing well and actual costs exceed budgeted ones? A. Readiness assessment. B. Project management methodology assessment. C. Risk assessment D. A post-implementation review. Answer: B 17.An internal auditor interviews for a position within the organization ’ s IT department while simultaneously conducting an audit of the area ’ s ability to manage the organization ’ s user network accounts This presents a conflict of which of the following principles? A. Confidentiality. B. Objectivity. C. Competency. D. Integrity. Answer: B 18.Which of the following will help the chief audit executive (CAE) of a large organization ensure that the independence of the internal audit function is maintained? A. The board is required to approve the salary package for all audit staff. B. The internal audit charter is approved by the CAE. C. The internal audit budget and resource plan are approved by the board. D. The decision regarding the appointment or termination of the CAE belongs to the CEO. Answer: C 19.Which of the following statements is true regarding organization wide risk management? A. Risk management is a function centralized at the top-level of management. B. Risk management centers on inventorying the applicable risks to the organization. C. Risk management is complementary to the system of internal controls. D. Risk management centers on governance and culture. Answer: C 20.An organization uses hedging to address foreign currency risk. Which of the following best describes this risk strategy? A. Avoidance. B. Acceptance. C. Reduction. D. Sharing. Answer: D