
Free IIA-CRMA-ADV Braindumps Download Updated on Apr 27, 2024 with 285 Questions
IIA IIA-CRMA-ADV Exam Practice Test Questions
NEW QUESTION # 47
Forty-five percent of an organization's customer payments are submitted online. Eight percent of online payments are rejected. Executive management decides to outsource its online payment services to a contractor that will assume 75 percent of the total value of rejected payments. The organization estimates $1.25 million customer payments due during the contract period.
Which of the following represents the organization's residual risk for online customer payments due?
- A. $11, 250
- B. $45, 000
- C. $25, 000
- D. $33, 750
Answer: A
NEW QUESTION # 48
Which of the following actions should the audit committee take to promote organizational independence for the internal audit activity?
- A. Approve the annual budget and resource plan for the internal audit activity.
- B. Assist the CAE with hiring objective and competent internal audit staff.
- C. Delegate final approval of the risk-based internal audit plan to the chief audit executive (CAE).
- D. Encourage the CAE to communicate and coordinate with the external auditor.
Answer: C
NEW QUESTION # 49
Suspecting fraud, the chief financial officer (CFO) asked the internal audit activity to investigate a significant increase in travel related expenditures. Work was performed by a qualified internal auditor. Following the completion of the engagement, the chief audit executive (CAE) reported to the CFO that no violations were found and no fraud had occurred.
According to the Standards, which of the following principles did the CAE violate?
- A. Organizational independence.
- B. Individual objectivity.
- C. Proficiency.
- D. Due professional care.
Answer: D
NEW QUESTION # 50
Which of the following would provide the best evidence of errors in the quantities of items received from suppliers?
- A. Observation and inspection of inventory.
- B. Suppliers' reports of over shipments.
- C. Purchase requisitions and purchase orders.
- D. Warehouse receiving logs.
Answer: D
NEW QUESTION # 51
Which of the following is a valid statement about the use of visual observations during an audit engagement?
1. Visual observations can be used to detect ineffective controls, idle resources, and safety hazards.
2. Visual observations can be used during both preliminary survey and fieldwork stages of the audit engagement.
3. Visual observations can provide unsubstantiated facts to management if the internal auditor believes the information is useful.
4. Visual observations can assist an auditor in determining if a material observation should be communicated through informal means to the organization's senior management.
- A. 2 and 3 only
- B. 1 and 4 only
- C. 3 and 4 only
- D. 1 and 2 only
Answer: D
NEW QUESTION # 52
Which of the following statements describes a control failure that is not directly attributable to a customer billing application?
1. End users have raised a number of concerns regarding data integrity.
2. An untested program change is transferred from the test environment to production.
3. Purchase history does not reconcile with accounts receivable for some customers.
4. End user security is inadvertently granted to an unauthorized individual by management.
- A. 2 and 4.
- B. 1 and 4.
- C. 2 and 3.
- D. 1 and 3.
Answer: A
NEW QUESTION # 53
An internal audit activity includes in its audit reports the assertion that its work is performed in conformance with the International Standards for the Professional Practice of Internal Auditing {Standards). A recent external quality assessment concluded that the internal audit activity had substantial deficiencies that impact its overall operations. According to IIA guidance, which of the following is the most appropriate action for issuing future audit reports?
- A. Update and reissue previous audit reports, removing the assertion that the internal audit activity operates in conformance with the Standards, and distribute them to all parties who received the original reports.
- B. Refrain from indicating that the internal audit activity operates in conformance with the Standards until the chief audit executive confirms that the internal audit activity has addressed all areas of nonconformance and the audit committee has been notified.
- C. Refrain from indicating that the internal audit activity operates in conformance with the Standards until another external assessment confirms that the significant areas of nonconformance have been addressed.
- D. Indicate that the internal audit activity operates in partial conformance with the Standards, as the internal audit activity has a quality assurance and improvement program in place to address deficiencies and has met the requirement for conducting an external assessment.
Answer: C
NEW QUESTION # 54
An internal auditor uses a predefined macro provided in a popular spreadsheet application to verify the present value of the organization's investments. Which of the following is the most appropriate course of action regarding the auditor's use of this functionality?
- A. The auditor should accept the calculations generated by the function, as any further work or documentation would be inefficient.
- B. The auditor should tabulate the results in the spreadsheet to ensure the macro has generated the correct results for all calculations.
- C. The auditor should review the programming of the macro before its use to ensure that it is appropriate for the required calculations.
- D. The auditor should perform a manual recalculation of several results to validate and document the results.
Answer: D
NEW QUESTION # 55
The chief audit executive (CAE) has been asked to manage the regulatory compliance function for the organization's retail store operations. Store operations are included in the annual audit plan.
Which of the following strategies best fulfills the requirements of the Standards regarding these audits?
- A. The scope of store operations audits should exclude compliance.
- B. A store operations compliance audit should be performed by a staff internal auditor under the direction of the CAE.
- C. Store operations audits should be performed by an external service provider.
- D. Store operations audits can be fully executed with appropriate disclosure to the board.
Answer: C
NEW QUESTION # 56
What is the purpose of a secondary control?
- A. It replaces primary controls that are either ineffective or cannot fully mitigate a risk.
- B. lt combines with other controls to help reduce significant risk exposures to an acceptable level.
- C. It partially reduces the residual risk level when a key control does not operate effectively.
- D. It helps to ensure the completeness and accuracy of automated controls in a system environment.
Answer: B
NEW QUESTION # 57
The chief audit executive (CAE) is planning to conduct an internal assessment of the internal audit activity (IAA). Part of this assessment will include benchmarking. According to IIA guidance, which of the following qualitative metrics would be appropriate for the CAE to use?
1. Average client customer satisfaction score for a given year.
2. Client survey comments on how to improve the IAA.
3. Auditor interviews once an audit has been completed.
4. Percentage of audits completed within 90 days.
- A. 1 and 2.
- B. 3 and 4.
- C. 2 and 3.
- D. 1 and 3.
Answer: C
NEW QUESTION # 58
According to IIA guidance, which of the following best describes processes and tools typically used in ongoing internal assessments?
- A. Self-assessments and surveys of stakeholder groups.
- B. Report of internal assessment results, response plans, and outcomes.
- C. Benchmarking of the internal audit activity's practices and performance.
- D. Analysis of performance metrics such as cycle times.
Answer: D
NEW QUESTION # 59
Sometimes, internal audit staff may partner with operating managers to rank risks. Which of the following outcomes may be the most beneficial aspects of this strategy?
1. Reappraising risks levels.
2. Providing accurate information to management.
3. Marketing the internal audit activity.
4. Planning safeguards for assets in high-risk areas.
- A. 1 and 2.
- B. 3 and 4.
- C. 1 and 3.
- D. 2 and 3.
Answer: C
NEW QUESTION # 60
An internal auditor is reviewing the accounts receivable when she discovers account balances more than three years old. The auditor was previously supervising the area during this time, and she subsequently advises the chief audit executive (CAE) of a potential conflict.
Which of the following is the most appropriate course of action for the CAE to take?
- A. Continue with the present auditor, as more than one year has passed.
- B. Replace the auditor with another audit staff member.
- C. Withdraw the audit team and outsource the financial audit of the division.
- D. Work with the division's management to resolve the situation.
Answer: B
NEW QUESTION # 61
Which of the following actions does not violate the IIA Code of Ethics or Standards?
- A. An internal auditor disclosing details of an audit report to colleagues from a different organization.
- B. An internal auditor performing an audit on procedures that they were responsible for creating.
- C. An internal auditor disclosing confidential information in response to a lawsuit.
- D. An internal auditor performing an audit on an operation that they managed less than a year ago.
Answer: C
NEW QUESTION # 62
Which of the following is a detective control strategy against fraud?
- A. Requiring employees to attend ethics training.
- B. Performing a surprise audit.
- C. Performing background checks on employees.
- D. Implementing a control self-assessment.
Answer: B
NEW QUESTION # 63
Which of the following items should the chief audit executive disclose to senior management regarding the results of the internal audit activity's quality assessments?
- A. The internal audit activity's plan for resource allocation.
- B. The qualifications and independence of the assessment Team.
- C. The amount of the organization's potential loss prevented by the risk-based auditing of the internal audit activity.
- D. The number of audits from the annual internal audit plan that were completed last year.
Answer: C
NEW QUESTION # 64
An organization is beginning to implement an enterprise risk management program. One of the first steps is to develop a common risk language. Which of the following statements about a common risk language is true?
- A. Decision makers will understand that the likelihood of missing or ineffective controls will be reduced.
- B. Management will be able to reduce inherent risk because they will have a better understanding of risk.
- C. Stakeholders will have more assurance that the risks are assessed consistently.
- D. Internal auditors will be able to reduce their sample sizes because controls will be more consistent.
Answer: C
NEW QUESTION # 65
Which of the following is not one of the 10 core competencies identified in the IIA Competency Framework?
- A. Internal audit delivery.
- B. Business acumen.
- C. Governance, risk, and control.
- D. Performance management.
Answer: D
NEW QUESTION # 66
A new director was hired to lead the internal audit activity at a small start-up company. Which of the following assignments would impair the director's independence?
- A. Performing a pre-implementation review of the company's payroll application.
- B. Providing the COBIT framework as a possible IT management tool.
- C. Reviewing the company's policy for foreign currency translation adjustments for compliance with accounting standards.
- D. Preparing the financial statements for the company's defined contribution plan.
Answer: D
NEW QUESTION # 67
Given the highly technical and legal nature of privacy issues, which of the following statements best describes the internal audit activity's responsibility with regard to assessing an organization's privacy framework?
- A. The internal audit activity may delegate to nonaudit IT specialists the responsibility of determining whether personal information has been secured adequately and data protection controls are sufficient.
- B. If an organization does not have a mature privacy framework, the internal audit activity should assist in developing and implementing an appropriate privacy framework.
- C. The internal audit activity should have appropriate knowledge and competence to conduct an asses
.......framework. - D. Because the audit committee is ultimately responsible for ensuring that appropriate control processes are in place to mitigate risks associated with personal information, the internal audit activity is C. required to conduct privacy assessments.
Answer: C
NEW QUESTION # 68
Which of the following would be considered a violation of The IIA's mandatory guidance on independence?
- A. The CAE confirms to the board, at least once every five years, the organizational independence of the internal audit activity.
- B. The board seeks senior management's recommendation before approving the annual salary adjustment of the CAE.
- C. The chief audit executive (CAE) reports functionally to the board and administratively to the chief financial officer.
- D. The CAE updates the internal audit charter and presents it to the board for approval periodically, not on a specific timeline.
Answer: B
NEW QUESTION # 69
......
Updated Verified IIA-CRMA-ADV dumps Q&As - Pass Guarantee or Full Refund: https://pass4sures.free4torrent.com/IIA-CRMA-ADV-valid-dumps-torrent.html