Which of the following network types should an organization choose if it wants to allow access only to its own personnel?
The management of working capital is most crucial for which of the following aspects of business?
Which type of bond sells at a discount from face value, then increases in value annually until it reaches maturity and provides the owner with the total payoff?
An internal auditor is reviewing the organization's performance appraisal process. Which of the following methods would be most effective to identify stereotyping?
Which of the following factors is considered a disadvantage of vertical integration?
Which of the following statements is true regarding the "management-by-objectives" method?
The board of directors wants to implement an incentive program for senior management that is specifically tied to the long-term health of the organization.
Which of the following methods of compensation would be best to achieve this goal?
An internal auditor performed a review of IT outsourcing and found that the service provider was failing to meet the terms of the service level agreement. Which of the following approaches is most appropriate to address this concern?
Which stage in the industry life cycle is characterized by many different product variations?
Which of the following performance measures would be appropriate for evaluating an investment center, which has responsibility for its revenues, costs, and investment base, but would not be appropriate for evaluating cost, revenue, or profit centers?
Which of the following should an organization consider when developing strategic objectives for its business processes?
1) Contribution to the success of the organization.
2) Reliability of operational information.
3) Behaviors and actions expected of employees.
4) How inputs combine with outputs to generate activities.
An internal auditor is reviewing physical and environmental controls for an IT organization. Which control activity should not be part of this review?
Which of the following describes a typical desktop workstation used by most employees in their daily work?
Which of the following authentication controls combines what a user knows with the unique characteristics of the user respectively?
The board has requested that the internal audit activity be involved in all phases of the organization's outsourcing of its network management. During which of the following stages is the internal auditor most likely to verify that the organization's right-to-audit clause is drafted effectively?
Which of the following is an example of a key systems development control typically found in the in-house development of an application system?
Which of the following statements is most accurate with respect to various forms, elements, and characteristics of business contracts?
Organizations mat adopt just-in-time purchasing systems often experience which of the following?
Which of the following is a primary objective of the theory of constraints?
With regard to disaster recovery planning, which of the following would most likely involve stakeholders from several departments?
Which of the following performance measures includes both profits and investment base?
While conducting audit procedures at the organization's data center, an internal auditor noticed the following:
Backup media was located on data center shelves.
Backup media was organized by date.
Backup schedule was one week in duration.
The system administrator was able to present restore logs.
Which of the following is reasonable for the internal auditor to conclude?
Which of the following is the first step an internal audit activity should undertake when executing a data analytics process?
Which of the following types of data analytics would be used by a hospital to determine which patients are likely to require readmittance for additional treatment?
An organization is considering outsourcing its IT services, and the internal auditor is assessing the related risks. The auditor grouped the related risks into three categories:
Risks specific to the organization itself.
Risks specific to the service provider.
Risks shared by both the organization and the service provider.
Which of the following risks should the auditor classify as specific to the service provider?
Which of the following application controls checks the integrity of data entered into a business application?
In an organization's established accounts payable department employees perform highly structured activities follow clearly defined procedures and have strict deadlines for performing their tasks The head of the department recently retired, and a new department head was hired To achieve the greatest benefit for this department and avoid redundancy the new leader should adopt which of the following leadership styles?
Which of the following is a primary driver behind the creation and prioritization of new strategic initiatives established by an organization?
In an effort to increase business efficiencies and improve customer service offered to its major trading partners, management of a manufacturing and distribution company established a secure network, which provides a secure channel for electronic data interchange between the company and its partners.
Which of the following network types is illustrated by this scenario?
According to HA guidance or IT which of the following spreadsheets is most likely to be considered a high-risk user-develop application?
An organization had a gross profit margin of 40 percent in year one and in year two. The net profit margin was 18 percent in year one and 13 percent in year two.
Which of the following could be the reason for the decline in the net profit margin for year two?
According to IIA guidance, which of the following best describes the activities that occur during the conversion phase of an IT project?
An organization produces two products, X and Y. The materials used for the production of both products are limited to 500 kilograms (kg) per month. All other resources are unlimited and their costs are fixed. Individual product details are as follows:
Product X
Product Y
Selling price per unit
$10
$13
Materials per unit (at $1/kg)
2 kg
6 kg
Monthly demand
100 units
120 units
In order to maximize profit, how much of product Y should the organization produce each month?
All of the following are possible explanations for a significant unfavorable material efficiency variance except:
Which of the following is not a method for implementing a new application system?
According to the International Professional Practices Framework, internal auditors who are assessing the adequacy of organizational risk management processes should not:
Multinational organizations generally spend more time and effort to identify and evaluate:
Maintenance cost at a hospital was observed to increase as activity level increased. The following data was gathered:
Activity Level -
Maintenance Cost
Month
Patient Days
January
5,600
$7,900
February
7,100
$8,500
March
5,000
$7,400
April
6,500
$8,200
May
7,300
$9,100
June
8,000
$9,800
If the cost of maintenance is expressed in an equation, what is the independent variable for this data?
The internal audit activity completed an initial risk analysis of the organization's data storage center and found several areas of concern. Which of the following is the most appropriate next step?
In which type of business environment are price cutting strategies and franchising strategies most appropriate?
Which of the following methods, if used in conjunction with electronic data interchange (EDI), will improve the organization's cash management program, reduce transaction data input time and errors, and allow the organization to negotiate discounts with EDI vendors based on prompt payment?
An organization accumulated the following data for the prior fiscal year:
Value of Percentage of
Quarter
Output Produced
Cost X
1
$4,750,000
2.9
2
$4,700,000
3.0
3
$4,350,000
3.2
4
$4,000,000
3.5
Based on this data, which of the following describes the value of Cost X in relation to the value of Output Produced?
Which of the following statements is true regarding the resolution of interpersonal conflict?
Where complex problems need to be addressed, which of the following communication networks would be most appropriate?
The process of scenario planning begins with which of the following steps?
A small furniture-manufacturing firm with 100 employees is located in a two-story building and does not plan to expand. The furniture manufactured is not special-ordered or custom-made. The most likely structure for this organization would be:
Which of the following are included in ISO 31000 risk principles and guidelines?
Within an enterprise, IT governance relates to the:
1) Alignment between the enterprise's IT long term plan and the organization's objectives.
2) Organizational structures of the company that are designed to ensure that IT supports the organization's strategies and objectives.
3) Operational plans established to support the IT strategies and objectives.
4) Role of the company's leadership in ensuring IT supports the organization's strategies and objectives.
Which of the following statements regarding database management systems is not correct?
Which of the following statements regarding program change management is not correct?
Which of the following is false with regard to Internet connection firewalls?
The decision to implement enhanced failure detection and back-up systems to improve data integrity is an example of which risk response?
Which of the following phases of a business cycle are marked by an underuse of resources?
1) The trough.
2) The peak.
3) The recovery.
4) The recession.
When assessing the adequacy of a risk mitigation strategy, an internal auditor should consider which of the following?
1) Management’s tolerance for specific risks.
2) The cost versus benefit of implementing a control.
3) Whether a control can mitigate multiple risks.
4) The ability to test the effectiveness of the control.
An organization is considering mirroring the customer data for one regional center at another center. A disadvantage of such an arrangement would be:
According to Porter's model of competitive strategy, which of the following is a generic strategy?
1 Differentiation.
2) Competitive advantage.
3) Focused differentiation.
4) Cost focus.
Which of the following statements is true regarding the roles and responsibilities associated with a corporate social responsibility (CSR) program?
A retail organization is considering acquiring a composite textile company. The retailer's due diligence team determined the value of the textile company to be $50 million. The financial experts forecasted net present value of future cash flows to be $60 million. Experts at the textile company determined their company's market value to be $55 million if purchased by another entity. However, the textile company could earn more than $70 million from the retail organization due to synergies. Therefore, the textile company is motivated to make the negotiation successful. Which of the following approaches is most likely to result in a successful negotiation?
Which of the following concepts of managerial accounting is focused on allocating overheads to products?
Which of the following statements is true regarding an organization's servers?
Which of the following types of analytics would be used by an organization to examine metrics by business units and identity the most profitable business units?
Based on lest results an IT auditor concluded that the organization would suffer unacceptable toss of data if there was a disaster at its data center. Which of the following test results would likely lead the auditor to this conclusion?
An internal auditor computed that one of the organization's accounting divisions is processing 30 travel reports per hour while another accounting division is processing 22 travel reports per hour.
Which of the following efficiency measures did the internal auditor most likely employ?
A restaurant deeded to expand its business to include delivery services rather than relying on third-party food delivery services. Which of the following best describes the restaurant's strategy?