Free IIA CIA Exam Braindumps (page: 102)

Which of the following is an example of sharing risk?

  1. An organization redesigned a business process to change the risk pattern.
  2. An organization outsourced a portion of its services to a third-party service provider.
  3. An organization sold an unprofitable business unit to its competitor.
  4. In order to spread total risk, an organization used multiple vendors for critical materials.

Answer(s): B



A records management system is an example of what type of control?

  1. Preventive.
  2. Detective.
  3. Corrective.
  4. Directive.

Answer(s): A



Which of the following procedures is not a step that an auditor would perform when planning an audit of an organization?

  1. Obtaining detailed knowledge about the organization.
  2. Obtaining a management representation letter.
  3. Assessing the audit risk of the organization.
  4. Having discussions with the organization's management team.

Answer(s): B



Which of the following risk assessment tools would best facilitate the matching of controls to risks?

  1. Control matrix.
  2. Internal control questionnaire.
  3. Control flowchart.
  4. Program evaluation and review technique (PERT) analysis.

Answer(s): A






Post your Comments and Discuss IIA CIA exam prep with other Community members:

CIA Exam Discussions & Posts