IIA IIA-CRMA Exam
Certification in Risk Management Assurance (CRMA) Exam (Page 8 )

Updated On: 9-Feb-2026

Which of the following would be considered a preventive control?

  1. A library control log.
  2. A review of exception reports.
  3. A password lock on a server.
  4. A software scan of financial records for irregularities.

Answer(s): C



Which of the following are components of the COSO enterprise risk management framework?

1. Objective setting.
2. External environment.
3. Data collection.
4. Control activities.

  1. 1and3only
  2. 1and4only
  3. 2and3only
  4. 2and4only

Answer(s): B



According to IIA guidance, which of the following is the best example of a system application control?

  1. A physical security control over a data center.
  2. A system development lifecycle control.
  3. A program change management control.
  4. An input control over data integrity.

Answer(s): D



Which type of objectives can best be described as broad goals that promote the effective and efficient use of resources?

  1. Strategic objectives.
  2. Operational objectives.
  3. Reporting objectives.
  4. Compliance objectives.

Answer(s): B



An internal audit manager of a furniture manufacturing organization is planning an audit of the procurement process for kiln-dried wood. The procurement department maintains six procurement officers to manage 24 different suppliers used by the organization.

Which of the following controls would best mitigate the risk of employees receiving kickbacks from suppliers?

  1. The periodic rotation of procurement officers' assignments to supplier accounts.
  2. A pre-award financial capacity analysis of suppliers.
  3. An automated computer report, organized by supplier, of any invoices for the same amount.
  4. Periodic inventories of kiln-dried wood at the organization's warehouse.

Answer(s): A






Post your Comments and Discuss IIA IIA-CRMA exam prep with other Community members:

Join the IIA-CRMA Discussion