IIA-CIA-Part3 Exam Questions & Answers
Certified Internal Auditor-Internal Audit Knowledge Elements • IIA
100% money-back guarantee
Sample IIA-CIA-Part3 Questions
Practice with real exam-style questions, each with the verified correct answer and explanation.
Which of the following inventory costing methods requires the organization to account for the actual cost paid for the unit being sold?
The specific identification method is an inventory costing approach where the actual cost of each individual unit sold is recorded. This method is used when items are uniquely identifiable, such as in industries dealing with luxury goods, automobiles, or custom-manufactured products.
Correct Answer (D - Specific identification)
Under the specific identification method, each inventory unit is tracked separately, and its actual purchase cost is assigned to the cost of goods sold (COGS) when sold.
This method is commonly used for high-value, low-volume items where unique tracking is feasible.
The IIA's GTAG 8: Audit of Inventory Management explains how different costing methods impact financial reporting and internal controls.
Why Other Options Are Incorrect:
Option A (LIFO - Last-in, First-out):
LIFO assumes that the most recent (last-in) inventory is sold first, but it does not track actual unit cost. Instead, it assigns the cost of the newest inventory to COGS.
LIFO is often used for tax benefits but does not follow actual unit cost identification.
Option B (Average cost):
The weighted average cost method calculates an average cost for all inventory units rather than assigning actual unit costs.
This method smooths out price fluctuations but does not track specific items' costs.
Option C (FIFO - First-in, First-out):
FIFO assumes that the oldest (first-in) inventory is sold first, assigning its cost to COGS.
However, like LIFO, it does not track individual unit costs.
IIA GTAG 8: Audit of Inventory Management -- Explains different inventory costing methods, including specific identification.
IIA Practice Guide: Assessing Inventory Risks -- Covers inventory valuation and fraud risks.
Step-by-Step IIA Reference for Validation:Thus, the specific identification method (D) is the only one that accounts for the actual cost paid for each unit sold.
Which of the following IT-related activities is most commonly performed by the second line of defense?
Comprehensive and Detailed In-Depth
The Three Lines of Defense Model classifies risk management roles as follows:
First Line of Defense: Operational management responsible for risk controls (e.g., blocking unauthorized traffic, encrypting data).
Second Line of Defense: Risk management and compliance functions that monitor and assess the effectiveness of first-line controls (e.g., reviewing disaster recovery test results).
Third Line of Defense: Independent audit functions providing assurance (e.g., conducting security assessments).
Option C (Reviewing disaster recovery test results) aligns with the second line of defense because it involves oversight and evaluation of IT controls rather than direct execution.
Which of the following security controls would provide the most efficient and effective authentication for customers to access these online shopping account?
Two-level (or multi-factor) authentication (MFA) is the most efficient and effective security control for authenticating customers when accessing online shopping accounts. It provides an extra layer of security beyond just passwords, making it more difficult for unauthorized users to gain access.
Stronger Authentication -- It requires two independent verification methods, such as:
Something you know (password, PIN)
Something you have (one-time code, mobile device, smart card)
Something you are (biometric feature)
Reduces Risk of Credential Theft -- Even if hackers obtain a user's password, they still need the second factor to gain access.
Meets Regulatory Standards -- Many cybersecurity frameworks (NIST, ISO 27001, PCI-DSS) recommend or mandate MFA for customer authentication.
Enhanced Customer Trust -- Provides users with better security, reducing risks of fraud or account takeovers.
A . 12-digit password feature -- Longer passwords improve security, but they can still be compromised through phishing or brute force attacks.
B . Security question feature -- These are often weak because users choose predictable answers (e.g., mother's maiden name).
C . Voice recognition feature -- Biometric authentication is useful, but voice recognition can be bypassed using deepfake or recorded audio.
IIA's GTAG (Global Technology Audit Guide) on Information Security Management -- Recommends multi-factor authentication for access control.
IIA's International Professional Practices Framework (IPPF) -- Standard 2110.A2 -- Highlights the need for strong security controls to protect customer data.
NIST SP 800-63 (Digital Identity Guidelines) -- Encourages multi-factor authentication as a best practice for securing user accounts.
Why Two-Level Sign-On (MFA) Is the Best Choice?Why Not the Other Options?IIA Reference: Final Answe r: D. Two-level sign-on feature (Most effective for online customer
authentication).
Which of the following statements is true regarding change management?
Change management is a structured approach to transitioning individuals, teams, and organizations from a current state to a desired future state while minimizing risk and disruption.
Definition of Change Management:
Change management ensures that all modifications to IT systems, processes, and applications are controlled and documented.
As per the IIA GTAG on Change Management, an effective change management process should be repeatable, defined, and predictable to reduce errors and system failures.
Why Change Management Must Be Structured?
Uncontrolled changes increase risks such as security vulnerabilities, data loss, and system downtime.
Best practices (e.g., ITIL, COBIT) require organizations to follow a consistent change management process to protect the production environment.
A structured approach includes:
Documenting change requests
Testing in non-production environments
Gaining approvals before deployment
Why Not Other Options?
A . The degree of risk associated with a proposed change determines whether the change request requires authorization:
All changes should require authorization, not just high-risk ones.
B . Program changes generally are developed and tested in the production environment:
Changes should never be tested in production due to risk exposure. Best practice is to test in a development or staging environment first.
C . Changes are only required by software programs:
Change management applies broadly to IT infrastructure, business processes, security protocols, and governance frameworks, not just software.
IIA GTAG -- Change Management Controls
COBIT 2019 -- Change Management Best Practices
ITIL Change Management Framework
IIA Standard 2120 -- Risk Management
Step-by-Step Justification:IIA Reference:Thus, the correct and verified answer is D. To protect the production environment, changes must be managed in a repeatable, defined, and predictable manner.
On the last day of the year, a total cost of S 150.000 was incurred in indirect labor related to one of the key products an organization makes. How should the expense be reported on that year's financial statements?
Indirect labor costs incurred in the production process are treated as part of manufacturing overhead. Since the cost was incurred on the last day of the year, it is likely that the related products are still in inventory rather than being sold.
Under Generally Accepted Accounting Principles (GAAP) and International Financial Reporting Standards (IFRS), indirect labor costs associated with manufacturing should be included in the cost of inventory until the related goods are sold.
Once the goods are sold, the cost will be transferred to the cost of goods sold (COGS) in the income statement.
A . It should be reported as an administrative expense on the income statement. (Incorrect)
Indirect labor related to manufacturing is classified as part of manufacturing overhead, not an administrative expense.
B . It should be reported as a period cost other than a product cost on the management accounts. (Incorrect)
Indirect labor in production is a product cost (i.e., a cost that is included in inventory and matched with revenues when the product is sold).
Period costs refer to expenses like selling and administrative costs, which are expensed immediately.
C . It should be reported as cost of goods sold on the income statement. (Incorrect)
Since the cost was incurred on the last day of the year, the related products have likely not yet been sold, meaning the cost remains in inventory.
D . It should be reported on the balance sheet as part of inventory. (Correct)
Manufacturing overhead, including indirect labor, is included in inventory (work-in-process or finished goods) on the balance sheet until the goods are sold.
IIA Practice Guide: Auditing Inventory Management emphasizes that manufacturing costs, including indirect labor, should be allocated properly to inventory.
IIA Standard 2330 -- Documenting Information requires auditors to ensure proper financial reporting of costs in accordance with GAAP/IFRS inventory valuation principles.
IFRS (IAS 2 -- Inventories) and GAAP (ASC 330 -- Inventory) state that indirect production costs must be capitalized as inventory until sold.
Explanation of Answer Choices:IIA Reference:Thus, the correct answer is D. It should be reported on the balance sheet as part of inventory.
Get access to all 791 verified questions with detailed answers.
Unlock All IIA-CIA-Part3 Questions