
合格させるIIA-CIA-Part2テスト問題集で[2026年02月04日]に更新された712問あります
IIA IIA-CIA-Part2実際の問題と100%カバー率でリアル試験問題
質問 # 191
While performing an audit of the human resources department, an internal auditor discovered unencrypted files containing the personal information of employees stored on a public shared drive. According to IIA guidance, which of the following actions by the auditor would be the most appropriate?
- A. Immediately review the audit logs to see if anyone has accessed this information and follow-up.
- B. Remove the files containing the social security numbers and personal information.
- C. Communicate the issue to the chief audit executive as well as IT and legal departments.
- D. Change permissions to the shared drive to only allow access to human resources personnel.
正解:C
質問 # 192
An organization experiencing staff shortages wants to contract a temporary employee to assist with work in the accounting office. Which of the following controls should be in place to ensure the temporary employee performs the assigned work before payment is issued?
- A. Payments to the vendor are analyzed monthly to ensure they do not exceed the amount approved on the purchase order
- B. A member of management approves the purchase requisition before the temporary employee begins work
- C. A scope of work for the temporary employee is included in the purchase requisition and signed by the organization
- D. A three-way match between the invoice, purchase requisition, and documentation of receipt of services
正解:D
解説:
Comprehensive and Detailed Explanation:
The three-way match (A) is the most effective control to ensure that services have been received and align with both requisition and invoicing. For temporary employees, this means verifying that hours worked or services provided match the purchase requisition and that an invoice is only paid if supported by documentation of services received.
* Option B (management approval) ensures authorization but not service completion.
* Option C provides clarity but is not a control for verifying actual work.
* Option D ensures budgetary compliance but does not prevent overpayment for unperformed services.
Thus, the strongest control is Option A, ensuring validity, accuracy, and completeness of vendor payments.
質問 # 193
Which of the following examples of audit evidence is the most persuasive?
- A. Canceled checks written by the treasurer and returned from a bank.
- B. Real estate deeds, which were properly recorded with a government agency.
- C. Vendor invoices filed by the accounting department.
- D. Time cards for employees, which are stored by a manager.
正解:B
解説:
Section: Volume C
質問 # 194
Which of the following is an advantage of utilizing an external fraud specialist in a suspected fraud investigation?
- A. Increased ability to preserve evidence and the chain of command.
- B. Increased access to the organization's software and proprietary data.
- C. Increased ability to scrutinize the organization's key business processes.
- D. Increased access to the organization's employees.
正解:A
解説:
Utilizing an external fraud specialist in a suspected fraud investigation offers several advantages, particularly in preserving evidence and maintaining the chain of command. This is crucial for ensuring that the investigation is conducted legally and that any findings can be used in potential legal proceedings.
* Expertise in Evidence Handling:
* External fraud specialists typically have specific expertise in collecting, preserving, and documenting evidence in a manner that maintains its integrity. This includes maintaining a proper chain of custody, which is essential for legal admissibility.
* IIA Practice Guide on Fraud Investigations:
* The IIA suggests that involving specialists can enhance the credibility and effectiveness of an investigation. Specialists are trained to handle sensitive evidence and ensure that it is preserved correctly, reducing the risk of contamination or loss.
* Chain of Command:
* Maintaining a clear and secure chain of command during an investigation is critical. An external specialist is often better equipped to manage this process, ensuring that evidence is not tampered with and that all actions are documented appropriately.
* Option A (Increased access to employees): While an external specialist may interview employees, this is not their primary advantage over internal auditors.
* Option C (Increased ability to scrutinize processes): Specialists are skilled at this, but the key advantage lies in evidence preservation.
* Option D (Increased access to software and data): Access to proprietary data is important, but internal auditors usually have this access as well.
Detailed Explanation:Why Not Other Options?
質問 # 195
During a fraud interview, it was discovered that unquestioned authority enabled a vice president to steal funds from the organization. Which of the following best describes this condition?
- A. Opportunity.
- B. Scheme.
- C. Pressure.
- D. Rationalization.
正解:A
質問 # 196
Which of the following represents a ratio that measures short-term debt-paying ability?
- A. Profit margin
- B. Times interest earned
- C. Debt-to-equity ratio
- D. Current ratio
正解:D
解説:
Comprehensive and Detailed Explanation From Exact Extract:
The current ratio = Current Assets ÷ Current Liabilities. This is a key liquidity measure, showing an organization's ability to pay short-term obligations with short-term assets.
* Debt-to-equity (A) measures leverage.
* Profit margin (B) measures profitability.
* Times interest earned (D) measures ability to cover interest expense.Thus, the correct ratio for short- term debt-paying ability is the current ratio.
質問 # 197
An internal auditor performed a test of controls and found that a statistically selected representative sample of recorded transactions within the account receivables ledger had an error rate that was within management expectations. The associated revenue account was outside the scope of the audit engagement. How should the conclusion to this engagement be reported?
- A. Positive assurance could be provided for the effectiveness of the accounts receivable controls.
- B. The auditor should state that controls over the recording of transactions in the revenue account are operating effectively.
- C. The auditor should state that the error rate was within the selected confidence level.
- D. Negative assurance should be provided, as the associated revenue account was not examined.
正解:A
解説:
In this scenario, the internal auditor performed a test of controls on the accounts receivable ledger and found that the error rate was within management's expectations. Since the audit focused on the accounts receivable controls, the conclusion should be specific to the scope of the engagement. The auditor can provide positive assurance about the effectiveness of the controls over the recording of transactions in the accounts receivable ledger, as the evidence gathered supports this conclusion.
IIA References:
* IIA Standard 2410: Criteria for Communicating states that communications must include the engagement's objectives and scope as well as applicable conclusions, recommendations, and action plans. Since the engagement was focused on accounts receivable, the assurance provided should relate specifically to the controls in that area.
* The Practice Guide on Communicating Results emphasizes that conclusions and assurance should be directly related to the scope of the engagement and the evidence obtained.
質問 # 198
Which of the following actions best describes an internal auditor's use of test data to determine whether an organization's new accounts payable system avoids processing questionable invoices for payment?
- A. Using an automated system that assists internal auditors with automating the risk analysis of the computer program for invoicing
- B. Embedding tools in the computer program to analyze the review processes of invoices for potential issues that may hamper payments
- C. Creating an automated tool that monitors the computer program on a daily basis for potential issues that need corrective actions.
- D. Adding invoices to the computer program to assess the reliability and effectiveness of the review process and whether controls work.
正解:D
解説:
Adding invoices to the computer program to assess the reliability and effectiveness of the review process and whether controls work best describes an internal auditor's use of test data. This approach involves introducing test data into the system to evaluate how well the system processes invoices and whether it effectively identifies and prevents questionable invoices from being processed for payment.
Reference:
IIA Standards: 1220.A2 - Proficiency and Due Professional Care
IIA Practice Guide: Use of Technology in Auditin
質問 # 199
Which of the following is true about surveys?
- A. A survey with closed-ended questions can produce quantifiable evidence
- B. A survey, like inspections and confirmations are best used to test the operating effectiveness of controls
- C. A survey's participants are likely to volunteer information that was not specifically requested
- D. A survey with open-ended questions is weaker than a structured interview
正解:A
解説:
A survey with closed-ended questions can produce quantifiable evidence. Closed-ended questions limit responses to predefined options, making it easier to analyze and quantify the results. This type of survey is effective in gathering specific, comparable data from respondents.
References:
* IIA Practice Guide: Survey Methods in Internal Auditing
* IIA Standards: 2310 - Identifying Information
質問 # 200
An internal auditor developed a list of internal and external risk considerations across the organization's processes, developed a scale to assess each risk and allocated the relative importance of each risk. When of the following approaches did the auditor take?
- A. Risk-factor approach
- B. Bottom up approach
- C. Process-Metrix approach
- D. Top-down approach
正解:A
解説:
The risk-factor approach involves developing a list of internal and external risk considerations, creating a scale to assess each risk, and allocating the relative importance of each risk. This approach allows the auditor to systematically evaluate risks based on predefined criteria and weightings, ensuring a comprehensive risk assessment across the organization's processes.
References:
* The Institute of Internal Auditors (IIA) Standards
* Risk Assessment Methodologies in Internal Auditing
質問 # 201
Which of the following would be the least important reason for a company to merge with another company?
- A. To increase stock prices.
- B. To reduce labor costs.
- C. To diversify risk.
- D. As a response to new government policy.
正解:A
解説:
Section: Volume B
質問 # 202
A chief audit executive (CAE) reviews the supervision of an internal audit engagement Which of the following would most likely assure the CAE that the engagement had adequate supervision?
- A. The supervisor reviews weekly progress reports from the audit team members
- B. The supervisor meets periodically with management in the reviewed area to get feedback during the engagement.
- C. The engagement supervisor has an open door pokey for audit team members to discuss concerns
- D. The supervisor reviews and initials internal audit workpapers for the engagement
正解:D
解説:
Reviewing and initialing internal audit workpapers ensures that the engagement has adequate supervision.
This practice demonstrates that the supervisor has reviewed the work performed by the audit team, verified the accuracy and completeness of the documentation, and provided necessary guidance. It is a critical step in the quality assurance process, ensuring that the audit findings and conclusions are supported by sufficient and appropriate evidence.References:
* Institute of Internal Auditors (IIA), International Standards for the Professional Practice of Internal Auditing (Standards), Standard 2340 - Engagement Supervision.
質問 # 203
Management requested internal audit consulting services. During fieldwork significant control issues were identified by the internal audit team. Which of the following is an appropriate response from the chief audit executive?
- A. Mutually agree with the engagement client on corrective actions
- B. Focus on the consulting engagement and schedule an assurance engagement next to address the control issues
- C. End the consulting engagement and report the results to management as planned
- D. Report the significant control issues to senior management and the board and recommend corrective action
正解:D
解説:
When significant control issues are identified during a consulting engagement, it is the responsibility of the chief audit executive to ensure that these issues are communicated to senior management and the board. This ensures that the organization is aware of the risks and can take corrective action. Consulting engagements should not overshadow the priority of addressing critical control issues that may affect the organization's risk profile. References:
* "International Standards for the Professional Practice of Internal Auditing" (IIA Standards)
* "Internal Auditing: Assurance & Advisory Services" (The Institute of Internal Auditors)
質問 # 204
An auditor is using an internal control questionnaire as part of a preliminary survey. Which of the following is the best reason for the auditor to interview management regarding the questionnaire responses?
- A. Interviewing is the least costly audit technique when a large amount of information is involved.
- B. Interviews are the most efficient way to upgrade the information to the level of objective evidence.
- C. Interviewing is the only audit procedure which does not require confirmation of the information that is obtained.
- D. Interviews provide the opportunity to insert questions to probe promising areas.
正解:D
解説:
Section: Volume A
質問 # 205
A recent survey indicated that residents of a small town take the train to a nearby city eight times per month, on average. The same survey showed that the number of train trips that a resident takes per month (y) is determined by the number of days per month that the resident works in the nearby city (x), according to the equation: y = 2 + 2x. A person who never works in the nearby city is expected to take the train:
- A. Zero times per month.
- B. Four times per month.
- C. Eight times per month.
- D. Two times per month.
正解:D
解説:
Section: Volume B
質問 # 206
Which of the following processes real-transaction data through auditor-developed test programs?
- A. Parallel simulation.
- B. Generalized audit software.
- C. Tracing.
- D. Mapping.
正解:A
質問 # 207
When estimating the impact of an inherent risk, which of the following should internal auditors consider?
- A. Financial and nonfinancial factors related to the risk
- B. The residual risk following implementation of appropriate controls
- C. The probability and frequency of occurrence
- D. The number of risks identified on the heat map
正解:A
解説:
When estimating the impact of an inherent risk, internal auditors should consider both financial and nonfinancial factors. Financial factors include direct monetary impacts, while nonfinancial factors may include reputational damage, operational disruptions, and compliance issues. Considering a broad range of factors provides a comprehensive understanding of the potential impact of the risk, which is essential for effective risk assessment and management.
References:
* Institute of Internal Auditors (IIA) Standards: Performance Standards 2120: Risk Management
* COSO Enterprise Risk Management (ERM) Framework: Risk Assessment and Risk Response Components
質問 # 208
If an organization's chief audit executive wants to implement continuous auditing, what is the appropriate order in which key steps should be undertaken?
I.Identify business applications that require access.
II.
Implement steps to continuously assess risks and controls.
III.
Define objectives of continuous auditing.
IV.
Manage and report results.
- A. III, I, II, IV.
- B. III, I, IV, II.
- C. II, III, I, IV.
- D. II, I, III, IV.
正解:A
質問 # 209
Which of the following would be most useful for an internal auditor to obtain during the preliminary survey of an engagement on internal controls over user access management?
- A. The policy for granting, modifying, and deleting user access to ensure processing requirements are clearly articulated.
- B. A sample of change request forms to verify whether the forms bear the required approval for the user access change.
- C. User access reports that were reviewed by management to ensure that access rights are appropriate for employee roles.
- D. A current listing of system users and an employee listing to determine whether system users are active employees of the organization.
正解:A
解説:
Step-by-Step Detailed Explanation:
A . The policy for granting, modifying, and deleting user access:
Correct. Understanding the policy ensures the auditor knows the framework and controls in place.
B . A sample of change request forms:
Useful for testing but not as foundational as reviewing the policy.
C . User access reports reviewed by management:
This evaluates monitoring but does not establish a baseline understanding of controls.
D . A current listing of system users and employees:
Important for reconciliation but secondary to understanding the control framework.
CIA Exam Syllabus Reference:
Domain V: Performing Internal Audit Services - Preliminary Surveys.
質問 # 210
During a routine audit of a customer service hotline, an internal auditor noticed that an unusually high number of customer complaints pertained to payments not being applied to the customers' accounts. Which of the following would most likely be the reason for the high volume of complaints?
- A. Poor controls in the invoice approval processes.
- B. An ineffective customer service department.
- C. Submission of fraudulent expense reports.
- D. Check tampering by an employee.
正解:D
質問 # 211
Which of the following statements about assurance maps is correct?
- A. An assurance map is a picture of all assurance engagements performed by the internal audit activity across the organization
- B. An assurance map is used by the chief audit executive to coordinate assurance activities with other internal and external assurance providers
- C. An assurance map lists the procedures and testing activities performed by an internal audit team during an assurance engagement
- D. An assurance map is used by the engagement supervisor to coordinate the roles of various internal audit team members assigned to assurance engagements
正解:B
解説:
An assurance map is a tool used by the chief audit executive (CAE) to provide a visual representation of the assurance activities performed by various assurance providers within the organization, including internal audit, compliance, risk management, and external auditors. It helps in identifying areas of overlap, gaps in assurance coverage, and ensuring efficient and effective coordination among different assurance providers. References:
* The IIA's Practice Guide on Coordinating Risk Management and Assurance.
質問 # 212
Management has asked the internal audit activity to perform an operational audit of a division that recently reported an increase in expenditures in addition to a decrease in profits. However, existing internal audit resources are currently engaged in a legal compliance audit. Which factor would be considered least important in deciding whether resources should be removed from the legal compliance audit to the operational audit?
- A. The potential for regulatory fines associated with the legal compliance audit.
- B. The results of the external auditor's most recent financial audit.
- C. The probability that the legal compliance audit will detect fraud.
- D. The increase in expenditures at the division over the past year.
正解:B
質問 # 213
Which of the following is true regarding the monitoring of internal audit activities?
- A. The chief audit executive must develop all monitoring policies related to the activity
- B. Both large and small audit departments must have written policies on monitoring.
- C. The board of directors is responsible for the establishment of monitoring polities
- D. The form and content of monitoring policies could vary by industry
正解:D
解説:
The form and content of monitoring policies can indeed vary depending on the industry and the specific requirements of the organization. While all internal audit activities require some level of monitoring to ensure effectiveness and compliance with standards, the specific approach and documentation may differ based on industry norms, regulatory requirements, and organizational size and complexity.
References:
* The Institute of Internal Auditors (IIA) Practice Guide: Quality Assurance and Improvement Program
* IIA Standard 1300 - Quality Assurance and Improvement Program
質問 # 214
......
IIA-CIA-Part2試験は、内部監査士協会(IIA)が提供する認定試験の一つです。この試験は、内部監査の実践における内部監査士の知識とスキルをテストするために設計されています。この試験は、内部監査士の標準としてグローバルに認められているCertified Internal Auditor(CIA)認定プログラムの一部であり、内部統制、リスク管理、ガバナンス、詐欺リスクなどのトピックをカバーしています。これらのトピックとその実際のシナリオでの応用について深い理解が必要な厳しい試験です。
IIA-CIA-Part2 試験は、内部監査のキャリアを追求したい個人にとって重要な資格です。この資格を取得することにより、候補者の内部監査の実践に関する知識と技能が証明され、どの組織においても重要な機能となります。また、この資格は候補者の信頼性と市場価値を高め、潜在的雇用主からより魅力的な存在となるでしょう。
IIA IIA-CIA-Part2リアルな2026年最新のブレーン問題集で模擬試験問題集:https://www.goshiken.com/IIA/IIA-CIA-Part2-mondaishu.html
IIA-CIA-Part2無料試験問題と解答PDF更新されたのは2026年02月:https://drive.google.com/open?id=1hAMSUXCb0RxwOxZfMx8F8_2goC2Kcvof