IIA-CIA-Part3-KR 문제 166
* Vertical integration is a business strategy where a company expands its operations into different stages of its supply chain.
* In this case, the chocolate-producing company is moving upstream by producing its own milk rather than purchasing it from suppliers.
* Why This Is Vertical Integration:
* The company controls more of its supply chain, reducing dependency on external suppliers.
* Benefits include:
* Cost savings on raw materials (by producing instead of buying).
* Improved quality control (since the company controls milk production).
* Greater market control (reducing reliance on third-party vendors).
* Why Other Options Are Incorrect:
* B. Unrelated diversification - Incorrect.
* Unrelated diversification occurs when a company expands into a completely different industry (e.g., a chocolate company entering the technology sector).
* C. Differentiation - Incorrect.
* Differentiation refers to creating unique products to gain a competitive advantage, but the strategy here is about controlling supply, not product uniqueness.
* D. Focus - Incorrect.
* Focus strategy targets a narrow market segment, but this scenario involves expanding into the supply chain, not focusing on a niche.
* IIA's Perspective on Business Strategy and Risk Management:
* IIA Standard 2120 - Risk Management requires auditors to assess the risks and benefits of vertical integration strategies.
* COSO ERM Framework advises monitoring operational and financial risks associated with supply chain integration.
* Porter's Value Chain Model supports vertical integration as a way to enhance operational efficiency and cost control.
IIA References:
* IIA Standard 2120 - Risk Management in Business Strategy
* COSO ERM - Managing Vertical Integration Risks
* Porter's Value Chain Model - Supply Chain Control
Thus, the correct and verified answer is A. Vertical integration.
IIA-CIA-Part3-KR 문제 167
* A cash budget is a financial plan that outlines expected cash inflows and outflows over a specific period.
* The financing section records activities related to borrowing, repaying debt, issuing securities, and managing interest payments.
* Why Debt and Interest Payments Belong in the Financing Section:
* Debt repayment (principal and interest) is a financial activity rather than an operational or investing activity.
* Companies must plan for financing costs to ensure liquidity and compliance with loan agreements.
* Why Other Options Are Incorrect:
* A. Collections from customers - Incorrect.
* Customer payments belong in the operating section of the cash budget, as they represent core business activities.
* B. Sale of securities - Incorrect.
* The sale of securities is an investing activity unless related to issuing new debt or equity.
* C. Purchase of trucks - Incorrect.
* Buying trucks is a capital expenditure, which belongs in the investing section of the cash budget.
* IIA's Perspective on Financial Planning and Budgeting:
* IIA Standard 2120 - Risk Management requires organizations to assess financial risks, including debt repayment obligations.
* COSO ERM Framework highlights the importance of cash flow forecasting to maintain financial stability.
* GAAP and IFRS Financial Reporting Standards classify debt repayment and interest under financing activities.
IIA References:
* IIA Standard 2120 - Risk Management & Cash Flow Oversight
* COSO ERM - Financial Planning and Liquidity Management
* GAAP & IFRS - Cash Flow Statement Classifications
Thus, the correct and verified answer is D. Payment of debt, including interest.
IIA-CIA-Part3-KR 문제 168
, including:
* Password policies (length, complexity, change frequency)
* User access rights and permissions
* Login activity logs to detect unauthorized access attempts
* Correct Answer (B - Reviewing Password Policies and User List for Login Process)
* Logical access controls ensure only authorized users can access a workstation.
* Reviewing password length, complexity, and change frequency helps assess if security best practices are followed.
* Reviewing the list of authorized users ensures that only appropriate personnel have access.
* The IIA's GTAG 9: Identity and Access Management recommends evaluating password policies and user access lists as key control measures.
* Why Other Options Are Incorrect:
* Option A (Reviewing access badges and room logs):
* Physical access controls are important but do not assess logical access (login security, user authentication).
* Option C (Reviewing failed access attempts and error messages):
* Reviewing failed login attempts identifies security breaches but does not directly assess password policies or user access lists.
* Option D (Reviewing unsuccessful passwords and activity logs):
* Passwords should not be reviewed due to privacy and security policies. Logs should be checked, but reviewing actual passwords is a security violation.
* IIA GTAG 9: Identity and Access Management - Covers password controls and user authentication.
* IIA Practice Guide: Auditing IT Security Controls - Recommends reviewing password policies as a key security measure.
Step-by-Step Explanation:IIA References for Validation:Thus, B is the correct answer because reviewing password policies and user lists is essential for auditing logical access controls.
IIA-CIA-Part3-KR 문제 169
* Physical access controls protect assets by preventing unauthorized access and detecting potential security violations.
* Controls can be preventive (stop incidents from occurring) or detective (identify incidents after they occur).
* Why Surveillance Cameras Function as Both Preventive and Detective Controls:
* Preventive: The presence of cameras discourages unauthorized access and malicious activities.
* Detective: If an incident occurs, cameras provide recorded evidence for investigation and accountability.
* Why Other Options Are Less Suitable:
* A. Locked doors - Purely preventive, as they block unauthorized access but do not detect breaches.
* B. Firewalls - Primarily an IT security measure, not a physical access control.
* D. Login IDs and passwords - These are logical (IT) access controls, not physical controls.
* IIA GTAG 15 - Auditing Privacy and Security Risks: Highlights the dual role of surveillance as a preventive and detective control.
* IIA Standard 2120 - Risk Management: Encourages controls that both prevent and detect risks.
* COSO's Internal Control Framework: Supports security measures that serve multiple control functions.
Relevant IIA References:# Final Answer: Surveillance cameras (Option C).
IIA-CIA-Part3-KR 문제 170
* The Internet of Things (IoT) refers to connected devices that continuously collect and transmit data in real-time.
* IoT generates massive amounts of data at high speeds, affecting the velocity of data processing and analysis.
* Why Velocity is the Most Affected Attribute:
* Velocity refers to the speed at which data is generated, processed, and transmitted.
* IoT devices continuously stream data, requiring real-time or near-real-time processing.
* Examples include:
* Smart sensors in factories sending real-time equipment status.
* Wearable devices tracking health metrics every second.
* Smart cities using IoT for traffic monitoring and instant updates.
* Why Other Options Are Incorrect:
* A. Normalization - Incorrect.
* Normalization refers to organizing database structures, but IoT deals with data transmission speed rather than database design.
* C. Structuration - Incorrect.
* Structuration relates to how data is formatted (structured vs. unstructured), but IoT's biggest challenge is real-time data flow.
* D. Veracity - Incorrect.
* Veracity concerns data accuracy and reliability, which is a challenge in IoT but not the most significant impact compared to velocity.
* IIA's Perspective on IoT and Data Management:
* IIA Standard 2110 - Governance emphasizes the need for robust data processing frameworks to handle IoT-generated data velocity.
* IIA GTAG (Global Technology Audit Guide) on Big Data highlights real-time data analytics and IoT challenges.
* ISO 27001 Information Security Standard recommends ensuring real-time data processing controls for IoT security and management.
IIA References:
* IIA Standard 2110 - IT Governance & Data Management
* IIA GTAG - IoT and Big Data Risks
* ISO 27001 - Information Security and Real-Time Data Processing
Thus, the correct and verified answer is B. Velocity.
- 최근 업로드
- 139F5.F5CAB3.v2026-06-20.q47
- 142Appian.ACD201.v2026-06-20.q47
- 133Archer.Archer-Expert.v2026-06-20.q25
- 116ITSpecialist.INF-306.v2026-06-20.q24
- 192Salesforce.Salesforce-AI-Specialist.v2026-06-19.q86
- 166Oracle.1Z1-948.v2026-06-19.q40
- 346EXIN.ITILFNDv4.v2026-06-18.q182
- 197Adobe.AD0-E605.v2026-06-18.q77
- 250Huawei.H12-831_V1.0-ENU.v2026-06-18.q172
- 340Microsoft.MB-700.v2026-06-18.q349
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. IIA.IIA-CIA-Part3-KR.v2026-02-16.q207 모의시험 시험자료를 다운 받으세요.
