IIA-CIA-Part3-KR 문제 56
(A) Inability to adapt.
Incorrect. Decentralization typically enhances adaptability, as individual units can quickly respond to local market conditions, customer needs, and emerging risks without waiting for corporate approval.
(B) Greater costs of control function.
Partially correct but not the primary risk. While decentralization may increase oversight costs (e.g., more auditors and compliance personnel), the primary issue is lack of uniform decision-making rather than costs alone.
(C) Inconsistency in decision making. #
Correct. When decision-making authority is spread across various units, inconsistencies arise in areas such as risk management, compliance, operational procedures, and resource allocation. This can lead to conflicts, inefficiencies, and misalignment with corporate strategy.
IIA Standard 2120 - Risk Management emphasizes the need for consistent risk oversight in all business units.
IIA GTAG "Auditing the Control Environment" warns that inconsistent policies weaken internal controls and governance.
(D) Lack of resilience.
Incorrect. A decentralized structure often improves resilience because decision-making is spread out, reducing dependency on a central authority. This allows units to function independently if one area experiences disruption.
IIA Standard 2120 - Risk Management
IIA GTAG - "Auditing the Control Environment"
COSO Framework - Internal Control Principles
Analysis of Answer Choices:IIA References:Thus, the correct answer is C, as decentralization introduces decision-making inconsistencies, affecting governance and strategic alignment.
IIA-CIA-Part3-KR 문제 57
Rooting (on Android) or Jailbreaking (on iOS) is the process of bypassing manufacturer and administrative security controls on a smart device.
This allows users to gain full control (root access) over the operating system, which can override security restrictions and allow installation of unauthorized applications.
How Rooting Increases Data Security Risks:
Bypassing Security Measures: Rooting removes built-in security protections, making the device more vulnerable to malware, unauthorized access, and data breaches.
Exposure to Malicious Apps: Rooted devices can install third-party applications that are not vetted by official app stores, increasing the risk of data theft, spyware, and ransomware attacks.
Circumventing Enterprise Security Policies: Many organizations use Mobile Device Management (MDM) to enforce security policies, but rooted devices can bypass these controls, exposing corporate data to cyber threats.
Increased Risk of Privilege Escalation Attacks: Attackers can exploit root access to take full control of the device, leading to unauthorized access to sensitive information.
IIA's Perspective on Cybersecurity Risks:
IIA Standard 2110 - Governance emphasizes the importance of protecting sensitive data and ensuring compliance with IT security policies.
IIA's GTAG (Global Technology Audit Guide) on Information Security warns against the dangers of rooted or jailbroken devices, as they compromise cybersecurity defenses.
NIST Cybersecurity Framework and ISO 27001 Information Security Standards identify unauthorized modifications to devices as a critical security risk.
Eliminating Incorrect Options:
B). Eavesdropping: This refers to intercepting communications (e.g., listening in on phone calls or network traffic) but does not involve circumventing administrative restrictions.
C). Man-in-the-Middle (MITM) Attack: This is an attack where an attacker intercepts and alters communication between two parties but does not involve rooting a device.
D). Session Hijacking: This attack involves stealing session tokens to impersonate a user but is unrelated to bypassing security controls on devices.
IIA References:
IIA Standard 2110 - Governance and IT Security
IIA GTAG - Information Security Risks
NIST Cybersecurity Framework
ISO 27001 Information Security Standards
IIA-CIA-Part3-KR 문제 58
IIA-CIA-Part3-KR 문제 59
Primary controls in spreadsheet management focus on ensuring data accuracy, integrity, and security.
Option A (Locking formulas and static data) prevents unauthorized changes, ensuring data integrity. This is a direct control over spreadsheet accuracy, making it the correct answer.
Option B (Backup storage) is an IT operational control, not a primary financial reporting control.
Option C (Documentation of spreadsheet use) is important for governance but does not directly prevent errors.
Option D (Version control software) helps manage changes but does not directly ensure financial reporting accuracy.
Thus, locking and protecting spreadsheet formulas is the most critical primary control for accurate financial reporting.
Reference: IIA IT Controls & Data Governance
IIA-CIA-Part3-KR 문제 60
Detecting Duplicate Payments: Fraudulent employees may submit the same invoice multiple times with slight modifications to avoid detection. Duplicate testing helps find identical or similar transactions.
Identifying Unusual Patterns: By analyzing payment records, auditors can detect repeat payments to the same vendor, same invoice number, or similar amounts within a short time frame.
Aligns with Fraud Prevention Practices: As per IIA Standard 2120 - Risk Management, internal auditors must identify and assess fraud risks, including duplicate invoice payments.
Supports Data Analytics in Auditing: IIA GTAG (Global Technology Audit Guide) 16 - Data Analysis Techniques recommends using duplicate testing to identify fraud, control weaknesses, and errors in financial transactions.
A). Perform gap testing: Gap testing is used to identify missing data or transactions in a sequence (e.g., missing invoice numbers), but it does not specifically target duplicate or fraudulent payments.
B). Join different data sources: This method is useful for cross-checking information across multiple databases, but it is not directly related to identifying duplicate invoice payments.
D). Calculate statistical parameters: Statistical analysis provides summary insights about data (e.g., mean, median), but it does not specifically detect duplicate payments.
IIA Standard 2120 - Risk Management: Internal auditors must evaluate fraud risks, including duplicate payments.
IIA Standard 1220 - Due Professional Care: Requires auditors to apply appropriate data analytics techniques.
IIA GTAG 16 - Data Analysis Techniques: Recommends duplicate testing as an effective fraud detection method.
Key Reasons Why Option C is Correct:Why Other Options Are Incorrect:IIA References:Thus, the correct answer is C. Perform duplicate testing.
- 다른 버전
- 1797IIA.IIA-CIA-Part3-KR.v2026-08-19.q374
- 1774IIA.IIA-CIA-Part3-KR.v2026-02-16.q207
- 2740IIA.IIA-CIA-Part3-KR.v2025-04-09.q203
- 최근 업로드
- 131Oracle.1Z0-1050-26.v2026-09-05.q19
- 195Salesforce.Manufacturing-Cloud-Professional.v2026-09-05.q111
- 215EXIN.ITILFND_V4.v2026-09-05.q129
- 231Citrix.1Y0-312.v2026-09-05.q182
- 178NVIDIA.NCP-AIN.v2026-09-05.q56
- 182Huawei.H12-351_V1.0.v2026-09-04.q76
- 813Cisco.300-435.v2026-09-03.q259
- 403Oracle.1Z0-1045-26.v2026-09-03.q17
- 710IIA.IIA-CIA-Part1.v2026-09-03.q627
- 571Fortinet.NSE6_OTS_AR-7.6.v2026-09-03.q95
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. IIA.IIA-CIA-Part3-KR.v2026-05-02.q255 모의시험 시험자료를 다운 받으세요.
