IIA-CIA-Part3-KR 문제 6
Correct Answer (C - Cleaning the Data in Preparation for Determining Involved Processes) Data cleaning involves:
Removing duplicate entries to prevent misinterpretation.
Standardizing data formats for consistency.
Handling missing or inaccurate values to ensure reliability.
This step prepares the data for analysis and identification of high-risk processes.
The IIA's GTAG 16: Data Analysis Technologies emphasizes data cleaning as a critical part of internal audit analytics.
Why Other Options Are Incorrect:
Option A (Normalizing data in preparation for analyzing it):
Normalization refers to structuring data efficiently (e.g., in databases) but does not necessarily involve eliminating redundancies in the way described.
Option B (Analyzing data in preparation for communicating results):
The auditor is still in the data preparation phase, not the analysis or reporting phase.
Option D (Reviewing data prior to defining the question):
The auditor is already working with data. Defining questions typically happens before data collection.
GTAG 16: Data Analysis Technologies - Covers data preparation, cleaning, and analytics in internal auditing.
IIA Practice Guide: Data Analytics in Internal Auditing - Outlines best practices for data validation and cleaning.
Step-by-Step Explanation:IIA References for Validation:Thus, cleaning the data (C) is the correct answer, as it ensures data integrity before identifying relevant processes and risks.
IIA-CIA-Part3-KR 문제 7
IIA-CIA-Part3-KR 문제 8
Change management ensures that modifications to IT systems are controlled, tested, and implemented in a way that reduces risks.
A structured and consistent process is required to prevent disruptions, maintain system integrity, and comply with governance requirements.
IIA Standard 2110 - Governance:
IT governance must include structured change management processes.
Change management should be repeatable and standardized to ensure effectiveness.
IIA GTAG (Global Technology Audit Guide) on Change Management:
Change management must be conducted in a controlled environment to minimize unintended consequences and security risks.
A). The sole responsibility for change management is assigned to an experienced and competent IT team.
(Incorrect)
While IT plays a key role, change management should involve multiple stakeholders, including business units, security, compliance, and risk management teams.
IIA Standard 2120 - Risk Management states that risk oversight should not be assigned to a single function.
C). Internal audit participates in the implementation of change management throughout the organization.
(Incorrect)
Internal audit evaluates change management but does not implement it.
IIA Standard 1000 - Purpose, Authority, and Responsibility emphasizes that internal audit provides independent assurance rather than operational involvement.
D). All changes to systems must be approved by the highest level of authority within an organization.
(Incorrect)
Approvals should be based on a risk-based hierarchy rather than requiring executive-level approval for all changes.
IIA GTAG - Change Management recommends a tiered approval system based on change complexity and risk impact.
Explanation of Incorrect Answers:Conclusion:The most critical factor in effective IT change management is having a consistent, controlled process (Option B).
IIA References:
IIA Standard 2110 - Governance
IIA Standard 2120 - Risk Management
IIA Standard 1000 - Purpose, Authority, and Responsibility
IIA GTAG - Change Management
IIA-CIA-Part3-KR 문제 9
MBO is a performance management approach where employees and managers set specific, measurable goals together.
The main purpose of MBO is to align individual objectives with organizational goals, enhancing motivation and engagement.
Why Option C (Helps Keep Employees Motivated) Is Correct?
Employee motivation improves when individuals understand how their efforts contribute to the organization's success.
Setting clear objectives and allowing employees to participate in goal-setting increases job satisfaction and engagement.
IIA Standard 2120 - Risk Management supports frameworks like MBO that contribute to organizational performance and employee effectiveness.
Why Other Options Are Incorrect?
Option A (Most helpful in organizations with rapid changes):
MBO is less effective in rapidly changing environments because it relies on long-term goal setting.
Option B (Best in mechanistic organizations with rigid tasks):
MBO works better in adaptive, flexible organizations, not those with rigid structures.
Option D (Distinguishes strategic from operational goals):
MBO focuses on individual and team goals, not distinguishing strategic vs. operational goals.
MBO enhances employee motivation by involving them in goal-setting and performance tracking.
IIA Standard 2120 supports employee engagement strategies for better performance management.
Final Justification:IIA References:
IPPF Standard 2120 - Risk Management (Employee Engagement & Performance Management) COSO ERM - Performance Measurement & Goal Alignment
IIA-CIA-Part3-KR 문제 10
Simplicity and Practicality:
The direct write-off method is straightforward and only requires writing off bad debts as they occur.
It is best suited for companies where bad debt losses are minimal or rare.
Acceptable for Insignificant Losses:
If bad debts are not material, then estimating and recording an allowance in advance (as in the allowance method) may not be necessary.
Used by Small Businesses and Tax Accounting:
The IRS allows the direct write-off method for tax purposes because it recognizes expenses only when they occur.
Not Aligned with GAAP for Significant Losses:
Generally Accepted Accounting Principles (GAAP) prefer the allowance method, which estimates bad debts in advance to match expenses with related revenues.
B). It provides a better alignment with revenue:
Incorrect because the allowance method provides a better revenue-expense matching approach, not the direct write-off method.
C). It is the preferred method according to The IIA:
The IIA does not have a stated preference between the two methods; however, GAAP prefers the allowance method.
D). It states receivables at net realizable value on the balance sheet:
The allowance method states receivables at net realizable value (NRV) by estimating bad debts in advance, while the direct write-off method does not adjust receivables until a loss occurs.
IIA Standard 2120 - Risk Management: Internal auditors must assess financial risks, including credit risks and bad debt write-offs.
COSO Internal Control Framework - Financial Reporting Component: Emphasizes accurate financial reporting, where the allowance method is generally preferred for better estimation.
Key Reasons Why Option A is Correct:Why Other Options Are Incorrect:IIA References:Thus, the correct answer is A. It is useful when losses are considered insignificant.
- 다른 버전
- 1762IIA.IIA-CIA-Part3-KR.v2026-08-19.q374
- 1754IIA.IIA-CIA-Part3-KR.v2026-02-16.q207
- 2718IIA.IIA-CIA-Part3-KR.v2025-04-09.q203
- 최근 업로드
- 693Cisco.300-435.v2026-09-03.q259
- 349Oracle.1Z0-1045-26.v2026-09-03.q17
- 626IIA.IIA-CIA-Part1.v2026-09-03.q627
- 481Fortinet.NSE6_OTS_AR-7.6.v2026-09-03.q95
- 472Snowflake.DAA-C01.v2026-09-03.q67
- 3497Salesforce.AP-223.v2026-09-01.q94
- 2603Splunk.SPLK-5001.v2026-09-01.q60
- 3918Cisco.300-540.v2026-09-01.q62
- 5170Microsoft.MS-102-KR.v2026-09-01.q239
- 3548Microsoft.AI-900-KR.v2026-09-01.q162
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. IIA.IIA-CIA-Part3-KR.v2026-05-02.q255 모의시험 시험자료를 다운 받으세요.
