IIA-CIA-Part3-KR 문제 126
Correct Answer (D - Specific identification)
Under the specific identification method, each inventory unit is tracked separately, and its actual purchase cost is assigned to the cost of goods sold (COGS) when sold.
This method is commonly used for high-value, low-volume items where unique tracking is feasible.
The IIA's GTAG 8: Audit of Inventory Management explains how different costing methods impact financial reporting and internal controls.
Why Other Options Are Incorrect:
Option A (LIFO - Last-in, First-out):
LIFO assumes that the most recent (last-in) inventory is sold first, but it does not track actual unit cost.
Instead, it assigns the cost of the newest inventory to COGS.
LIFO is often used for tax benefits but does not follow actual unit cost identification.
Option B (Average cost):
The weighted average cost method calculates an average cost for all inventory units rather than assigning actual unit costs.
This method smooths out price fluctuations but does not track specific items ' costs.
Option C (FIFO - First-in, First-out):
FIFO assumes that the oldest (first-in) inventory is sold first, assigning its cost to COGS.
However, like LIFO, it does not track individual unit costs.
IIA GTAG 8: Audit of Inventory Management - Explains different inventory costing methods, including specific identification.
IIA Practice Guide: Assessing Inventory Risks - Covers inventory valuation and fraud risks.
Step-by-Step Explanation:IIA References for Validation:Thus, the specific identification method (D) is the only one that accounts for the actual cost paid for each unit sold.
IIA-CIA-Part3-KR 문제 127
Option A: Veracity, velocity, and variety.
Incorrect. These attributes are commonly associated with big data and data analytics rather than cybersecurity.
Cybersecurity controls focus on ensuring that data is secure, rather than on its volume, speed, or diversity.
IIA Reference: Cybersecurity risk management frameworks emphasize the CIA triad over big data attributes.
(IIA GTAG: Auditing Cybersecurity Risk)
Option B: Integrity, availability, and confidentiality.
Correct. These three principles are at the core of cybersecurity:
Confidentiality: Ensures that sensitive information is only accessible to authorized individuals.
Integrity: Protects data from unauthorized modifications or corruption.
Availability: Ensures that data and systems are accessible when needed.
IIA Reference: The IIA's guidance on IT governance highlights the CIA triad as the foundation of cybersecurity. (IIA GTAG: Information Security Governance) Option C: Accessibility, accuracy, and effectiveness.
Incorrect. While these attributes are important in data management and usability, they do not directly define cybersecurity controls.
Option D: Authorization, logical access, and physical access.
Incorrect. While these are essential security components, they fall under broader IT security measures rather than forming the fundamental principles of cybersecurity.
IIA-CIA-Part3-KR 문제 128
Job rotation involves periodically moving employees between different tasks, roles, or departments to increase engagement, reduce boredom, and enhance skill development.
Option A (Job specification) - Defines job responsibilities but does not address boredom.
Option B (Job objectives) - Focuses on performance goals rather than task variety.
Option D (Job description) - Simply documents job roles without changing daily tasks.
Thus, job rotation (Option C) is the most effective strategy for overcoming monotony and job-related boredom.
Reference: IIA Human Resource Management - Employee Motivation Techniques
IIA-CIA-Part3-KR 문제 129
Internal audit may review budgeting controls to determine whether spending requests are supported, aligned with objectives, and challenged appropriately. Zero-based budgeting can improve cost discipline but may require significant time and analysis. Therefore, Option C is correct.
IIA-CIA-Part3-KR 문제 130
Why Two-Step Verification is Effective (B - Correct Answer)
Multi-factor authentication (MFA) adds an additional security layer beyond a password, requiring a second factor such as a one-time code sent to a mobile device, biometric authentication, or a security key.
Even if an attacker obtains a password, they cannot access the account without the second authentication factor.
The IIA Global Technology Audit Guide (GTAG) 1: Information Security Management emphasizes the use of multi-factor authentication to prevent unauthorized access.
Why Other Options Are Less Effective:
Option A: Changing passwords every two years
Ineffective because attackers often use compromised credentials that may be recent. Best practices recommend regular password updates but coupled with MFA.
The IIA ' s GTAG 16: Identity and Access Management highlights that password rotation alone does not fully protect against automated attacks.
Option C: Using a VPN when out of the office
Irrelevant to password attacks. A VPN encrypts data and secures network connections but does not prevent brute force or credential stuffing attacks.
The IIA GTAG 17: Auditing Network Security discusses VPNs for secure remote access but does not consider them a solution for password-based attacks.
Option D: Using antivirus and security tools
While important for overall security, these tools cannot prevent attacks that exploit stolen or weak passwords.
The IIA GTAG 15: Information Security Governance states that security tools should be combined with authentication controls like MFA for best protection.
GTAG 1: Information Security Management - Recommends multi-factor authentication to prevent unauthorized system access.
GTAG 16: Identity and Access Management - Highlights the limitations of password-only security and supports multi-factor authentication.
GTAG 17: Auditing Network Security - Covers VPN usage but does not consider it a solution for password attacks.
GTAG 15: Information Security Governance - Discusses the role of security tools and authentication in securing user accounts.
Step-by-Step Explanation:IIA References for Validation:Thus, requiring two-step verification (B) is the most effective control against automated password attacks.
- 다른 버전
- 1868IIA.IIA-CIA-Part3-KR.v2026-05-02.q255
- 1627IIA.IIA-CIA-Part3-KR.v2026-02-16.q207
- 2547IIA.IIA-CIA-Part3-KR.v2025-04-09.q203
- 최근 업로드
- 149Microsoft.DP-700-KR.v2026-08-20.q47
- 290ISC.CISSP-KR.v2026-08-20.q862
- 196Microsoft.SC-100-KR.v2026-08-20.q141
- 237Microsoft.AZ-305-KR.v2026-08-20.q223
- 851IIA.IIA-CIA-Part1-KR.v2026-08-19.q374
- 1347IIA.IIA-CIA-Part3-KR.v2026-08-19.q374
- 182Microsoft.DP-700-KR.v2026-08-19.q59
- 235AMP.CRL.v2026-08-18.q46
- 894Microsoft.AZ-305-KR.v2026-08-17.q162
- 236IIA.IAA-IAP-KR.v2026-08-17.q41
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. IIA.IIA-CIA-Part3-KR.v2026-08-19.q374 모의시험 시험자료를 다운 받으세요.
