An internal auditor discusses user-defined default passwords with the database administrator. Such passwords will be reset as soon as the user logs in for the first time, but the initial value of the password is set as " 123456. " Which of the following are the auditor and the database administrator most likely discussing in this situation?
A chief audit executive (CAE) joined an organization in the middle of the financial year. A risk-based annual audit plan has been approved by the board and is already underway. However, after discussions with key stakeholders, the CAE realizes that some significant key risk areas have not been covered in the original audit plan. How should the CAE respond?
How should a chief audit executive learn about emerging risk areas in an organization?
In a final audit report, internal auditors drafted the following management action plan with a due date of the last day of the calendar year:
" Plan: A bank reconciliation template has been updated to address issues with formulas incorrectly calculating variances. "
Which critical element of the action plan is missing?
An organization had a gross profit margin of 40 percent in year one and in year two. The net profit margin was 18 percent in year one and 13 percent in year two. Which of the following could be the reason for the decline in the net profit margin for year two?
Which of the following statements regarding flat and hierarchical internal audit functions is true?
An internal auditor found the following information while reviewing the monthly financial siatements for a wholesaler of safety
The cost of goods sold was reported at $8,500. Which of the following inventory methods was used to derive this value?
Which of the following controls would an internal auditor consider the most relevant to reduce risks of project cost overruns?
According to the Standards, the internal audit activity must evaluate risk exposures relating to which of the following when examining an organization ' s risk management process?
Organizational governance.
Organizational operations.
Organizational information systems.
Organizational structure.
The board is considering outsourcing the internal audit function to an external service provider. Which of the following would always remain the responsibility of the organization?
An attacker, posing as a bank representative, convinced an employee to release certain, financial information that ultimately resulted in fraud. Which of the following best describes this cybersecurity risk?
An organization sells 1,000 shares of its treasury stock at $15 per share previously acquired at $10 per share.
Which of the following statements is true?