CIA Part 2 Practice Exam — CIA Part 2:Internal Audit Engagement

1. The question bank is cloud‑connected and updates automatically; no manual re‑acquisition is required.

2. Start practicing right after activating the question bank. It supports simultaneous use on websites and mini‑programs, with one‑click bilingual switching for each question.

3. Functions include online practice, mock tests, note‑taking, wrong‑question recording, etc., valid for one year.

4. Recommended practice order: Turn on review mode to browse questions → Complete sequential practice → Take mock exams for pre‑test self‑assessment.

5. Activation codes can be purchased by clicking Buy Now on the right or via our official Tmall flagship store.

6. For inquiries, contact customer service through mini‑program, WeChat, WhatsApp or LINE.

Sample questions

CIA Part 2 · Q1
Question #1 An internal auditor needs to test logical controls to determine whether all users access the organization's enterprise resource planning system according to the principle of least privilege.Which engagement procedure would be most effective in carrying out this test?
  • A.
    Obtain the user access list created by management that shows user roles and permissions, and observe the actions of a sample of users for consistency.
  • B.
    Generate a user access list from the system that shows roles and permissions, and observe the actions of a sample of users for consistency.
  • C.
    Generate a user access list from the system that shows roles and permissions, and use access rights management software to confirm permissions.
  • D.
    Obtain the user access list created by management that shows user roles and permissions, and compare with job descriptions for consistency.

Answer: C

The core audit objective here is to test logical controls to verify all ERP system users adhere to the principle of least privilege, meaning no user has more access than required to perform their authorized job functions. For this test, two critical elements are required to ensure audit evidence is reliable and the test is comprehensive: first, the auditor must use the actual, active access permissions configured in the ERP system rather than potentially inaccurate management-prepared documentation, and second, the test must cover all permissions assigned to users, not just a limited subset of observed activity. Option C meets both requirements: pulling the access list directly from the system eliminates the risk of relying on outdated or incorrect management-provided lists, and using access rights management software enables systematic, automated validation of all assigned permissions against least privilege requirements, including identifying overprovisioned access, orphaned accounts, and excessive rights that would not be detected via limited sampling or manual comparison. This aligns with CIA Part 2 2025 guidance on testing IT logical controls, which prioritizes direct system evidence and automated testing tools for more accurate, complete control assessment. Option Analysis: A. Incorrect. First, the management-created user access list is not validated against actual system configurations, so it may contain errors, outdated entries, or omissions that do not reflect true access rights. Second, observing a sample of user actions only captures activities performed during the observation window, and cannot detect excess permissions that the user holds but does not use during observation, so it fails to comprehensively test least privilege for all assigned access. B. Incorrect. While generating the access list directly from the system provides reliable baseline data on actual configured permissions, observing a sample of user actions is still insufficient. Observation only captures a narrow, time-bound subset of user activity, and cannot identify overprovisioned access that is not exercised during the observation period, so it does not fully validate that all assigned permissions align with least privilege. C. Correct. This procedure addresses both key requirements for the test: system-generated access lists provide reliable, accurate data on the actual active permissions in the ERP, eliminating reliance on potentially flawed management documentation. Access rights management software is purpose-built to systematically map assigned permissions to required job functions, identify excessive or unused rights, and validate alignment with least privilege across all users, delivering a far more complete and accurate assessment than manual or sample-based procedures. This directly meets the audit objective and adheres to CIA Part 2 best practices for logical access control testing. D. Incorrect. First, the management-created access list is not verified against actual system configurations, so it may not reflect true access rights. Second, comparing access lists to job descriptions is a high-level, imprecise check, as job descriptions rarely include granular details of required ERP system permissions, so it cannot reliably identify excess granular access that violates least privilege. Key Concepts: 1. Reliability of Audit Evidence: CIA Part 2 guidance establishes that evidence obtained directly by the auditor from the underlying system (e.g., system-generated access lists) is far more reliable than evidence provided by management, as it reduces the risk of manipulation or inaccuracy in management-prepared documentation. 2. Logical Access Control Testing for Least Privilege: Testing least privilege requires validating that all assigned access permissions, not just actively used permissions, are limited to the minimum required for a user's job function, as unexercised excess permissions present a material control risk. 3. Automated Control Testing Efficiency and Completeness: CIA Part 2 recommends using automated tools (such as access rights management software) for testing IT controls where possible, as these tools can evaluate entire populations of access rights rather than limited samples, reducing sampling risk and improving the accuracy of test results. References: The IIA International Standards for the Professional Practice of Internal Auditing, Standard 2310: Identifying Information, The IIA Global Technology Audit Guide (GTAG) 1: Information Technology Controls
CIA Part 2 · Q2
Question #2 An internal auditor performed a review that focused on the organization's process for vetting vendors. The internal auditor's testing identified that 120 out of 130 vendors had a business relationship with the organization's procurement manager that violated conflict-of-interest policies.Which of the following conclusions could the internal auditor draw from these results?
  • A.
    The organization is exposed to significant fraud and abuse risks as a result of the vendor and employee business relationships.
  • B.
    Due to improper relationships and favoritism, vendors are not providing goods or services at a reasonable price to meet the objectives.
  • C.
    The organization's conflict-of-interest policies are not clear or well communicated throughout the organization.
  • D.
    Improper relationships and favoritism means that controls are not effective and significant fraud occurs.

Answer: A

CIA Part 2 2025 focuses on core internal audit engagement competencies including evidence evaluation, risk-based conclusion drawing, and adherence to professional standards. The scenario provides confirmed evidence that the vendor vetting process failed to prevent widespread conflict-of-interest policy violations between the procurement manager and nearly all active vendors. Internal auditors are required to draw conclusions that are directly supported by collected evidence, without overreaching to assume unproven negative outcomes. The only valid conclusion from the provided test results is recognition of the elevated risk exposure created by these unaddressed conflicts, as unmitigated employee-vendor conflicts are a well-documented precursor to procurement fraud and abuse, even if actual harm has not been explicitly confirmed through additional testing. Option Analysis: A. Correct. This conclusion is appropriately limited to identifying the significant risk exposure created by the widespread unaddressed conflict-of-interest relationships, which aligns with IIA guidance on risk-based auditing and evidence-based conclusion drawing. It includes no unsupported assumptions about actual harm already occurring, so it is a valid, defensible auditor conclusion. B. Incorrect. The auditor only tested for compliance with conflict-of-interest policies, not for pricing reasonableness or alignment with organizational cost objectives. There is no evidence provided to confirm vendors are charging unreasonable prices, so this conclusion is an unwarranted assumption not supported by collected test data, which violates IIA requirements for sufficient, reliable evidence to support all auditor conclusions. C. Incorrect. The test results confirm that conflict-of-interest violations occurred, but provide no insight into whether the policy was unclear or poorly communicated. The violations could equally stem from intentional noncompliance by the procurement manager despite clear, well-communicated policies. No evidence supports the claim that policy clarity or communication gaps are the root cause, so this conclusion is invalid. D. Incorrect. This conclusion asserts that significant fraud has already occurred, but the auditor only identified conflict-of-interest violations, no evidence of actual fraud (such as overpayments, bid rigging, or kickbacks) was collected. Asserting fraud occurred without supporting evidence violates due professional care and IIA standards for evidence-based conclusion drawing. Key Concepts: 1. Evidence-Based Conclusion Drawing (IIA Standard 2310): Internal auditors must base all conclusions and engagement results on sufficient, reliable, relevant, and useful evidence, and avoid drawing conclusions that are not directly supported by collected data. 2. Conflict of Interest as a Fraud Risk Factor: Per IIA fraud guidance, unmanaged conflicts of interest between employees and external vendors are a high-priority fraud risk red flag that creates significant exposure to procurement fraud, kickbacks, and favoritism, even if actual fraud has not yet been confirmed through targeted testing. 3. Risk vs. Proven Outcome Distinction: Internal auditors must differentiate between identifying control deficiencies that create risk exposure and confirming that negative outcomes (such as fraud, overpayments) have actually occurred, as the latter requires additional targeted testing to validate before conclusions are drawn. References: The IIA's International Standards for the Professional Practice of Internal Auditing, Standard 2310: Identifying Information, The IIA Fraud Risk Management Guide, 2nd Edition
CIA Part 2 · Q3
Question #3 During planning, the chief audit executive submits a risk-and-control questionnaire to management of the activity under review. Which of the following statements is true regarding the questionnaire?
  • A.
    It would be an inefficient way for internal auditors to address multiple controls in the activity under review.
  • B.
    It would limit certain members of the internal audit team from being fully involved in the engagement.
  • C.
    It would be the most effective way for the internal audit team to obtain a detailed understanding of the processes and controls in the activity to be audited.
  • D.
    It would be an efficient way for the internal audit team to determine whether specified control activities are in place.

Answer: D

This question aligns with the 2025 CIA Part 2 domain covering engagement planning and audit evidence collection tools. Risk-and-control questionnaires (RCQs) are structured, standardized tools used during preliminary engagement planning to gather targeted information about control activities from process management. The scenario specifies the CAE submits the RCQ during planning, a phase where the audit team first seeks to identify what controls are in place before investing resources in deeper testing or process analysis. The correct answer reflects the core purpose of RCQs as an efficient mechanism to confirm the existence of pre-identified, specified control activities without requiring extensive initial fieldwork. Option Analysis: A. Incorrect. Risk-and-control questionnaires are explicitly designed to efficiently address multiple control activities across a process in a single, structured format, rather than being inefficient. They reduce the time required to gather preliminary control information compared to ad-hoc interviews or full process reviews for all controls early in planning. B. Incorrect. There is no inherent limitation to audit team involvement associated with RCQs. The questionnaire can be designed, distributed, and analyzed by cross-functional members of the audit team, and responses often inform further team activities such as walkthroughs or control testing, supporting rather than limiting team engagement. C. Incorrect. While RCQs provide preliminary control information, they are not the most effective tool for obtaining a detailed understanding of processes and controls. Detailed understanding requires deeper procedures such as process walkthroughs, review of formal process documentation, and targeted stakeholder interviews, which capture nuance and process flow that standardized questionnaires cannot. This option incorrectly overstates the effectiveness of RCQs for deep process analysis. D. Correct. RCQs are structured with targeted questions tied to pre-identified control activities relevant to the auditable activity. They allow the audit team to quickly and efficiently collect responses from management to confirm whether those specified control activities are implemented, which is a key objective of the planning phase to inform subsequent audit scope and testing plans. Key Concepts: 1. Engagement Planning Tool Selection (2025 CIA Part 2 Domain 1: Managing Internal Audit Engagements): Audit teams select tools based on the planning phase objective of efficiently identifying initial control structure and risk areas, with RCQs being a standard tool for targeted preliminary control data collection. 2. Risk-and-Control Questionnaire Purpose: RCQs are designed to gather standardized, high-level information about the existence of predefined control activities, identify potential control gaps, and prioritize areas for deeper audit work, rather than providing comprehensive process detail. 3. Audit Evidence Efficiency vs. Effectiveness: Efficiency refers to the resource cost of gathering evidence, while effectiveness refers to the relevance and reliability of evidence for a given objective. RCQs are efficient for broad initial control existence checks but not effective for detailed process or control operating effectiveness validation. References: The IIA International Standards for the Professional Practice of Internal Auditing, Standard 2200: Engagement Planning, https://na.theiia.org/standards-guidance/standards/pages/2200-engagement-planning.aspx The IIA Practice Guide: Internal Audit Engagement Planning, https://na.theiia.org/standards-guidance/practice-guides/Pages/Practice-Guide-Internal-Audit-Engagement-Planning.aspx
CIA Part 2 · Q4
Question #4 What is a control implication for an organization that adopts a flat structure?
  • A.
    Mid-level employees are urged to innovate.
  • B.
    Available time for supervision is limited.
  • C.
    There are many hierarchical levels.
  • D.
    The organizational structure is dispersed vertically.

Answer: B

For the 2025 CIA Part 2 (Practice of Internal Auditing) exam, a core domain competency is evaluating how organizational design choices impact control environment effectiveness and inherent control risk. A flat organizational structure is defined by minimal hierarchical layers between entry-level/frontline staff and executive leadership, which results in a very wide span of control for each supervisory or managerial role. The primary control implication of this design is that supervisors oversee a far larger number of direct reports than in traditional tall hierarchical structures, so their available time to perform oversight, review work products, enforce control policies, and address performance or compliance gaps per employee is significantly constrained. This creates inherent control risks that internal auditors must account for when planning audits and assessing control design and operating effectiveness, making option B the correct response. Option Analysis: A. This option is incorrect. While increased employee autonomy and innovation are often cited as operational benefits of flat organizational structures, this is a business outcome, not a control implication. CIA Part 2 exam content explicitly distinguishes between operational advantages of organizational design and control-related risks or requirements, so this option does not address the question's focus on control implications. B. This option is correct. The wide span of control inherent to flat structures means each supervisor is responsible for many more direct reports than in a hierarchical structure, so their total available time for individual supervision, control monitoring, and work review is limited. This is a direct control implication that impacts the sufficiency of oversight controls, a core consideration for internal auditors per 2025 CIA Part 2 syllabus requirements. C. This option is incorrect. Many hierarchical levels are the defining characteristic of a tall, not flat, organizational structure. This option is factually inconsistent with the definition of a flat structure, so it is eliminated immediately. D. This option is incorrect. A vertically dispersed structure refers to a tall hierarchy with many layers across the vertical chain of command. Flat structures are vertically compressed, so this option is factually incorrect and irrelevant to the question scenario. Key Concepts: 1. Organizational Structure Control Risk Assessment: A core 2025 CIA Part 2 competency requires internal auditors to evaluate how structural design choices such as flat vs. tall hierarchies create inherent control risks and impact the suitability of existing control activities to mitigate those risks. 2. Span of Control: This term refers to the number of direct reports a single supervisor manages. Wide spans of control, standard in flat structures, increase control risk related to oversight gaps, as supervisors lack the capacity to consistently monitor individual employee adherence to control policies. 3. Control Implication Identification: CIA Part 2 exam content requires candidates to differentiate between operational benefits of organizational decisions and their associated control impacts, to accurately prioritize audit testing of high-risk control gaps. References: The IIA 2025 CIA Part 2 Syllabus: Practice of Internal Auditing, The IIA International Standard 2120: Risk Management
CIA Part 2 · Q5
Question #5 During engagement planning, which party provides the most accurate and up-to-date description of how organizational processes and key controls operate?
  • A.
    The management responsible for the activity under review.
  • B.
    The individuals who perform the daily tasks and functions of the activity under review.
  • C.
    The external auditors since they understand the key controls behind the financial statements.
  • D.
    The board of directors since they provide overall oversight for the organization.

Answer: B

This question aligns with the CIA Part 2 (Practice of Internal Auditing) 2025 domain covering engagement planning processes. During engagement planning, internal auditors must obtain an accurate understanding of the actual operating state of processes and controls, not just the formal, intended design. The most accurate and up-to-date source for this real-world operating information is personnel who perform the work daily, as they have first-hand visibility into workarounds, unrecorded control modifications, and day-to-day process deviations that higher-level stakeholders may not observe. This ensures auditors plan their engagement to assess true control effectiveness and operational risks, rather than relying on incomplete documented procedures. Option Analysis: A. Incorrect. Responsible management typically has knowledge of the intended, formally documented design of processes and controls, but they are often unaware of unapproved workarounds, temporary control adjustments, or recurring operational gaps that frontline staff encounter. Their description reflects the intended state, not the actual current operating state of the activity. B. Correct. Individuals performing daily tasks interact directly with processes and controls on an ongoing basis, so they have real-time, first-hand knowledge of how operations actually function, including deviations from formal documented procedures that management or other stakeholders do not observe. This aligns with IIA guidance that requires auditors to consult frontline personnel during planning to gain a complete, accurate view of the activity under review. C. Incorrect. External auditors only focus on controls relevant to financial statement reliability, which is a narrow subset of all organizational processes and key controls covered in most internal audit engagements. They do not have day-to-day visibility into operational or compliance-focused process operations, so their knowledge is limited to the scope of their own financial audit work. D. Incorrect. The board of directors provides high-level strategic oversight and governance, not granular, operational-level knowledge of how specific activity-level processes and controls function on a daily basis. Their understanding is aggregated, strategic, and not sufficiently detailed or up-to-date for engagement planning purposes. Key Concepts: 1. Engagement Planning (IIA Standard 2200): This mandatory standard requires internal auditors to develop a written engagement plan that includes a thorough understanding of the activity under review. Gathering input from frontline staff is a required step to ensure the plan is based on accurate, real-world operational data rather than only formal documented procedures. 2. Designed vs. Operating Control Effectiveness: A core internal audit concept is distinguishing between the intended design of controls and their actual operating effectiveness. Frontline staff are the only stakeholders who can reliably describe how controls operate in practice, as management may only be aware of the intended design state. 3. Stakeholder Engagement During Planning: CIA Part 2 2025 content emphasizes that auditors must solicit input from cross-functional stakeholders, including non-management operational staff, to mitigate the risk of planning based on incomplete or outdated information from higher-level stakeholders. References: The IIA International Standards for the Professional Practice of Internal Auditing (Standards), https://na.theiia.org/standards-guidance/mandatory-guidance/Pages/International-Standards-for-the-Professional-Practice-of-Internal-Auditing.aspx CIA Part 2 Exam Syllabus (2025 Edition), https://na.theiia.org/certifications/cia/Pages/CIA-Exam-Syllabus.aspx

FAQ

How many practice questions are available for CIA Part 2?

This question bank includes 100 CIA Part 2 practice questions covering single and multiple choice, each with answers and explanations.

Are CIA Part 2 practice questions available in Chinese and English?

Yes, CIA Part 2 practice questions are provided in both Chinese and English.

Can I try CIA Part 2 practice questions for free?

Yes. Free sample questions are available on this page, and the full question bank is available after signing up on Zhangxuetu.