10 free, exam-style Certified Internal Auditor (CIA) practice questions with answers and
explanations. No signup required. Work through them below, then take the
full free CIA practice test to study every exam domain.
These 10 free CIA questions are organized by exam domain, so you can see how each part of the Certified Internal Auditor blueprint is tested. Reveal the answer and explanation under each question.
Domain 1: Internal Audit Fundamentals (Part 1)
Question 1
The CEO instructs the CAE not to report a significant finding to the audit committee. The CAE should:
- Comply with the CEO's instruction since the CAE reports administratively to the CEO
- Report the finding to the audit committee regardless, as functional reporting to the board takes precedence
- Seek guidance from external auditors before deciding whether to report the finding to the audit committee
- Document the CEO's instruction and delay reporting until the next audit committee meeting to allow reconsideration
Show answer & explanation
Correct answer: B - Report the finding to the audit committee regardless, as functional reporting to the board takes precedence
Question 2
The CAE agrees to temporarily manage the IT security function during a leadership vacancy. Which of the following safeguards is LEAST effective?
- Documenting the arrangement in writing with clear role definitions
- Establishing a time limit on the temporary assignment
- Having the CAE personally audit the IT security function after the assignment ends
- Implementing additional oversight controls during the temporary management period
Show answer & explanation
Correct answer: C - Having the CAE personally audit the IT security function after the assignment ends
Domain 3: Governance, Risk Management, and Control (Part 1)
Question 3
The key difference between risk appetite and risk tolerance is:
- Risk appetite is set by management; risk tolerance is set by external auditors
- Risk appetite is strategic and qualitative; risk tolerance is tactical and quantitative
- They are identical concepts with no meaningful difference
- Risk appetite applies to financial risks; risk tolerance applies to operational risks
Show answer & explanation
Correct answer: B - Risk appetite is strategic and qualitative; risk tolerance is tactical and quantitative
Question 4
All of the following are principles within the COSO Internal Control Framework EXCEPT:
- The organization demonstrates commitment to integrity and ethical values
- The organization establishes structures and reporting lines that enable execution
- The organization establishes risk appetite as part of strategy-setting
- The organization identifies and assesses changes that could significantly impact the system
Show answer & explanation
Correct answer: C - The organization establishes risk appetite as part of strategy-setting
Domain 4: Fraud Risks (Part 1)
Question 5
Management override of controls is a particular concern in fraud risk assessment because:
- It occurs only in small organizations
- Senior management can circumvent fraud controls
- It is easily detected by auditors
- It only affects financial reporting
Show answer & explanation
Correct answer: B - Senior management can circumvent fraud controls
Domain 5: Managing the Internal Audit Function (Part 2)
Question 6
An organization has an RTO of 4 hours for its e-commerce platform but its actual recovery capability is 24 hours. This gap indicates:
- No concern since the platform is not critical to business operations
- A significant business continuity risk that the engagement should address
- The RTO should be increased to match the actual recovery capability
- The IT department is performing well within acceptable parameters
Show answer & explanation
Correct answer: B - A significant business continuity risk that the engagement should address
Domain 6: Planning the Internal Audit Engagement (Part 2)
Question 7
The unauthorized purchase orders resulted in $250,000 in payments for goods that were never received. This represents which finding attribute?
- Criteria
- Condition
- Root Cause
- Effect
Show answer & explanation
Correct answer: D - Effect
Domain 11: Information Technology (Part 3)
Question 8
The auditor's recommendation to implement automated reconciliations would cost $500,000 annually. The estimated risk exposure from the finding is $50,000 per year. The auditor should:
- Recommend the automated reconciliation regardless of cost
- Reconsider the recommendation and explore less expensive alternatives
- Remove the finding since the cost of remediation is too high
- Recommend management accept the risk without implementing controls
Show answer & explanation
Correct answer: B - Reconsider the recommendation and explore less expensive alternatives
Question 9
Management implements all recommended action plans within the agreed timeframe. During follow-up, the auditor tests the implemented controls and finds they are not actually reducing the identified risk. The finding should be:
- Closed since management implemented the actions
- Kept open with updated findings
- Closed and a new finding issued in the next engagement
- Reported as a new finding unrelated to the original
Show answer & explanation
Correct answer: B - Kept open with updated findings
Question 10
An auditor evaluates the organization's ERP system and finds that a single administrator has unrestricted access to modify financial data, approve transactions, and delete audit logs. This finding involves which control concepts?
- Application control weakness and data integrity concern
- Segregation of duties violation and IT access control weakness
- Physical security breach and unauthorized system access
- IT operations failure and system configuration error
Show answer & explanation
Correct answer: B - Segregation of duties violation and IT access control weakness
The rest of the CIA blueprint
The CIA exam also covers these domains. Drill them in the full free practice test:
- Domain 2: Ethics and Professionalism (Part 1)
- Domain 7: Performing the Internal Audit Engagement (Part 2)
- Domain 8: Communicating Internal Audit Results and Monitoring Progress (Part 2)
- Domain 9: Business Acumen (Part 3)
- Domain 10: Information Security (Part 3)