When management uses the absorption costing approach, fixed manufacturing overhead costs are classified as which of the following types of costs?
Correct Answer: B
Absorption costing is a costing method that allocates all manufacturing costs (both variable and fixed) to the cost of a product. In this method, fixed manufacturing overhead costs are treated as indirect product costs because they are not directly traceable to a single unit of production but are still part of the total cost of producing goods. Let's analyze each option: * Option A: Direct, product costs. * Incorrect. Direct costs are costs that can be traced directly to a specific product, such as direct materials and direct labor. Fixed manufacturing overhead is not a direct cost because it is spread across all units produced. * Option B: Indirect product costs. * Correct. Fixed manufacturing overhead costs (such as rent, depreciation, and utilities for the production facility) are indirect costs because they support the entire production process rather than a specific product. However, under absorption costing, they are still treated as product costs and allocated to inventory. * IIA Reference: The IIA's guidance on cost allocation states that absorption costing assigns all manufacturing costs (including fixed overhead) to products. (IIA Practice Guide: Cost and Profitability Analysis) * Option C: Direct period costs. * Incorrect. Period costs are expensed in the period they occur, while absorption costing treats fixed manufacturing overhead as part of inventory (product cost) until sold. * Option D: Indirect period costs. * Incorrect. Fixed manufacturing overhead is not expensed immediately as a period cost under absorption costing; it is capitalized into inventory and expensed as Cost of Goods Sold (COGS) when the product is sold. Thus, the verified answer is B. Indirect product costs.
Question 52
According to IIA guidance, which of the following corporate social responsibility evaluation activities may be performed by the internal audit activity? * Consult on CSR program design and implementation. * Serve as an advisor on CSR governance and risk management. * Review third parties for contractual compliance with CSR terms. * Identify and mitigate risks to help meet the CSR program objectives.
Correct Answer: A
Internal audit may provide consulting and assurance services related to corporate social responsibility, provided management retains ownership of the program. Consulting on CSR design and implementation can be acceptable if objectivity safeguards exist. Serving as an advisor on CSR governance and risk management is also appropriate. Reviewing third parties for contractual compliance with CSR terms is a valid assurance activity. However, identifying and mitigating risks to meet CSR objectives is a management responsibility if internal audit owns the mitigation. Internal audit may identify risks during an engagement and recommend responses, but it should not implement or own mitigation. Therefore, items 1, 2, and 3 are appropriate, making Option A correct.
Question 53
Which of the following application controls is the most dependent on the password owner?
Correct Answer: A
Comprehensive and Detailed In-Depth Explanation: Password selection is the most dependent on the user, as it involves choosing and setting a secure password that meets organizational security requirements. Option B (Password aging) - Controlled by system settings, not directly by the user. Option C (Password lockout) - Automatically triggered after failed login attempts. Option D (Password rotation) - Enforced by system policies, not the individual user's decision. Since password security starts with user selection, Option A is correct. Reference: IIA IT Security - Access Control Best Practices
Question 54
Which of the following situations best applies to an organisation that uses a project, rather than a process, to accomplish its business activities?
Correct Answer: B
A project is a temporary initiative with a defined start and end date, specific objectives, and unique deliverables. Unlike ongoing business processes, projects have distinct goals, require coordination across various resources, and are not repeated continuously. Let's analyze each option: * Option A: A clothing company designs, makes, and sells a new item. * Incorrect. * While designing a new clothing item could be a project, the production and sale of the item are ongoing processes, not a one-time project. * Option B: A commercial construction company is hired to build a warehouse. * Correct. * Construction projects are classic examples of project-based work because: * They have a defined beginning and end. * They involve unique deliverables (a specific warehouse). * They require temporary coordination of resources. * IIA Reference: Internal auditors assess project management frameworks to ensure compliance with organizational and financial controls. (IIA Practice Guide: Auditing Project Management) * Option C: A city department sets up a new firefighter training program. * Incorrect. * If the training program is a one-time initiative, it could be considered a project. However, if the program is recurring (e.g., new firefighter training every year), it would be a process, not a project. * Option D: A manufacturing organization acquires component parts from a contracted vendor. * Incorrect. * Procurement of component parts is a continuous operational process, not a project. Thus, the verified answer is B. A commercial construction company is hired to build a warehouse.
Question 55
To assess the effectiveness of an organization ' s privacy program, which of the following approaches should an internal auditor take?
Correct Answer: D
The most effective way to assess a privacy program is to analyze the life cycle of sensitive data. This includes how personal or confidential data are collected, classified, used, stored, shared, retained, archived, and destroyed. Privacy effectiveness depends on whether controls operate throughout the full data life cycle, not merely whether policies exist. Employee interviews may provide useful context but are not sufficient. Penetration tests assess technical security weaknesses, not the overall privacy program. Reviewing policies and procedures confirms design but does not prove operational effectiveness. Internal audit should trace sensitive data flows, assess consent, access, retention, third-party sharing, breach response, and monitoring. Therefore, Option D is correct.