9 real CIA-2 sample questions, each with an explanation of why every option is right or wrong. No account, no card. This is the reasoning the CIA-2 tests: knowing why the tempting answer is wrong, not just spotting the right one.
The real CIA-2 is 100 questions in 120 minutes, pass mark 600 / 750 (scaled). For a domain-by-domain breakdown and a study plan, read the CIA-2 study guide. The full bank has 309 questions.
lock_openFree sampleEngagement Planningmedium
During planning, an audit lead must decide whether an upcoming procurement engagement is assurance or advisory. Which statement correctly distinguishes the two engagement types?
- AIn an assurance engagement the auditor advises management and management remains free to reject the recommendations offered.
- BAn assurance engagement involves a three-party relationship and an objective assessment against criteria, while advisory work is directed by the client to add value.check_circle Correct
- CIn an advisory engagement the auditor issues an independent opinion to third parties on the adequacy of the control environment.
- DBoth engagement types require the auditor to design and then implement the controls that management will later operate.
Distinguish assurance engagements, which give an objective three-party assessment against criteria, from advisory engagements directed by the client to add value. Assurance depends on a three-party relationship and evaluation against suitable criteria so that reliant users can trust the conclusion, whereas advisory work is shaped with the client and produces no independent opinion for third parties.
Why A is wrong: This is tempting because advice is common in audit work, but it describes advisory work; assurance involves an independent assessment against criteria, not optional advice.
Why B is correct: Correct because assurance rests on a process owner, an assessor, and a user, tested against defined criteria, whereas advisory scope and nature are agreed with the client.
Why C is wrong: This sounds authoritative, but issuing an independent opinion to reliant parties is the hallmark of assurance, not advisory work, which is client-directed counsel.
Why D is wrong: This is plausible because auditors advise on control gaps, but designing and implementing controls destroys independence; management owns and builds its own controls.
lock_openFree sampleEngagement Planningmedium
Midway through planning, management refuses to grant the audit team access to a set of vendor payment records that fall squarely within the agreed engagement objectives. In internal audit terms, this situation is best described as which of the following?
- AA residual risk, because the missing records represent exposure that remains after controls have already been applied to payments.
- BAn engagement objective, because the records define what the team set out to evaluate at the start of the work.
- CA scope limitation, because a restriction is preventing the team from gathering evidence needed to meet the engagement objectives.check_circle Correct
- DA control deficiency, because withholding the records shows that a payment control has failed to operate effectively.
Identify a restriction on access to information needed to meet engagement objectives as a scope limitation requiring the chief audit executive's attention. A scope limitation arises when circumstances restrict the audit from obtaining the evidence necessary to achieve its objectives; recognising it as such triggers evaluation and, where significant, communication to the board or senior management.
Why A is wrong: This borrows a real term, but residual risk describes leftover exposure after controls, not a restriction on the auditor's access to evidence.
Why B is wrong: This is tempting since the records relate to the objective, but the objective is the goal being tested, not the access restriction that impedes it.
Why C is correct: Correct because a condition that blocks access to information required to achieve the objectives is a scope limitation, which the chief audit executive should evaluate and often report.
Why D is wrong: This confuses two ideas; a refusal of access limits the audit, whereas a control deficiency is a weakness in management's own control operation.
lock_openFree sampleEngagement Planningmedium
During planning, management informs the internal auditor that access to a key third-party service provider's records will not be granted for the engagement. In internal audit terms, this situation is best described as which of the following?
- AA residual risk that the auditor should simply accept and then document within the engagement work programme.
- BAn inherent limitation of sampling that reduces the reliability of every item of evidence gathered.
- CA control deficiency that must be reported immediately as a significant finding to the audit committee.
- DA scope limitation that the auditor should evaluate and, if significant, discuss with senior management and the board.check_circle Correct
Identify a denial of access to needed information as a scope limitation requiring evaluation and escalation when significant. A scope limitation arises when circumstances restrict the internal auditor's ability to gather the evidence an engagement needs. Denial of access to a service provider's records is such a restriction, and a significant one must be evaluated and communicated to senior management and the board.
Why A is wrong: Tempting because it involves accepting a condition, but a denial of access restricts the work itself rather than being a risk remaining after controls operate.
Why B is wrong: Sampling limitations concern how conclusions are drawn from tested items; a blanket denial of access is a restriction on scope, not a property of sampling.
Why C is wrong: A restriction on the engagement is not itself a control weakness in the area under review, and treating it as a confirmed finding prejudges evidence not yet gathered.
Why D is correct: A restriction on access to information needed for the engagement is a scope limitation; when significant it should be assessed and raised with senior management and the board.
lock_openFree sampleInformation Gathering, Analysis, and Evaluationhard
An internal auditor gathers a signed contract from the client's legal department, a verbal assurance from the process owner, and a copy of an invoice provided by the vendor being examined. When judging the reliability of this evidence, which principle should the auditor apply first?
- AEvidence obtained from a source independent of the client is generally more reliable than evidence supplied by an interested party.check_circle Correct
- BVerbal assurances from a process owner are the most reliable because they come directly from the person accountable for the control.
- CDocumentary evidence is reliable purely because it is written, regardless of who produced or supplied it.
- DThe most recently dated item is the most reliable because it reflects the current state of the process.
Recognise that independence of the evidence source is a primary factor determining evidence reliability. Reliability rises with the independence and objectivity of the source, because a party with no interest in the outcome has little incentive to distort what the evidence shows, unlike an internal owner or the audited vendor.
Why A is correct: Independence of source is a core determinant of reliability; evidence from a party with no stake in the outcome is less likely to be biased or manipulated.
Why B is wrong: Tempting because the owner is accountable, but oral evidence from an interested internal party is among the least reliable forms and needs corroboration.
Why C is wrong: Form of evidence matters, but written form alone does not confer reliability when the document originates from an interested source such as the vendor.
Why D is wrong: Recency can aid relevance, yet it says nothing about source independence or authenticity, so it is the wrong first test of reliability.
lock_openFree sampleInformation Gathering, Analysis, and Evaluationhard
During a payroll engagement, an auditor confirms overtime hours by comparing supervisor-approved timesheets against independent building access logs and system login records. Which concept best describes what the auditor is applying by drawing on these multiple independent items?
- ASufficiency, meaning the auditor has gathered a large enough quantity of evidence to satisfy the objective.
- BCorroboration, whereby consistent evidence from separate independent sources strengthens confidence in a conclusion.check_circle Correct
- CRelevance, meaning the evidence logically relates to the specific assertion being tested.
- DReperformance, meaning the auditor independently re-executes the client's control to test its operation.
Identify corroboration as the use of consistent, independent sources to reinforce an audit conclusion. Corroboration works because agreement between sources that do not depend on one another makes it far less likely that all are wrong or manipulated, so the combined evidence is more persuasive than any single item.
Why A is wrong: Sufficiency concerns quantity and is tempting here, but the point of cross-checking independent sources is agreement across them, not sheer volume.
Why B is correct: Comparing several independent sources that agree is the definition of corroboration, which raises the persuasiveness of the overall evidence.
Why C is wrong: Relevance is necessary but describes the link between evidence and objective, not the act of confirming one source against others.
Why D is wrong: Reperformance is a distinct technique that re-runs a control; here the auditor is matching existing records, not re-executing the payroll control.
lock_openFree sampleInformation Gathering, Analysis, and Evaluationhard
A lead auditor tells the team that they now hold enough appropriate evidence to support the engagement conclusion. In the context of evidence evaluation, the phrase describing evidence as sufficient refers most precisely to which attribute?
- AThe relevance of the evidence to the particular control objective under review.
- BThe reliability of the evidence, driven by the independence and competence of its source.
- CThe quantity of evidence, judged as enough for a prudent auditor to reach the same conclusion.check_circle Correct
- DThe authenticity of the evidence, meaning it is genuine and has not been altered.
Define sufficiency of evidence as the quantity needed for a prudent person to reach the same conclusion. Sufficiency is fundamentally a quantitative test: it asks whether the volume of evidence, given its quality, would persuade a prudent and informed person to arrive at the same conclusion the auditor reached.
Why A is wrong: Relevance is a genuine evidence attribute and easily confused with sufficiency, but it concerns logical connection, not how much evidence has been gathered.
Why B is wrong: Reliability is a quality dimension often paired with sufficiency, yet it addresses trustworthiness of the source rather than the amount held.
Why C is correct: Sufficiency is the measure of quantity, assessed against whether a prudent, informed person would find the amount adequate to support the conclusion.
Why D is wrong: Authenticity supports reliability and sounds rigorous, but it describes whether an item is genuine, not whether enough has been collected.
lock_openFree sampleEngagement Supervision and Communicationmedium
In the context of an internal audit engagement, what does appropriate supervision primarily provide assurance about?
- AThat the engagement objectives are achieved and the work supports the conclusions reached.check_circle Correct
- BThat every individual finding is separately escalated to the audit committee before the report is issued.
- CThat the auditors in charge design the operating controls that management will later implement.
- DThat the fieldwork is completed within the originally budgeted hours regardless of scope changes.
Understand that engagement supervision gives reasonable assurance that objectives are achieved and evidence supports the conclusions. Supervision is a quality mechanism: through direction, review, and oversight it gives reasonable assurance that engagement objectives are met and that the workpapers adequately support the conclusions and results communicated, rather than serving as a reporting or control-design function.
Why A is correct: Supervision exists to give reasonable assurance that objectives are met, quality is attained, and evidence supports the conclusions; that is its defining purpose.
Why B is wrong: Escalation of individual findings is a reporting and communication judgement, not the aim of supervision; treating supervision this way confuses two distinct activities.
Why C is wrong: Designing operating controls would breach independence and objectivity; supervision never extends internal audit into owning management's controls.
Why D is wrong: Budget adherence is a management concern that can be part of supervision, but it is not its primary assurance purpose and is subordinate to quality.
lock_openFree sampleEngagement Supervision and Communicationmedium
The extent of supervision that an engagement requires is best described as depending on which of the following?
- AThe number of days remaining before the audit committee's next scheduled meeting.
- BThe proficiency and experience of the internal auditors and the complexity of the engagement.check_circle Correct
- CThe preference of the auditee for a lighter or heavier audit presence on site.
- DA fixed organisation-wide ratio of one reviewer for every staff auditor on any engagement.
Recognise that the extent of supervision varies with the auditors' proficiency and the complexity of the engagement. The appropriate amount of supervision is not fixed; it increases when assigned auditors are less experienced or when the engagement is complex, and decreases when highly proficient staff handle straightforward work, so oversight is matched to the risk of unsupported conclusions.
Why A is wrong: Committee timing may pressure the schedule, but it does not determine how much direction and review the work itself needs; this confuses scheduling with supervision.
Why B is correct: Supervision is scaled to the competence of the staff assigned and the difficulty of the work; less experienced auditors on complex engagements need more direction and review.
Why C is wrong: Letting the auditee dictate supervision would compromise objectivity; the auditee's comfort is not a basis for setting the level of oversight.
Why D is wrong: A rigid fixed ratio ignores that supervision must flex with competence and complexity; a single mandated ratio cannot fit engagements of differing risk.
lock_openFree sampleEngagement Supervision and Communicationmedium
When a reviewer signs off on an internal auditor's workpaper, what does that evidence of review most directly confirm?
- AThat the auditee's management has formally accepted the finding documented in the workpaper.
- BThat the workpaper was completed strictly within the hours allotted in the engagement budget.
- CThat the work was performed, adequately supports the conclusions, and meets the required quality.check_circle Correct
- DThat the workpaper will be exempt from any later review by the quality assurance programme.
Understand that a reviewer's workpaper sign-off attests that the work was performed and supports the conclusions to the required quality. Documented review provides evidence that supervision occurred: it confirms procedures were completed, the workpaper adequately supports the observations and conclusions, and applicable quality requirements were satisfied, which is distinct from management acceptance or budget compliance.
Why A is wrong: Management acceptance is captured separately in the response to findings; a reviewer's sign-off speaks to audit quality, not to the auditee agreeing.
Why B is wrong: Time budgeting is a resourcing matter; the review sign-off addresses whether the work and its support are adequate, not how long it took.
Why C is correct: The reviewer's evidence of review confirms the procedures were carried out, the documentation supports the results, and quality standards were met; that is exactly what review attests.
Why D is wrong: Ongoing quality assurance can still examine reviewed workpapers; a sign-off never grants immunity from the periodic quality assessment process.
Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. CIA-2 and related marks belong to their respective owners.