WGU D560 – INTERNAL AUDITING I |
OBJECTIVE ASSESSMENT (OA) | QUESTIONS
AND ANSWERS | NEW 2025/2026 UPDATE |
WITH COMPLETE SOLUTION
WGU D560 – Internal Auditing I Objective
Assessment (OA)
Question 1
A company's internal auditor evaluates its internal control procedures
designed to prevent unauthorized access to resources. Which category of
business objective is the internal auditor helping the company
accomplish?
A. Financial
B. Structural
C. Operations ✅
D. Compliance
Rationale:
Controls that prevent unauthorized access safeguard assets and ensure
efficient and effective use of resources. These objectives directly support
operational effectiveness rather than financial reporting accuracy or
regulatory compliance. Internal controls over access reduce losses,
disruptions, and inefficiencies in daily operations. Therefore, this activity
aligns with operational objectives.
,Question 2
An internal auditor acts in a way that does not align with the Code of
Ethics. In which situation will the IIA be unable to enforce the Code of
Ethics?
A. The auditor works in consulting
B. The auditor reports to management
C. The auditor is neither an IIA member nor IIA-certified ✅
D. The auditor is a chief audit executive
Rationale:
The IIA can only enforce its Code of Ethics over individuals who are
members or who hold IIA certifications. Non-members are not subject to
IIA disciplinary authority. While ethical behavior is still expected,
enforcement authority is limited. Thus, lack of membership or certification
prevents enforcement.
Question 3
Which entity is responsible for developing, issuing, and maintaining the
Code of Ethics in the IPPF?
A. International Federation of Accountants
B. National Auditors Association
C. Global Accounting Standards Committee
D. International Internal Audit Standards Board ✅
Rationale:
The International Internal Audit Standards Board (IIASB) is responsible for
maintaining the IPPF, including the Code of Ethics. This ensures
consistency and global applicability of internal audit standards. Other
accounting bodies do not govern internal audit ethics. Therefore, IIASB is
the correct authority.
, Question 4
What is the internal audit’s responsibility regarding governance, risk
management, and control?
A. Creating
B. Applying
C. Directing
D. Evaluating ✅
Rationale:
Internal audit does not design or manage governance and controls. Its
role is to independently assess and evaluate their effectiveness. This
ensures objectivity and preserves independence. Evaluation provides
assurance and recommendations for improvement.
Question 5
An internal auditor evaluates controls protecting systems from computer
viruses and malware. Which type of IT technical control is being
evaluated?
A. Processing control
B. Entity-level control
C. Process-level control
D. Systems software control ✅
Rationale:
Anti-virus and anti-malware tools operate at the system software level.
These controls protect the operating environment rather than specific
business processes. They are foundational IT controls that support
application reliability. Hence, they are systems software controls.
OBJECTIVE ASSESSMENT (OA) | QUESTIONS
AND ANSWERS | NEW 2025/2026 UPDATE |
WITH COMPLETE SOLUTION
WGU D560 – Internal Auditing I Objective
Assessment (OA)
Question 1
A company's internal auditor evaluates its internal control procedures
designed to prevent unauthorized access to resources. Which category of
business objective is the internal auditor helping the company
accomplish?
A. Financial
B. Structural
C. Operations ✅
D. Compliance
Rationale:
Controls that prevent unauthorized access safeguard assets and ensure
efficient and effective use of resources. These objectives directly support
operational effectiveness rather than financial reporting accuracy or
regulatory compliance. Internal controls over access reduce losses,
disruptions, and inefficiencies in daily operations. Therefore, this activity
aligns with operational objectives.
,Question 2
An internal auditor acts in a way that does not align with the Code of
Ethics. In which situation will the IIA be unable to enforce the Code of
Ethics?
A. The auditor works in consulting
B. The auditor reports to management
C. The auditor is neither an IIA member nor IIA-certified ✅
D. The auditor is a chief audit executive
Rationale:
The IIA can only enforce its Code of Ethics over individuals who are
members or who hold IIA certifications. Non-members are not subject to
IIA disciplinary authority. While ethical behavior is still expected,
enforcement authority is limited. Thus, lack of membership or certification
prevents enforcement.
Question 3
Which entity is responsible for developing, issuing, and maintaining the
Code of Ethics in the IPPF?
A. International Federation of Accountants
B. National Auditors Association
C. Global Accounting Standards Committee
D. International Internal Audit Standards Board ✅
Rationale:
The International Internal Audit Standards Board (IIASB) is responsible for
maintaining the IPPF, including the Code of Ethics. This ensures
consistency and global applicability of internal audit standards. Other
accounting bodies do not govern internal audit ethics. Therefore, IIASB is
the correct authority.
, Question 4
What is the internal audit’s responsibility regarding governance, risk
management, and control?
A. Creating
B. Applying
C. Directing
D. Evaluating ✅
Rationale:
Internal audit does not design or manage governance and controls. Its
role is to independently assess and evaluate their effectiveness. This
ensures objectivity and preserves independence. Evaluation provides
assurance and recommendations for improvement.
Question 5
An internal auditor evaluates controls protecting systems from computer
viruses and malware. Which type of IT technical control is being
evaluated?
A. Processing control
B. Entity-level control
C. Process-level control
D. Systems software control ✅
Rationale:
Anti-virus and anti-malware tools operate at the system software level.
These controls protect the operating environment rather than specific
business processes. They are foundational IT controls that support
application reliability. Hence, they are systems software controls.