Multiple Choice
Which of the following would not be an appropriate step for an internal auditor to perform during an assessment of compliance with an organization's privacy policy?
A) Determine who can access databases containing confidential information.
B) Evaluate the organization's privacy policy to determine if appropriate information is covered.
C) Analyze access to permanent files and reports containing confidential information.
D) Evaluate the government's security measures related to confidential information received from the organization.
Correct Answer:

Verified
Correct Answer:
Verified
Q95: According to IIA guidance, which of the
Q96: In addition to the internal auditor, which
Q97: According to the Standards, which of the
Q98: A manufacturing organization is considering a merger
Q99: Which of the following would be an
Q101: Which of the following would be the
Q102: Five brand managers in a consumer products
Q103: When interviewing an individual suspected of fraud,
Q104: In which of the following situations would
Q105: A company's cellular phone costs vary significantly