Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free OCEG GRC Auditor Certification Exam GRCA Exam Questions

Page: 1 / 8 Total 45 questions

Want more questions? Get Premium Access.

Question 1

Which of the following is defined as "a measure of the desirable effect of uncertainty on objectives?

Correct Answer: A. Risk
Explanation:

Risk is defined as a measure of the desirable effect of uncertainty on objectives. According to the ISO 31000 standard, risk is 'the effect of uncertainty on objectives' which can be either positive (opportunity) or negative (threat). This definition encompasses the uncertainty that can impact the achievement of goals and objectives. It highlights that risk is not just about potential losses but also about potential gains that come from taking risks. Reference:

ISO 31000:2018 - Risk management -- Guidelines

NIST SP 800-30 Rev. 1 - Guide for Conducting Risk Assessments


Question 2

Follow-up on the implementation status of the recommendation based on high priority, due or overdue items or time-sensitive items is known as:

Correct Answer: C. Follow-Up by Targeted Review
Explanation:

Follow-up on the implementation status of recommendations based on high priority, due or overdue items, or time-sensitive items is known as Follow-Up by Targeted Review. This approach focuses on areas that are of critical importance or where timely implementation is essential. It helps ensure that the most significant risks are addressed promptly and that any delays in addressing recommendations are identified and managed. Reference:

IIA Standards for the Professional Practice of Internal Auditing

COSO Internal Control -- Integrated Framework


Question 3

What are the dimensions of TOTAL Performance?

Correct Answer: C. Effectiveness, Resiliency, and Agility
Explanation:

The dimensions of TOTAL Performance are Effectiveness, Resiliency, and Agility. Effectiveness refers to achieving the desired outcomes. Resiliency is the ability to recover from setbacks and continue operations. Agility is the capacity to adapt quickly to changes and new opportunities. These three dimensions collectively ensure that an organization can perform well under various conditions and sustain its success over time. Reference:

ISO 9001:2015 - Quality management systems -- Requirements

COSO Enterprise Risk Management -- Integrating with Strategy and Performance


Question 4

Which of these is defined as "internally directing, controlling and evaluating an entity, process or resource"

Correct Answer: A. Management
Explanation:

Management is defined as 'internally directing, controlling and evaluating an entity, process or resource.' Management involves overseeing the day-to-day operations of an organization, making decisions, setting policies, and ensuring that the organization's resources are used effectively to achieve its goals. This function includes planning, organizing, leading, and controlling organizational activities to meet established objectives. Reference:

ISO 9001:2015 - Quality management systems -- Requirements

COSO Internal Control -- Integrated Framework


Question 5

What is the BEST sequence of testing

Correct Answer: A. Control testing and then substantive testing
Explanation:

The best sequence of testing is to conduct control testing first and then substantive testing. This approach ensures that the effectiveness of internal controls is evaluated before examining the details of transactions and data. By testing controls first, assurance providers can determine if controls are reliable and can potentially reduce the extent of substantive testing needed. Effective controls can provide confidence that transactions and data are accurate, reducing the need for extensive substantive testing. Reference:

AICPA Auditing Standards

ISO 19011:2018 - Guidelines for auditing management systems


Question 6

If (Inherent Risk x Control Risk) is low

Correct Answer: B. We may consider performing less testing
Explanation:

If the inherent risk and control risk are both low, we may consider performing less testing. Inherent risk refers to the risk of an event occurring without considering any controls, while control risk is the risk that controls will not prevent or detect the event. When both risks are low, it indicates that the likelihood of issues occurring and not being detected is minimal, allowing for a reduced level of testing. This approach helps in efficiently allocating resources while maintaining a reasonable level of assurance. Reference:

AICPA Auditing Standards

ISO 31000:2018 - Risk management -- Guidelines