An Introduction to the Questions on the CIA Exam

There is one type of question you must master to pass the CIA Exam: multiple-choice. While you’ve probably answered plenty of multiple-choice questions (MCQs) before, you can’t write off the CIA version of MCQs, as they can be more complicated than standard MCQs. The more you know about CIA MCQs, the better you’ll do on the exam. We’ll discuss how many and what kind of MCQs are on the exam so you can be completely prepared to pass.

Exam Question Basics

A quick introduction to the exam format will help set the scene for the CIA MCQs. We’ve organized some of the exam basics for you in the chart below.

Exam Format


Number of Questions

Total Testing Time

Part 1: Internal Audit Basics


2 ½ hours

Part 2: Internal Audit Practice


2 hours

Part 3: Internal Audit Knowledge Elements


2 hours

Examples of Exam Questions

There are five different types of CIA exam MCQs, but at the most basic level, each question consists of three parts:

  • The question stem: The question stem includes the question, details necessary for answering the question, and extraneous information.
  • The best answer choice: The correct answer is the best possible answer choice of the four answer choices provided.
  • The distractors: The remaining three answer choices are designed to distract you by seeming plausible. For example, the distractors in computational questions are calculations resulting from common mistakes.

You could see any combination of the five different MCQ types when you sit for each exam part. We’ll discuss each so you know what to expect.

  • Direct Questions

This is the type of MCQ most candidates will be familiar with, and it’s the most common type of question on the CIA exam. Most will either ask you a question or have you complete a sentence, as the example below does, but all are straightforward and present four single-statement answer choices.

1. An organization is in the process of establishing its new internal audit activity. The controller has no previous experience with internal auditors. Due to this lack of experience, the controller advised the applicants that the CAE will be reporting to the external auditors. However, the new chief audit executive will have free access to the controller to report anything important. The controller will then convey the CAE’s concerns to the board of directors. The internal audit activity will

  1. Be independent because the CAE has direct access to the board.
  2. Not be independent because the CAE reports to the external auditors.
  3. Not be independent because the controller has no experience with internal auditors.
  4. Not be independent because the organization did not specify that the applicants must be certified internal auditors.
  • Negative Questions

Sometimes, MCQs like the one above include negative phrasing, with words like except, not, unless, least, etc. Here are some examples:

Which of the following is not included in the statement of scope in an engagement final communication?

The purposes of the Standards include all of the following except

Presumably, The IIA will print negative words in bold, as we did here, but you should always read the question stem carefully and completely just in case. These questions can be tricky because they ask you to select the false answer choice among three correct answers, which can feel counterintuitive. To avoid being caught off guard by the exam’s shifting expectations, always give the question stem your undivided attention.

  • Questions with Two or Three Answer Options

Other times, the exam will pose a question and provide a number of statements separate from the answer choices. The four answer choices will ask you to specify if one or more of the statements satisfy the question. This is demonstrated in the example below.

2. Which of the following facts, by themselves, could contribute to a lack of independence of the internal audit activity?

  1. The CEO accused the new auditor of not operating “in the best interests of the organization.”
  2. The majority of audit committee members come from within the organization.
  3. The internal audit activity’s charter has not been approved by the board.
  1. I only.
  2. II only.
  3. II and III only.
  4. I, II, and III.

Our candidates have informed us that this type of question is one of the most difficult to answer, so we’ve made a special Gleim Instruct video revealing the best approaches to multiple-answer MCQs. You can find this video in your Gleim CIA Review Course or at Basically, the best strategy is to determine which sentences you’re sure are right or wrong and use them to eliminate answer choices. Read the entire question stem carefully. Even if you’re not certain about the right answer, the amount of information provided gives you high odds for making a correct educated guess.

  • Questions with Several Variables

Some MCQs present several variables within each answer choice. The answer choices appear in columns, and you must select the one containing the right mix of variables.

3. Which of the following represents the best statement of responsibilities for risk management?

Management                                                   Internal Auditing                                              Board
A. Responsibility for risk                              Oversight role                                                   Advisory role
B. Oversight role                                            Responsibility for risk                                     Advisory role
C. Responsibility for risk                              Advisory role                                                    Oversight role
D. Oversight role                                           Advisory role                                                     Responsibility for risk

CIA candidates have confirmed that this type of question can also be quite difficult, but again, our CIA multiple-choice question video can help you ace it. Ruling out answers as you go through each column is a very efficient and effective approach. Consider the example above. If you can’t remember the responsibilities of Management and Internal Auditing but know the Board plays an oversight role, you can just pick C, and you’ll get the question right.

  • Questions with Graphical Illustrations

Finally, CIA MCQs occasionally require you to interpret a graph or other image before selecting the appropriate answer choice. See the example below.


cia exam questions

The yield curve shown implies that the

  1. Credit risk premium of corporate bonds has increased.
  2. Credit risk premium of municipal bonds has increased.
  3. Long-term interest rates have a higher annualized yield than short-term rates.
  4. Short-term interest rates have a higher annualized yield than long-term rates.

Most MCQs with visual elements are direct questions, but they may be one of the other question variations as well.

Question Scoring

The CIA exam is computer-graded, so you receive your score right away. A passing score is 600, which corresponds to the minimum level of knowledge that CIAs need. The IIA determines your CIA exam score by calculating the number of questions answered correctly from the total number of questions on the exam and converting that number to a scale ranging from 250-750. If you earn at least a 600, your score report will simply say that you passed. If you didn’t score a 600, your score report will show your score as a number less than 600. This number lets you compare your performance to a passing performance.

Review for Exam Questions

You’ll get all the exposure to exam questions you need by studying with the #1 CIA exam prep. Gleim CIA Review offers the best content coverage and the most refined test bank of MCQs available. Furthermore, our practice questions recreate the look, feel, and difficulty of the real CIA exam questions better than any other course on the market. See how well the first and most widely-used CIA review course will prepare you to pass by accessing our free CIA exam questions today!