Showing posts with label Computer Fraud. Show all posts
Showing posts with label Computer Fraud. Show all posts

Which of the following is not a way to improve fraud detection?

Which of the following is not a way to improve fraud detection?



A) Install fraud detection software.
B) Implement a fraud hotline.
C) Employ a computer security officer.
D) Implement computer-based controls over input, processing, storage, and output activities.


Answer: D

Which of the following is not a way to reduce fraud losses?

Which of the following is not a way to reduce fraud losses?



A) Conduct periodic external and internal audits.
B) Maintain adequate insurance.
C) Use software to monitor system activity.
D) Store backup copies of program and data files.


Answer: A

Which of the following is not a way to make fraud less likely to occur?

Which of the following is not a way to make fraud less likely to occur?



A) Adopt an organizational structure that minimizes the likelihood of fraud.
B) Create an organizational culture that stresses integrity and commitment to ethical values.
C) Create an audit trail so individual transactions can be traced.
D) Effectively supervise employees.


Answer: C

The fraud appears to be misappropriation of assets that is being concealed with a lapping scheme. Controls would include:

A teller at a savings and loan drive-through accepted a cash payment from customer #1 for an auto loan. The teller appeared to process the payment, but told the customer the printer was jammed and she can't print a receipt. The customer accepted the excuse and drove away. The teller pocketed the cash and wrote down customer #1's loan number and payment amount for future reconciling. A couple of days before customer #1's monthly statement was printed, the teller recorded a cash payment from customer #2 as if it were made by customer #1. The teller pocketed the difference between the two payments. The teller continued to steal and misapply customer payments for the next two years without detection.

Identify the type of fraud scheme described. Describe five controls you would implement to address the fraud risk, and label each control as preventive or detective.

The fraud appears to be misappropriation of assets that is being concealed with a lapping scheme. Controls would include:



1. rotation of duties (primarily detective)
2. mandatory vacations (primarily detective)
3. surveillance with cameras (primarily detective)
4. staggered statement printing schedules, unknown to tellers (detective)
5. sequentially prenumbered, duplicate receipts (detective)
6. segregation of duties between cash handling and recording (preventive)
7. encourage customers to utilize on-line banking for loan payments and to frequently check balances (detective)

Describe four ways companies can reduce losses from fraud.

Describe four ways companies can reduce losses from fraud.



Answer: Maintain adequate insurance. Keep a current backup copy of all program and data files in a secure off-site location. Develop a contingency plan for fraud occurrences and other disasters that might occur. Use special software designed to monitor system activity and help companies recover from frauds and malicious actions.

Describe at least four ways a company can make fraud less likely to occur.

Describe at least four ways a company can make fraud less likely to occur.



Answer: A company can decrease fraud by: good hiring and firing practices; good management of unhappy employees; training in fraud awareness; manage and track computer licenses; implement signed confidentiality agreements; maintain visible security; educate the workforce in ethics and the penalties for illegal acts.

What are the actions recommended by the Treadway Commission to reduce the possibility of fraudulent financial reporting?

What are the actions recommended by the Treadway Commission to reduce the possibility of fraudulent financial reporting?



Answer: organizational environment that contributes to the integrity of the financial reporting process. Identify and understand the factors that lead to fraudulent financial reporting. Assess the risk of fraudulent financial reporting within the company. Design and implement internal controls to provide reasonable assurance that the fraudulent financial reporting is prevented.

On Tuesday morning, Chen Lee, Chief Information Officer at American Trading Corporation (ATC), got some bad news. The hard drive use to store system data backups was lost while it was being transported to an offsite storage location. Chen called a meeting of her technical staff to discuss the implications of the loss. Which of the following is most likely to relieve her concerns over the potential cost of the loss?

On Tuesday morning, Chen Lee, Chief Information Officer at American Trading Corporation (ATC), got some bad news. The hard drive use to store system data backups was lost while it was being transported to an offsite storage location. Chen called a meeting of her technical staff to discuss the implications of the loss. Which of the following is most likely to relieve her concerns over the potential cost of the loss?



A) ATC has a comprehensive disaster recovery plan.
B) The hard drive was encrypted and password protected.
C) The shipper has insurance that will reimburse ATC for the cost of the hard drive.
D) ATC has a copy of the hard drive onsite, so a new copy for storage offsite can easily be prepared.


Answer: B

Most frauds are detected by

Most frauds are detected by



A) external auditors.
B) hotline tip.
C) internal auditors.
D) the police.


Answer: B

Why do fraudulent acts often go unreported and are therefore not prosecuted?

Why do fraudulent acts often go unreported and are therefore not prosecuted?



Answer: Most fraud cases go unreported and are not prosecuted for several reasons. Many cases of computer fraud are as yet still undetected. As new technology and methods become available to organizations, prior undetected fraud may be revealed in the future. A second reason is that companies are reluctant to report computer fraud and illegal acts simply because of bad publicity—a highly visible case can undermine consumer confidence in an organization such as a financial institution. Also, the fact that a fraud has occurred may indeed encourage others to attempt to commit further acts against the organization. It would seem that unreported fraud creates a false sense of security, as people think systems are more secure than they are in reality. Another reason for not reporting fraudulent acts is the fact that the court system and law enforcement is busy with violent crimes and criminals in its system. There is little time left to go after a crime where no physical harm is present. Also, the court system tends to treat teen hacking and cracking as "acts of childhood" rather than as serious crimes—this leads to many plea bargains when a computer fraud is brought to trial. Another reason is that a computer fraud case is difficult, costly, and time-consuming to investigate and prosecute. Before 1986 no federal law existed governing computer fraud. Law enforcement officials, lawyers, and judges generally lack the computer skills necessary to properly evaluate, investigate, and prosecute computer crimes. Sadly, when all is said and done a successful prosecution and conviction of computer fraud results in a very light sentence. All of these factors contribute to the under reporting and lack of prosecution of computer fraud crimes. Not everyone agrees on what constitutes computer fraud:
• Many networks have a low level of security
• Many Internet pages give instruction on how to carry out computer crimes
• Law enforcement has difficulty keep up with the growing number of computer frauds
• The total dollar value of losses from computer fraud is difficult to estimate.

Why is computer fraud on the rise?

Why is computer fraud on the rise?



Answer: Not everyone agrees on what constitutes computer fraud and some people may commit computer fraud unwittingly and not be aware of it. Many computer frauds go undetected. The belief that "it just can't happen to us." Most networks have a low level of security. Many Internet sites provide guidance on how to commit computer crimes. Law enforcement is unable to keep up with the number of computer frauds. Most frauds are not reported. The total dollar value of losses is difficult to calculate.

Why do many fraud cases go unreported and unprosecuted?

Why do many fraud cases go unreported and unprosecuted? 



A) Major fraud is a public relations nightmare.
B) Fraud is difficult, costly, and time-consuming to investigate and prosecute.
C) Law enforcement and the courts are often so busy with violent crimes that little time is left for fraud cases.
D) all of the above


Answer: D

Why is computer fraud often more difficult to detect than other types of fraud?

Why is computer fraud often more difficult to detect than other types of fraud? 



A) Rarely is cash stolen in computer fraud.
B) The fraud may leave little or no evidence it ever happened.
C) Computers provide more opportunities for fraud.
D) Computer fraud perpetrators are just more clever than other types of criminals.


Answer: B

Why is computer fraud often much more difficult to detect than other types of fraud?

Why is computer fraud often much more difficult to detect than other types of fraud?



A) because massive fraud can be committed in only seconds, leaving little-to-no evidence
B) because most perpetrators invest their illegal income rather than spend it, concealing key evidence
C) because most computer criminals are older and more cunning than perpetrators of other types of fraud
D) because perpetrators usually only steal very small amounts of money at a time, requiring a long period of time to pass before discovery


Answer: A

How does the U.S. Justice Department define computer fraud?

How does the U.S. Justice Department define computer fraud?



A) as any crime in which a computer is used
B) as any act in which cash is stolen using a computer
C) as an illegal act in which a computer is an integral part of the crime
D) as an illegal act in which knowledge of computer technology is essential


Answer: D