Get premium membership and access revision papers, questions with answers as well as video lessons.
Got a question or eager to learn? Discover limitless learning on WhatsApp now - Start Now!

Information Systems Audit Question Paper

Information Systems Audit 

Course:Bachelor Of Science In Information Technology

Institution: Kca University question papers

Exam Year:2009



UNIVERSITY EXAMINATIONS: 2008/2009
THIRD YEAR EXAMINATION FOR THE DEGREE OF BACHELOR OF
SCIENCE IN INFORMATION TECHNOLOGY
BIT 3201: INFORMATION SYSTEMS AUDIT
DATE: AUGUST 2009 TIME: 2 HOURS
INSTRUCTIONS: Answer question ONE and any other TWO questions
QUESTION ONE (COMPULSORY)
a) What are some of the characteristics of a system auditor? [2 Marks]
b) Describe what you understand by data forensics in system auditing [4 Marks]
c) The framework for the ISACA IS Auditing Standards provides for multiple levels, as follows:
(i) Standards
(ii) Guidelines
(iii)Procedures
Describe each of the above and give one example of each. [6 Marks]
d) Overview of the Risk-based Approach Consists of several steps. Describe them as they follow on
another and elaborate each step. [5 Marks]
e) What is ‘concept of materiality’ in relationship to system auditing? [3 Marks]
f) Audit planning consists of both short- and long-term planning.
(i) Describe each type mentioned above [2 Marks]
(ii) There are four major factors that affect planning. Describe them. [8 Marks]
2
QUESTION TWO
(a) Controls are generally categorized into three major classifications. Mention these three and give an
example of each in relation to information systems environment. [6 Marks]
(b) (i) What do you understand by Control Objectives for Information and related Technology
(CobiT)? [2 Marks]
(ii) CobiT is grouped into four major domains. Name them and give an example of each.
[8 Marks]
(c) Identify any four benefits of an organization having an information auditor. [4 Marks]
QUESTION THREE
a) Figure 3-1 below shows contingency planning hierarchies.
Describe and give an example of each:
i. Contingency planning
ii. Incident response
iii. Disaster recovery
iv. Business continuity
[8 Marks]
b) Discus in detail the information system audit process. [10 Marks]
c) An Information system auditor encounters several computer forensic scenarios in the course of his
work. Discus two common scenarios in the field [2 Marks]
3
QUESTION FOUR
a) Describe any six steps that guide an auditor while undertaking the audit tasks. [6 Marks]
b) Outline four procedures for testing and evaluating information System controls [4 Marks]
c) Describe three guidelines that assist system auditors detect and deter fraud occurrences in an
organization [6 Marks]
d) Discuss when and how an information system firm should retain a data forensic expert.
[4 Marks]
QUESTION FIVE
a) Briefly state three characteristics of a data forensic expert. [3 Marks]
b) There are numerous factors that a system auditor ought to put into consideration when undertaking
their duties. Discuss any three. [3 Marks]
c) Discuss five steps a data forensics firm goes through while reviewing a case [5 Marks]
d) Discuss three functions and facilities built-in to well designed computer systems to make the
systems auditors job easier. [9 Marks]






More Question Papers


Popular Exams



Return to Question Papers