ExamGecko
Question list
Search
Search

Related questions











Question 727 - CISA discussion

Report
Export

An IS auditor has been asked to review an event log aggregation system to ensure risk management practices have been applied. Which of the following should be of MOST concern to the auditor?

A.
Log feeds are uploaded via batch process.
Answers
A.
Log feeds are uploaded via batch process.
B.
Completeness testing has not been performed on the log data.
Answers
B.
Completeness testing has not been performed on the log data.
C.
The log data is not normalized.
Answers
C.
The log data is not normalized.
D.
Data encryption standards have not been considered.
Answers
D.
Data encryption standards have not been considered.
Suggested answer: B

Explanation:

The IS auditor should be most concerned if completeness testing has not been performed on the log data, as this could indicate that some logs are missing, corrupted, or tampered with, and that the log aggregation system is not reliable or accurate12.Completeness testing is a process of verifying that all the logs generated by the source systems are successfully collected, transferred, and stored by the log aggregation system, and that there are no gaps or inconsistencies in the log data34. Completeness testing is essential for ensuring the integrity and validity of the log data, and for supporting the risk management practices of the organization.

Reference

1: Log Aggregation: How it Works, Methods, and Tools - Exabeam22: Log Aggregation & Monitoring Relation in Cybersecurity43: Log Aggregation: What It Is & How It Works | Datadog34: Data Flow Testing - GeeksforGeeks1

asked 18/09/2024
Ubeydullah Kara
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first