nerdexam
Isaca

CISA · Question #119

An IS auditor has been asked to review an event log aggregation system to ensure risk management practices have been applied. Which of the following should be of MOST concern to the auditor?

Sign in or unlock CISA to reveal the answer and full explanation for question #119. The question stem and answer options stay visible for context.

Submitted by ricky.ec· Apr 18, 2026Information System Auditing Process

Question

An IS auditor has been asked to review an event log aggregation system to ensure risk management practices have been applied. Which of the following should be of MOST concern to the auditor?

Options

  • ACompleteness testing has not been performed on the log data.
  • BLog feeds are uploaded via batch process.
  • CThe log data is not normalized.
  • DData encryption standards have not been considered.

Unlock CISA to see the answer

You've previewed enough free CISA questions. Unlock CISA for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Event Log Auditing#Data Completeness#Risk Management#IS Audit Concerns
Full CISA Practice