nerdexam
Isaca

CISA · Question #239

An organization has decided to reengineer business processes to improve the performance of overall IT service delivery. Which of the following recommendations from the project team should be the GREAT

The correct answer is A. Disable operational logging to enhance the processing speed and save storage.. An IS auditor should be most concerned by a recommendation to disable operational logging for IT service delivery, as this severely compromises security, auditability, and troubleshooting capabilities.

Submitted by tarun92· Apr 18, 2026Protection of Information Assets

Question

An organization has decided to reengineer business processes to improve the performance of overall IT service delivery. Which of the following recommendations from the project team should be the GREATEST concern to the IS auditor?

Options

  • ADisable operational logging to enhance the processing speed and save storage.
  • BAdopt a service delivery model based on insights from peer organizations.
  • CDelegate business decisions to the chief risk officer (CRO).
  • DEliminate certain reports and key performance indicators (KPIs).

How the community answered

(50 responses)
  • A
    76% (38)
  • B
    6% (3)
  • C
    14% (7)
  • D
    4% (2)

Why each option

An IS auditor should be most concerned by a recommendation to disable operational logging for IT service delivery, as this severely compromises security, auditability, and troubleshooting capabilities.

ADisable operational logging to enhance the processing speed and save storage.Correct

Disabling operational logging to enhance processing speed and save storage is a significant concern for an IS auditor because it severely compromises the ability to monitor, troubleshoot, and audit IT service delivery. Without logs, it becomes impossible to detect security incidents, trace performance issues, or provide evidence for compliance, thereby increasing operational and security risks.

BAdopt a service delivery model based on insights from peer organizations.

Adopting a service delivery model based on insights from peer organizations is a potentially positive strategy for improvement and efficiency, and generally not a concern from an audit perspective unless there are specific risks with the model.

CDelegate business decisions to the chief risk officer (CRO).

Delegating business decisions to the chief risk officer (CRO) aligns with good governance and risk management principles, as the CRO is responsible for managing organizational risks.

DEliminate certain reports and key performance indicators (KPIs).

Eliminating certain reports and KPIs might be a concern if essential metrics are lost, but it is not as fundamentally damaging to security, auditability, and incident response as disabling operational logging entirely.

Concept tested: IT governance, audit concerns, logging, security controls

Source: https://learn.microsoft.com/en-us/azure/architecture/guide/security/monitoring-logging

Topics

#Operational Logging#Security Controls#Audit Trails#Risk Management

Community Discussion

No community discussion yet for this question.

Full CISA Practice