nerdexam
Isaca

CISM · Question #261

For event logs to be acceptable for incident investigation, which of the following is the MOST important consideration to establish chain of evidence?

The correct answer is B. Time clock synchronization. Time clock synchronization (via NTP or similar) is the foundation of establishing a reliable chain of evidence from log data. Without synchronized clocks across all systems, log entries from different devices cannot be reliably correlated into a coherent timeline, making it impos

Submitted by fatema_kw· Apr 18, 2026Information Security Incident Management

Question

For event logs to be acceptable for incident investigation, which of the following is the MOST important consideration to establish chain of evidence?

Options

  • ACentralized logging
  • BTime clock synchronization
  • CAvailable forensic tools
  • DAdministrator log access

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    93% (37)
  • C
    5% (2)

Explanation

Time clock synchronization (via NTP or similar) is the foundation of establishing a reliable chain of evidence from log data. Without synchronized clocks across all systems, log entries from different devices cannot be reliably correlated into a coherent timeline, making it impossible to reconstruct the sequence of events. Discrepancies in timestamps can render logs legally inadmissible or factually unreliable. Centralized logging (A) improves collection but does not fix timestamp inconsistencies. Forensic tools (C) and administrator access (D) are useful capabilities but are secondary to having trustworthy, time-accurate log data to analyze in the first place.

Topics

#Log Management#Incident Response#Digital Forensics#Chain of Evidence

Community Discussion

No community discussion yet for this question.

Full CISM Practice