IIA
IIA-CIA-PART3 · Question #290
An IT auditor is evaluating IT controls of a newly purchased information system. The auditor discovers that logging is not configured al database and application levels. Operational management…
The correct answer is C. The organization will be unable to determine why intrusions and cyber incidents took place. You've hit your session limit · resets 10:20pm (America/New_York)
Question
An IT auditor is evaluating IT controls of a newly purchased information system. The auditor discovers that logging is not configured al database and application levels. Operational management explains that they do not have enough personnel to manage the logs and they see no benefit in keeping logs. Which of the fallowing responses best explains risks associated with insufficient or absent logging practices?
Options
- AThe organization will be unable to develop preventative actions based on analytics.
- BThe organization will not be able to trace and monitor the activities of database administers.
- CThe organization will be unable to determine why intrusions and cyber incidents took place.
- DThe organization will be unable to upgrade the system to newer versions.
How the community answered
(23 responses)- A4% (1)
- B13% (3)
- C74% (17)
- D9% (2)
Explanation
You've hit your session limit · resets 10:20pm (America/New_York)
Community Discussion
No community discussion yet for this question.