Event Log Aggregation System Risk Management

Answer Correct answer: A — Completeness testing has not been performed on the log data.

An IS auditor has been asked to review an event log aggregation system to ensure risk management practices have been applied. Which of the following should be of MOST concern to the auditor?

  1. Completeness testing has not been performed on the log data. Correct Answer
  2. Log feeds are uploaded via batch process.
  3. The log data is not normalized.
  4. Data encryption standards have not been considered.

Community Votes

A
67%
D
33%

67% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the auditor's ability to prioritize data integrity and availability (completeness) over data confidentiality (encryption) when reviewing log systems for risk management purposes.

The question addresses risk management in event log aggregation systems, where community consensus identifies completeness testing as the primary concern over encryption or formatting issues.

Many candidates choose D (Encryption) because they associate security primarily with confidentiality. However, if logs are incomplete, forensic analysis and compliance reporting become impossible, representing a higher operational risk.

Community Discussion (5 comments)

Swallows 👍 1 Selected: A
Data encryption is important, but ensuring integrity is a fundamental security requirement.
Sibsankar 👍 2
Data encryption is crucial for protecting sensitive information contained within the event logs. If encryption standards have not been considered or implemented, it poses a significant risk to the confidentiality and integrity of the log data. Unauthorized access or tampering could occur, leading to potential breaches or manipulation of critical information. The best answer is D
Swallows 👍 1 Selected: A
Of the three categories of information security, confidentiality, integrity, and availability, logs fall into the integrity category.
Sibsankar 👍 2
D is wrong A is the right answer.
EC123 👍 1 Selected: D
I though encryption is very important to ensure the log data is not being modified.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Completeness is the foundational requirement for any audit trail or log aggregation system. If log data is missing due to failures in collection or transmission, the organization loses visibility into security events, making it impossible to detect incidents or prove compliance. Without complete data, other controls like encryption are moot because there is no reliable record to protect.

Why the Other Options Are Wrong

While data encryption (D) protects confidentiality, it does not ensure that the logs exist or are accurate. Batch processing (B) is a valid technical method and not inherently risky unless latency requirements are violated. Non-normalized data (C) may affect analysis efficiency but does not compromise the existence or integrity of the log records themselves.

Community Comment Notes

Comments highlight the tension between confidentiality and integrity. While some users argue for encryption (D), others correctly point out that logs fall under the integrity category of security. The consensus emphasizes that without completeness, the log system fails its primary purpose: providing a reliable history of events.

Official Reference

Array

Exam Strategy

When auditing log systems, always prioritize the 'Availability' and 'Integrity' of the data first. Ask yourself: 'Can we even see the events?' before asking 'Are the events protected?'. Completeness is a prerequisite for all other security functions.

Frequently Asked Questions

Why is completeness more important than encryption for logs?

Encryption protects data at rest/transit, but if logs are incomplete, you cannot detect breaches or meet compliance. Integrity/availability is the primary goal of logging.

Does batch processing pose a risk to log integrity?

Batch processing can introduce latency but does not inherently compromise integrity. It is a design choice, whereas missing logs (incompleteness) is a critical control failure.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide