What Must an IS Auditor Verify in Log Management Across Locations?

Information Systems Operations / Log Management
Answer Correct answer: C — An IS auditor must verify that server log files are synchronized across geographic sites to ensure a reliable timeline of events.

An IS auditor is evaluating the log management system for an organization with devices and systems in multiple geographic locations. Which of the following is MOST important for the auditor to verify?

  1. Log files are reviewed in multiple locations.
  2. Log files are encrypted and digitally signed.
  3. Log files of the servers are synchronized. Correct Answer
  4. Log files are concurrently updated.

Community Votes

C
62%
B
38%

62% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests log reliability and time-based correlation in a multi-site environment, and the common trap is picking B (encryption and digital signature) instead of C (synchronization).

When systems are spread over multiple geographic sites, the CISA answer hinges on whether the log files themselves are synchronized to support event reconstruction. This page explains why option C is the best audit verification over encryption/signing or review location choices.

Choosing B for encryption and digital signature because it protects log integrity, while missing that geographically separated logs that are not synchronized cannot be converted into a meaningful chronological audit trail.

Community Discussion (4 comments)

blehbleh 👍 2 Selected: C
It is C, it doesn't matter if they are encrypted and digitally signed if it isn't synchronized. You don't even know what is where or what is missing if the logs are not synchronized. The question even states in different geographical areas. It is literally pushing you to ensure synchronization between them.
RS66 👍 1 Selected: B
B. Log files are encrypted and digitally signed.
Swallows 👍 3 Selected: C
For devices and systems in multiple geographic locations, having synchronized log files is critical for overall monitoring and analysis integrity, ensuring log data is consistent and enables effective problem resolution and analysis of security incidents.
Swallows 👍 2 Selected: B
This ensures the integrity, authenticity, and confidentiality of the log data, which is crucial for protecting against tampering and ensuring trustworthiness across multiple geographic locations. While synchronization is important for consistency, security takes precedence in log management.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

With log sources placed in multiple geographic locations, the auditor's key task is to reconstruct a single, reliable timeline of events. Only synchronized logs establish a common frame of reference, because servers in different regions can introduce local time drift that distorts event order. From an ISACA audit-assurance perspective, if the auditor cannot verify sequencing across servers, incident discovery and forensic reconstruction are not trustworthy. Option C produces that foundational verification.

Why the Other Options Are Wrong

A is about procedural convenience rather than evidence assurance; reviewing log files in each location may complement the process but is not the core check. B is a legitimate control for confidentiality and tamper detection, but it protects individual files and does not assemble a unified timeline for geographically distributed events. D is premature and largely overlaps with C, while C more exactly captures the audit requirement for synchronized logs and timestamps. Thus C is the "most important" item for the auditor to verify.

Community Comment Notes

The community strongly favors option C, with commenters noting that multiple geographic areas make synchronization the essential foundation for security analysis. As blehbleh put it, "it doesn't matter if they are encrypted and digitally signed if it isn't synchronized." Another comment acknowledged that synchronization is important for consistency, and no comment demonstrated that digital signatures solve the multi-site time-ordering problem.

Exam Strategy

Treat the phrase "multiple geographic locations" as a direct reminder that distributed logs must share a consistent time base before any other control becomes meaningful. If one answer addresses time synchronization and another addresses cryptographic protection, prioritize the synchronization in this type of CISA scenario.

Frequently Asked Questions

Why is log synchronization more important than encryption in this CISA question?

Because logs from different geographic locations must share a consistent time basis for correlation; encryption and signatures protect integrity but not chronological order.

Could encrypted and digitally signed logs ever be enough without synchronization?

Only if timestamps were already proven consistent; otherwise signed logs from separate places cannot reliably prove event sequence or detect missing records.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide