What Must an IS Auditor Verify in Log Management Across Locations?
An IS auditor is evaluating the log management system for an organization with devices and systems in multiple geographic locations. Which of the following is MOST important for the auditor to verify?
Community Votes
62% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests log reliability and time-based correlation in a multi-site environment, and the common trap is picking B (encryption and digital signature) instead of C (synchronization).
When systems are spread over multiple geographic sites, the CISA answer hinges on whether the log files themselves are synchronized to support event reconstruction. This page explains why option C is the best audit verification over encryption/signing or review location choices.
Choosing B for encryption and digital signature because it protects log integrity, while missing that geographically separated logs that are not synchronized cannot be converted into a meaningful chronological audit trail.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
With log sources placed in multiple geographic locations, the auditor's key task is to reconstruct a single, reliable timeline of events. Only synchronized logs establish a common frame of reference, because servers in different regions can introduce local time drift that distorts event order. From an ISACA audit-assurance perspective, if the auditor cannot verify sequencing across servers, incident discovery and forensic reconstruction are not trustworthy. Option C produces that foundational verification.
Why the Other Options Are Wrong
A is about procedural convenience rather than evidence assurance; reviewing log files in each location may complement the process but is not the core check. B is a legitimate control for confidentiality and tamper detection, but it protects individual files and does not assemble a unified timeline for geographically distributed events. D is premature and largely overlaps with C, while C more exactly captures the audit requirement for synchronized logs and timestamps. Thus C is the "most important" item for the auditor to verify.
Community Comment Notes
The community strongly favors option C, with commenters noting that multiple geographic areas make synchronization the essential foundation for security analysis. As blehbleh put it, "it doesn't matter if they are encrypted and digitally signed if it isn't synchronized." Another comment acknowledged that synchronization is important for consistency, and no comment demonstrated that digital signatures solve the multi-site time-ordering problem.
Exam Strategy
Treat the phrase "multiple geographic locations" as a direct reminder that distributed logs must share a consistent time base before any other control becomes meaningful. If one answer addresses time synchronization and another addresses cryptographic protection, prioritize the synchronization in this type of CISA scenario.
Frequently Asked Questions
Why is log synchronization more important than encryption in this CISA question?
Because logs from different geographic locations must share a consistent time basis for correlation; encryption and signatures protect integrity but not chronological order.
Could encrypted and digitally signed logs ever be enough without synchronization?
Only if timestamps were already proven consistent; otherwise signed logs from separate places cannot reliably prove event sequence or detect missing records.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →