Missing Access Logs in Secure Communication Closets

Physical Security Auditing
Answer Correct answer: A — Verify whether video cameras cover the entrances to establish a compensating control for the missing electronic access logs.

An IS auditor finds that communication closets requiring electronic swipe card access are missing access logs. Which of the following should be done NEXT?

  1. Determine whether there are video cameras covering the entrances. Correct Answer
  2. Determine whether management approved the access policy.
  3. Determine whether anything is missing from the closets.
  4. Determine whether any access swipe cards have been lost or stolen.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests knowledge of compensating controls in physical security audits, where candidates often mistakenly investigate incidents or report deficiencies instead of checking for alternative monitoring mechanisms.

This CISA practice question addresses how auditors handle missing physical access logs in secure areas. The explanation confirms that verifying compensating controls like video surveillance is the correct next step.

Option D is frequently chosen because auditors instinctively look for potential breaches (lost/stolen cards), but ISACA prioritizes evaluating existing compensating controls before initiating incident-specific investigations.

Community Discussion (4 comments)

46080f2 👍 1 Selected: A
The absence of access logs for communication closets violates physical access control requirements outlined in the CISA Study Guide (Chapter 8), which emphasizes that "access logs are critical for monitoring and auditing entry to secure areas" [Study Guide, Auditing Physical Access]. Without logs, accountability for unauthorized entry or incidents is compromised. Compensating Controls: The CISA Review Manual (Chapter 5) states: "If electronic access logs are unavailable, auditors should evaluate compensating controls such as video surveillance to validate physical access accountability" [Review Manual, Physical Access Controls].
RS66 👍 1 Selected: A
I will go with A. The cameras are the only way to determine if unauthorized personnel accessed the closets. On the other hand, if you find out a card was stolen, then what? The logs are missing and you can't check if the missing cards were used. You will then need the cameras again.
Binagr8 👍 1
D. Identifying lost or stolen cards helps assess the severity of the situation. If cards are unaccounted for, it suggests a higher risk of unauthorized access and potential theft of equipment or data. Once the auditor determines the status of the swipe cards, they can then consider additional steps like reviewing video footage (option A) or investigating missing equipment (option C).
Swallows 👍 1 Selected: A
Video cameras covering the entrances can provide visual records of individuals entering and exiting these areas. If access logs are missing or incomplete, video footage can serve as an alternative or supplementary method to monitor who has accessed the closets.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

When an IS auditor identifies a missing primary control like electronic access logs, the immediate next step is to evaluate compensating controls. Video surveillance serves as a recognized alternative mechanism to monitor and record entry into secure areas, ensuring accountability continues despite the logging gap. ISACA’s audit framework prioritizes verifying existing mitigation measures before escalating findings or initiating reactive investigations.

Why the Other Options Are Wrong

Investigating lost or stolen cards (Option D) assumes a breach has already occurred, which jumps ahead of the standard audit procedure of assessing current control effectiveness. Checking for missing equipment (Option C) is also a reactive incident response rather than a systematic control evaluation. Determining management policy approval (Option B) addresses governance compliance but does not resolve the immediate operational monitoring deficit identified during testing.

Community Comment Notes

Several learners correctly identified video surveillance as the logical compensating measure, noting that without logs, visual records become essential for tracking unauthorized entries. As RS66 noted, "cameras are the only way to determine if unauthorized personnel accessed the closets." This aligns with ISACA’s emphasis on verifying alternative monitoring mechanisms first. Another participant initially favored assessing stolen cards but later recognized that evaluating the compensating control takes precedence in the audit workflow. The consensus firmly supports Option A as the standard procedural response.

Exam Strategy

Always follow the audit sequence: identify the control gap, verify compensating controls, then assess impact. Jumping straight to incident checks or policy reviews bypasses ISACA’s required risk evaluation steps and leads to incorrect sequencing answers.

Frequently Asked Questions

Why not investigate lost or stolen cards first?

Audit methodology requires evaluating compensating controls before launching incident-specific investigations.

Is checking management approval the right next step?

Policy approval is a governance matter; the immediate priority is assessing operational monitoring gaps to determine residual risk.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide