Primary Reason for Daily Network Admin Management Reviews?
What is the PRIMARY reason an IS auditor would recommend an automated management review process for network administration activity on a daily basis instead of quarterly?
Community Votes
67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests whether auditors confuse real-time technical controls with supervisory management reviews, with the common trap being selecting intrusion detection over change verification.
This question tests the distinction between technical intrusion detection and supervisory management reviews in network security auditing. It establishes that frequent automated management reviews are primarily implemented to promptly identify and validate system configuration changes.
Many candidates choose D because intrusion detection seems critical, but it overlooks that management reviews are administrative oversight tools focused on tracking configuration changes rather than real-time threat hunting.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A management review is a supervisory control designed to verify that operational processes comply with policies and standards. For network administration, configurations and access rules change frequently, making daily automated reviews essential to promptly identify system changes before they introduce vulnerabilities or compliance gaps. ISACA emphasizes that management reviews focus on validating authorized modifications and detecting configuration drift, which aligns directly with identifying system changes.Why the Other Options Are Wrong
Option B addresses transactional systems rather than network infrastructure. Option C relates to authentication logging, which is typically handled by automated security information and event management (SIEM) alerts rather than periodic management oversight. Option D describes a function of technical controls like IDS/IPS, which operate in real-time; management reviews are retrospective supervisory activities, not active intrusion detection mechanisms.Community Comment Notes
As PurpleParrot noted, 'network activity monitoring is more about network activities', while others emphasized that daily reviews ensure changes are monitored closely to maintain network integrity. Several learners initially favored intrusion detection due to its high profile in security discussions, but the consensus correctly shifted toward recognizing that supervisory reviews target change validation over real-time threat response.Exam Strategy
When answering audit frequency questions, always match the control type to its purpose: technical controls handle real-time threats, while management reviews verify ongoing compliance and track changes. Prioritize options that align with the specific control mechanism described in the scenario.
Frequently Asked Questions
Why isn't detecting network intrusions the primary reason?
Intrusion detection relies on real-time technical controls like IDS/IPS. Management reviews are supervisory audits focused on verifying changes and compliance, not live threat hunting.
How does daily frequency improve audit effectiveness?
Network configurations change rapidly. Daily reviews catch unauthorized or erroneous modifications quickly, preventing configuration drift and reducing the window of exposure compared to quarterly checks.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →