CISA Domain 4A-9 Practice Test 001

This practice test covers Domain 4 (Information Systems Operations & Business Resilience) Subdomain A-9 (Operational Log Management) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 4A-9 Operational Log Management Practice Test 001
10 questions • Single best answer
Question 1
An IS auditor reviewing centralized logging at a cloud-based SaaS provider finds that application, database, and network logs are collected but retained for only seven days, with no documented policy defining required retention periods. Given potential legal and investigative needs, which finding is MOST significant?
    Question 2
    During an audit of a hospital's electronic health record system, the IS auditor is informed by a system administrator that privileged administrator activity is not logged, although clinician access is fully captured. Before drawing conclusions about the log management program, what should the IS auditor do FIRST?
      Question 3
      A government agency's security operations team stores all system logs in a central repository where system administrators have full read and write access to the stored log files. No integrity controls or write-once storage are in place. Which risk is MOST significant to the reliability of the logs?
        Question 4
        During an audit of a manufacturing firm's ERP environment, the IS auditor finds that logs are generated and retained appropriately, but no one reviews them and no automated alerting is configured. Management asserts the logs provide an adequate detective control. Which conclusion is MOST appropriate?
          Question 5
          An IS auditor at an insurance company wants to determine whether security-relevant events on a critical database, such as failed logins and privilege changes, are actually being captured by the log management system, rather than merely configured to be captured. Which approach would provide the BEST evidence?
            Question 6
            A cloud migration review reveals that log timestamps across various systems are inconsistent because the servers are not synchronized to a common, authoritative time source. During a later incident investigation, analysts could not reliably correlate events across the affected systems. Which recommendation is MOST appropriate?
              Question 7
              During a review of a telecommunications provider's logging environment, the IS auditor notes that logging levels were reduced to errors-only on several production servers to save storage space, and the security operations team was not consulted about the configuration change. Which finding is MOST significant?
                Question 8
                An IS auditor has identified that a retailer's log management program lacks defined review responsibilities and retention standards. Several stakeholders dispute the severity of the findings during the closing meeting, arguing that residual risk is low. What is the IS auditor's BEST course of action?
                  Question 9
                  An organization forwards logs from thousands of endpoints and servers to a centralized SIEM platform. The IS auditor wants assurance that log records are not silently lost in transit or dropped before reaching the SIEM for analysis. Which control provides the BEST assurance of complete collection?
                    Question 10
                    An IS auditor is evaluating whether an energy utility's log management program captures all privileged administrator actions in production. To conclude on completeness, the auditor needs to verify that every actual privileged change is reflected in the log records. Which testing approach is MOST appropriate?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top