CISA - Information Systems Operations and Business Resilience (26% of the exam) - Section 4.1

Assess operational log management, IT service level management and database management.

Understand the purpose of operational log management in capturing system events for monitoring, troubleshooting and audit trail integrity. Assess IT service level management - including SLA compliance - and database management controls to confirm that data is accessible, accurate and protected.

operational log managementservice level managementSLAdatabase management

Practice question for this objective

Free sampleInformation Systems Operations and Business Resiliencemedium

An IS auditor is reviewing the operational log management programme of a payments processor. Which characteristic of log records is MOST important for them to be useful as audit evidence in an investigation?

  • AThe logs are written in a human readable text format so that responders can open them in any editor without specialist tooling.
  • BThe logs are sampled monthly by the security team and the sampled records are summarised in a management dashboard for the chief information security officer.
  • CThe logs are protected against unauthorised modification and supported by demonstrable controls over their creation, transmission and retention. Correct
  • DThe logs are stored on the same server that generates the events so that timing differences between systems do not distort the recorded sequence.
Recognise that protected integrity across the log lifecycle, not format or volume, is what makes operational logs reliable audit evidence. Logs become reliable evidence only when the auditor can demonstrate that the records have not been altered between generation and review. Controls over generation, secure transmission, write once or hash protected storage and retention enforcement together establish that chain, which is why integrity is the dominant attribute.

Why A is wrong: Human readability is convenient for responders but does not by itself preserve evidential value, because plain text files can be modified silently after the fact.

Why B is wrong: Sampling and dashboards aid monitoring but the surviving records are still only as reliable as their source, so sampling alone does not raise evidential quality.

Why C is correct: Integrity over the full lifecycle is what allows a log to be relied upon as audit evidence, because the auditor must show the record reflects the original event.

Why D is wrong: Local storage actually weakens reliability because a compromised host can rewrite its own logs, which is why central, write protected collection is preferred.

See more CISA practice questions, answers explained.

Exam traps in Information Systems Operations and Business Resilience

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISA bank for this domain.

  • A service level agreement is signed at executive level and an operational level agreement is signed by the technical teams, but both are external commitments to the customer of the service.

    Why it is wrong: Seniority of the signatory is not the distinction, and operational level agreements are internal arrangements rather than external customer commitments.

  • Atomicity ensures that once a transaction has been committed its effects survive any subsequent system failure or restart of the database engine.

    Why it is wrong: This describes durability rather than atomicity, which is a common confusion because both properties relate to the persistence of committed work.

  • Storage capacity on the central log server may be exhausted earlier than planned because of duplicate event timestamps.

    Why it is wrong: Duplicate timestamps are an unlikely consequence of time drift and the resulting storage impact would be minor compared with the implications for evidentiary quality.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.