Courseiva
mediumMultiple Choice

CISA Practice Question: During an audit, the IS auditor discovers that…

During an audit, the IS auditor discovers that the audit log for a critical server is overwritten every 24 hours. The auditor wants to ensure logs are preserved for a longer period. Which of the following recommendations is most appropriate?

⚠ Common exam trap

Many exam-takers choose Option C (increase log size) thinking it solves the retention issue, but they overlook that it only postpones the overwrite rather than providing a permanent, auditable archive, which is the core requirement for compliance and forensic readiness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the server to archive logs to a centralized log management system

The most appropriate recommendation is to configure the server to archive logs to a centralized log management system. This ensures logs are preserved beyond the 24-hour overwrite window by sending them to a separate, persistent storage location, which also supports security monitoring, forensics, and compliance requirements. Centralized logging (e.g., using syslog, SIEM, or a dedicated log collector) provides redundancy, integrity checks, and long-term retention without relying on the local server's limited storage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement a manual backup of logs daily

    Why it's wrong here

    Manual daily backups depend on an operator remembering to run them, so logs can still be overwritten before capture and the process is unauditable. It is tempting because it copies logs off the server, and would be correct where no automated tooling exists and volumes are tiny.

  • ✗

    Reduce the logging level to minimize data

    Why it's wrong here

    Lowering the logging level discards detail and shortens retention rather than extending it, weakening the audit trail the auditor wants preserved. It is tempting because it reduces the volume overwriting the file, and would be correct if storage were the constraint and full detail were unnecessary.

  • ✗

    Increase the log size to retain more data

    Why it's wrong here

    Enlarging the log file only delays overwriting within the same 24-hour rotation cycle; the retention period itself is unchanged. It is tempting because size feels like capacity, but the fix is to extend retention or forward logs to a centralised, tamper-evident log server.

  • ✓

    Configure the server to archive logs to a centralized log management system

    Why this is correct

    Forwarding logs to a centralised log management system preserves them beyond the server's 24-hour overwrite cycle, and typically enforces retention and access controls. Local archiving on the same server would still be vulnerable to the same overwrite and tampering risks.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.