hardMultiple Choice
CISA Practice Question: In a DevOps environment, which practice BEST…
In a DevOps environment, which practice BEST supports auditability?
⚠ Common exam trap
Many candidates confuse 'configuration management' (Option A) with 'change management' or 'audit logging,' assuming that tools like Chef or Terraform inherently provide auditability, when in fact they only track infrastructure state, not the full code change lifecycle including commits, approvals, and deployments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated logging of all code changes
Automated logging of all code changes (D) best supports auditability in a DevOps environment because it provides an immutable, timestamped record of every change made to the codebase, including who made the change, what was changed, and when. This aligns with the principle of continuous audit, where every deployment artifact is traceable through the CI/CD pipeline, enabling compliance with standards like SOC 2 or ISO 27001. Unlike manual processes, automated logging ensures no change goes unrecorded, which is critical for forensic analysis and regulatory audits.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use of configuration management tools
Why it's wrong here
Configuration management tools enforce and record desired state on hosts, yet they do not capture the full pipeline trail of who changed what, when and why across build and deploy stages. They would be correct for remediating server drift.
- ✗
Manual approval gates
Why it's wrong here
Manual approval gates insert human sign-off into pipelines, but the approvals themselves are not automatically recorded as immutable, traceable evidence of every change. They would be correct where regulatory control demands a person authorise production releases.
- ✗
Separate development and production environments
Why it's wrong here
Separating development and production environments limits blast radius and access, but isolation alone generates no auditable record of pipeline changes, approvals or deployments. It would be correct for containing test failures away from live workloads.
- ✓
Automated logging of all code changes
Why this is correct
Automated logging creates an immutable, timestamped record of every code change, directly satisfying the auditability constraint by enabling traceability of who changed what and when. Unlike manual processes, it captures the full change history continuously, providing auditors with verifiable evidence without relying on developer recollection or intervention.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.