Courseiva
hardMultiple ChoiceObjective-mapped

CRISC Practice Question: A multinational corporation has deployed a…

A multinational corporation has deployed a centralized log management system that collects security events from all subsidiaries. The CRO notices that the number of critical alerts from the Asia-Pacific region has dropped significantly over the past week. Upon investigation, the log source status shows that 30% of the devices in that region have not sent any logs in 48 hours. What is the MOST likely cause?

⚠ Common exam trap

Watch out — candidates often confuse a reduction in alerts (Option A) with a loss of raw logs, or assume a network change (Option D) is the root cause without considering that a configuration change to the log forwarder agent is a more targeted and common failure mode in centralized logging architectures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A configuration change was made to the log forwarder agent on the affected devices, causing it to stop sending logs.

A configuration change to the log forwarder agent (e.g., syslog-ng, rsyslog, or a proprietary agent) is the most plausible cause for a sudden, sustained drop in log volume from a subset of devices. Unlike network segmentation (Option D), which would affect all traffic, or a DDoS (Option B), which would cause intermittent or total loss, an agent misconfiguration selectively stops log generation while the device remains online. The 48-hour window and 30% device impact align with a staged or partial rollout of a faulty agent configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The security team applied a new log suppression rule that filters out low-severity events.

    Why it's wrong here

    Suppression would reduce alert volume but not stop log generation entirely.

  • The region experienced a distributed denial-of-service (DDoS) attack that overwhelmed the log collection infrastructure.

    Why it's wrong here

    A DDoS attack would likely cause an increase in alerts, not a drop.

  • A configuration change was made to the log forwarder agent on the affected devices, causing it to stop sending logs.

    Why this is correct

    Misconfigured log forwarders are a common cause of log loss.

  • The network team recently implemented a segmentation change that blocked log traffic from those devices.

    Why it's wrong here

    Network changes are usually documented and would affect more than just log transmission.

About these practice questions

One of 983 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.