
CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Information Systems Operations and Business Resilience.
Question
During a review of incident evidence, an auditor finds that firewall, web server, and database logs show inconsistent timestamps, which hinders event correlation. Which control would most effectively ensure consistent, reliable timestamps across systems?
Show the answer and explanation
Correct answer: B. Enforce organization-wide NTP configuration that uses authenticated, authoritative time sources and monitor synchronization status
The best control is enforcing organization-wide NTP with authenticated authoritative time sources and active monitoring. Proper time synchronization at the system level ensures original log entries carry accurate, consistent timestamps for reliable correlation and forensic analysis. A centralized SIEM that normalizes timestamps helps, but it relies on original timestamps being accurate; normalization cannot correct drift if source clocks are wrong. Application-level mapping adds complexity and the potential for translation errors during analysis. Manual weekly clock checks are labor-intensive, error-prone, and insufficient for detecting and preventing drift between verification intervals.
Want more practice?
Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.
