CISA Question of the Day: Time Synchronization for Log Integrity

CISA exam practice question — CISA Question of the Day: Time Synchronization for Log Integrity

CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Information Systems Operations and Business Resilience.

Question

During a review of incident evidence, an auditor finds that firewall, web server, and database logs show inconsistent timestamps, which hinders event correlation. Which control would most effectively ensure consistent, reliable timestamps across systems?

  • A. Configure all systems to use a centralized SIEM that normalizes timestamps to UTC during log ingestion
  • B. Enforce organization-wide NTP configuration that uses authenticated, authoritative time sources and monitor synchronization status
  • C. Implement application-level timestamp mapping rules to translate local times to a common time zone at analysis time
  • D. Require system administrators to manually verify and adjust system clocks weekly and retain adjustment records
Show the answer and explanation

Correct answer: B. Enforce organization-wide NTP configuration that uses authenticated, authoritative time sources and monitor synchronization status

The best control is enforcing organization-wide NTP with authenticated authoritative time sources and active monitoring. Proper time synchronization at the system level ensures original log entries carry accurate, consistent timestamps for reliable correlation and forensic analysis. A centralized SIEM that normalizes timestamps helps, but it relies on original timestamps being accurate; normalization cannot correct drift if source clocks are wrong. Application-level mapping adds complexity and the potential for translation errors during analysis. Manual weekly clock checks are labor-intensive, error-prone, and insufficient for detecting and preventing drift between verification intervals.

Want more practice?

Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.