An IS auditor concludes that logging and monitoring mechanisms within an organization are ineffective because central servers are not included within the central log repository. Which of the following audit procedures would have MOST likely identified this exception?
- Comparing all servers included in the current central log repository with the listing used for the prior-year audit
- Inspecting a sample of alerts generated from the central log repository
- Comparing a list of all servers from the directory server against a list of all servers present in the central log repository
- Inspecting a sample of alert settings configured in the central log repository
Reveal Solution Next Question