Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27001-Lead-Auditor Exam - Topic 4 Question 71 Discussion

To verify conformity to control 8.15 Logging of ISO/IEC 27001 Annex A, the audit team studied a sample of server logs to determine if they could be edited or deleted. Which audit procedure did the audit team use?
B) Technical verification
A) Analysis
C) Observation

PECB ISO-IEC-27001-Lead-Auditor Exam - Topic 4 Question 71 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Auditor exam
Question #: 71
Topic #: 4
[All ISO-IEC-27001-Lead-Auditor Questions]

To verify conformity to control 8.15 Logging of ISO/IEC 27001 Annex A, the audit team studied a sample of server logs to determine if they could be edited or deleted. Which audit procedure did the audit team use?

Show Suggested Answer Hide Answer
Suggested Answer: B

The audit team used technical verification, making option B the correct answer. Technical verification involves examining technical configurations, system settings, or operational characteristics of information systems to verify whether controls are implemented and effective. In this scenario, the auditors examined server logs to determine whether they could be altered or deleted, which directly assesses the technical enforcement of logging controls.

ISO/IEC 27002:2022 control 8.15 requires organizations to ensure that logs are protected against unauthorized modification or deletion. Verifying this requirement cannot be achieved through interviews or documentation alone; it requires direct interaction with or inspection of the technical system.

Option A is incorrect because analysis refers to evaluating information, patterns, or results after evidence has been collected, not to the act of examining system configurations. Option C is incorrect because observation involves watching activities or processes being performed, such as monitoring staff behavior or physical security practices, not inspecting system-level controls.

Therefore, reviewing server logs for editability or deletion capability is a clear example of technical verification, which is an appropriate and necessary audit procedure for technological controls.


Contribute your Thoughts:

0/2000 characters
I recall that technical verification is often used for ensuring data hasn't been tampered with, so that might be the right choice here.
upvoted 0 times
...
Phung
5 days ago
Observation seems like it could be relevant too, but I feel like it’s more about watching processes rather than checking logs directly.
upvoted 0 times
...
Troy
10 days ago
I'm not entirely sure, but I remember a practice question where we discussed analysis in relation to log reviews.
upvoted 0 times
...
Antonio
15 days ago
I think the audit team might have used technical verification since it involves checking the integrity of logs.
upvoted 0 times
...

Save Cancel