Which items must be logged regarding the lifecycle of audit logs?

Prepare for the PCI DSS Test with detailed questions and explanations. Use flashcards and quizzes to enhance knowledge. Ensure you're ready for your certification exam!

Multiple Choice

Which items must be logged regarding the lifecycle of audit logs?

Explanation:
Auditing must capture changes to the logging process itself to maintain a trustworthy record. If logging starts, you establish a baseline of what will be collected; if logging is stopped or paused, events occurring during that period could be missed unless that change is logged. Recording both the initialization and any stopping or pausing of audit logs creates a complete timeline of when logging was active, helps detect gaps or tampering, and supports forensics and compliance. The other options only cover partial aspects and miss either the start or the pause state, so they don’t provide the full, auditable picture of the logging lifecycle.

Auditing must capture changes to the logging process itself to maintain a trustworthy record. If logging starts, you establish a baseline of what will be collected; if logging is stopped or paused, events occurring during that period could be missed unless that change is logged. Recording both the initialization and any stopping or pausing of audit logs creates a complete timeline of when logging was active, helps detect gaps or tampering, and supports forensics and compliance. The other options only cover partial aspects and miss either the start or the pause state, so they don’t provide the full, auditable picture of the logging lifecycle.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy