Correct Answer: D
The correct answer is D. Completeness testing has not been performed on the log data.
For an event log aggregation system, the auditor must first be concerned with whether the log data is complete. If completeness testing has not been performed, the organization may not know whether all required logs are being collected, whether sources are missing, whether log feeds are interrupted, or whether critical events are excluded. Incomplete log data weakens monitoring, investigation, incident response, and risk management.
Option A is a concern because non-normalized logs can make correlation and analysis more difficult.
However, incomplete logs are a more fundamental problem because missing data cannot be analyzed at all.
Option B may be acceptable if batch uploads meet monitoring and investigation requirements. Option C is not the best answer because DES is an outdated encryption standard, but the question is mainly about whether the aggregated log data is complete and reliable for risk management.
This maps to Information Systems Operations and Business Resilience because ISACA's CISA Exam Content Outline includes operational log management, incident/problem management, and IT operations under Domain 4.
References: ISACA CISA Exam Content Outline, Domain 4; ISACA Interactive Glossary, audit evidence and control concepts.