Which of the following is a primary auditing activity?
Correct answer: Checking log files
Checking log files is the primary auditing activity as it involves systematically reviewing system, application, and security logs to identify unauthorized access attempts, policy violations, and security incidents. Auditing focuses on monitoring and analyzing what has already occurred rather than preventing future events. Encrypting data files is a data protection control, changing login accounts is an access management task, and configuring firewalls is a preventive security control - none of these constitute the core auditing function of reviewing and analyzing logged events for security assessment and compliance purposes.