easyMultiple Choice
200-201 Practice Question: A company's security policy requires that all…
A company's security policy requires that all system logs be retained for at least one year. A security analyst discovers that log files are being overwritten after 30 days. What is the most likely cause?
⚠ Common exam trap
200-201 often tests the confusion between symptom and root cause, tempting candidates to blame malware or disk space when the consistent, policy-matching 30-day overwrite clearly points to a misconfigured rotation setting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The log rotation policy is set to 30 days
Log files being overwritten after exactly 30 days is the classic signature of a log rotation policy configured with a 30-day retention window. Rotation tools such as logrotate, Windows Event Log auto-archive, or SIEM retention settings delete or overwrite the oldest data once the configured age or size threshold is reached. The fix is to adjust the rotation/retention configuration to meet the one-year policy requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Logs are being manually deleted by an administrator
Why it's wrong here
Manual deletion would remove log files entirely rather than overwrite them on a fixed 30-day cycle. Administrator deletion is the right answer when specific files vanish or retention is deliberately shortened, not when automatic rotation truncates them.
- ✗
Malware infection
Why it's wrong here
Malware can delete or tamper with logs, but it would not reliably overwrite them at a consistent 30-day interval. Malware is the correct answer when logs show gaps, altered entries or exfiltration rather than predictable rotation behaviour.
- ✓
The log rotation policy is set to 30 days
Why this is correct
Log rotation controls retention by archiving or deleting files once a threshold is reached. A 30-day rotation setting directly causes overwriting after 30 days, contradicting the one-year retention requirement. Adjusting this policy, not storage capacity, is the actual cause.
- ✗
Insufficient disk space
Why it's wrong here
Disk exhaustion causes write failures, service crashes or dropped events, not orderly 30-day rotation. Insufficient space is the correct diagnosis when logging stops entirely or the volume fills, whereas a configured retention or rotation policy produces the observed predictable overwrite.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.