Courseiva
easyMultiple Choice

200-201 Practice Question: A company's security policy requires that all…

A company's security policy requires that all system logs be retained for at least one year. A security analyst discovers that log files are being overwritten after 30 days. What is the most likely cause?

⚠ Common exam trap

200-201 often tests the confusion between symptom and root cause, tempting candidates to blame malware or disk space when the consistent, policy-matching 30-day overwrite clearly points to a misconfigured rotation setting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The log rotation policy is set to 30 days

Log files being overwritten after exactly 30 days is the classic signature of a log rotation policy configured with a 30-day retention window. Rotation tools such as logrotate, Windows Event Log auto-archive, or SIEM retention settings delete or overwrite the oldest data once the configured age or size threshold is reached. The fix is to adjust the rotation/retention configuration to meet the one-year policy requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Logs are being manually deleted by an administrator

    Why it's wrong here

    Manual deletion would remove log files entirely rather than overwrite them on a fixed 30-day cycle. Administrator deletion is the right answer when specific files vanish or retention is deliberately shortened, not when automatic rotation truncates them.

  • ✗

    Malware infection

    Why it's wrong here

    Malware can delete or tamper with logs, but it would not reliably overwrite them at a consistent 30-day interval. Malware is the correct answer when logs show gaps, altered entries or exfiltration rather than predictable rotation behaviour.

  • ✓

    The log rotation policy is set to 30 days

    Why this is correct

    Log rotation controls retention by archiving or deleting files once a threshold is reached. A 30-day rotation setting directly causes overwriting after 30 days, contradicting the one-year retention requirement. Adjusting this policy, not storage capacity, is the actual cause.

  • ✗

    Insufficient disk space

    Why it's wrong here

    Disk exhaustion causes write failures, service crashes or dropped events, not orderly 30-day rotation. Insufficient space is the correct diagnosis when logging stops entirely or the volume fills, whereas a configured retention or rotation policy produces the observed predictable overwrite.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.