Courseiva

200-201 Security Policies and Procedures Practice Question

A financial services company must retain security event logs for a period defined by its policy and applicable regulations. The security architect is documenting how long different log sources must be kept and where. Which statement best reflects a sound log retention practice for security operations?

⚠ Common exam trap

The trap here is equating storage savings with good retention practice, leading to keeping only alerts or deleting logs too quickly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Define retention periods per log source based on regulatory and business requirements, and store logs centrally with integrity protection.

Effective log retention ties each source to a defined period justified by regulation and business need, then centralizes storage with integrity protection so logs remain available and trustworthy. Indefinite retention on source systems, extremely short deletion windows, or keeping only correlated alerts all undermine investigations and compliance. The chosen approach supports both retrospective hunting and evidentiary requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Retain only logs that the SIEM has already correlated into alerts, discarding raw events to save space.

    Why it's wrong here

    Raw events are essential because correlation rules change and investigations often require reconstructing timelines from unfiltered data. Discarding raw logs means an alert can never be re-examined with new context, and missed detections cannot be retroactively discovered. Alert-only retention also hampers forensic analysis of scope and lateral movement. Saving space is better achieved through tiered storage and compression while preserving raw events for the required period.

  • ✗

    Delete logs after 24 hours to reduce the risk of exposing sensitive information in the event of a breach.

    Why it's wrong here

    A 24-hour retention window is far too short for security operations; many intrusions are discovered weeks or months after initial access, and investigations require historical data to reconstruct attacker activity. Deleting logs quickly also destroys evidence needed for regulatory reporting and legal proceedings. While minimizing retained sensitive data is a valid concern, the correct control is to protect logs, not to delete them before they can be useful.

  • ✓

    Define retention periods per log source based on regulatory and business requirements, and store logs centrally with integrity protection.

    Why this is correct

    Sound practice is to map each log source to a retention period derived from legal, regulatory, and investigative needs, then centralize storage so logs survive host rebuilds. Central storage with integrity protection, such as write-once or hashed archives, preserves evidentiary value. This approach balances cost with the ability to investigate incidents that may be discovered months after initial activity, and it supports audits by documenting the rationale for each period.

  • ✗

    Retain all logs indefinitely on the source system to guarantee availability for any future investigation.

    Why it's wrong here

    Keeping all logs forever on the source system consumes storage, degrades performance, and complicates backup and search. It also conflicts with data minimization principles and can increase legal exposure by retaining sensitive data longer than needed. Source systems are also poor long-term archives because they can be rebuilt or wiped during recovery, destroying evidence. This practice is neither sound nor aligned with typical retention policies.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.