200-201 Security Policies and Procedures Practice Question
A financial services firm must retain security audit logs for a period specified by its regulator and be able to produce them during an examination. Which action BEST ensures the logs remain trustworthy and available for that purpose?
⚠ Common exam trap
The trap here is equating longer local retention with trustworthy retention, when integrity and centralized control are what actually satisfy an examiner.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Forward logs to a centralized, access-controlled repository with integrity protection
Centralizing logs in an access-controlled repository with integrity protections ensures they survive host compromise or failure and can be trusted during a regulatory examination. Retention enforcement and restricted access are as important as collection, because examiners expect complete, unaltered records that can be produced on demand.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Forward logs to a centralized, access-controlled repository with integrity protection
Why this is correct
Centralizing logs on a hardened server with restricted access, combined with integrity measures such as hashing or write-once storage, preserves both trustworthiness and availability. If the source host is compromised or destroyed, the copies remain intact for examination. This design also supports retention policies and search during audits, directly meeting the regulator's expectation that records can be produced reliably.
- ✗
Increase the local log file size limit so events are overwritten less frequently
Why it's wrong here
Enlarging local log files only postpones overwriting and does nothing to protect records from tampering, theft, or disk failure. It also leaves logs scattered across hosts, making production during an examination slow and error-prone. Retention duration and integrity are the regulatory concerns, and neither is addressed by tuning a file size parameter on the originating system.
- ✗
Compress logs and email them weekly to the security team's distribution list
Why it's wrong here
Emailing compressed archives creates uncontrolled copies in mailboxes and backups, with no guaranteed retention or integrity. Recipients can modify or delete attachments, and the distribution list may include people without a need to know. There is no chain of custody or tamper evidence, so the firm could not demonstrate to an examiner that the records are authentic and complete.
- ✗
Store logs only on the originating server with local administrator access
Why it's wrong here
Keeping logs solely on the source system means an attacker who compromises that host can alter or delete them, and a disk failure destroys the record entirely. Local administrator access also lets insiders tamper with evidence. For regulatory examination, logs must be resistant to modification and survive host loss, so this approach fails both the integrity and availability requirements that the scenario demands.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.