hardMultiple Choice
200-201 Practice Question: Must retain security logs for at least one year…
An organization must retain security logs for at least one year due to regulatory compliance. However, their SIEM storage is limited. Which strategy best balances compliance and storage?
⚠ Common exam trap
200-201 often tests the trade-off between compliance and storage, tempting candidates to choose deletion or only alerts, which fail regulatory requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Archive logs to compressed files after 30 days and retain for one year.
Archiving logs to compressed files after 30 days and retaining them for one year balances compliance (one-year retention) with limited SIEM storage. This approach moves older logs to cheaper, compressed storage while keeping them accessible for audits. It reduces the active SIEM storage footprint without violating the retention requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Archive logs to compressed files after 30 days and retain for one year.
Why this is correct
Archiving logs to compressed files after 30 days satisfies the one-year regulatory retention requirement while freeing SIEM capacity, since compression reduces the storage footprint of aged data that is rarely queried. The SIEM retains recent logs for active correlation and hunting, and archived files remain retrievable for compliance audits or investigations.
- ✗
Delete logs after 30 days and rely on local log rotation.
Why it's wrong here
Deleting logs after 30 days breaches the one-year retention requirement, and local rotation offers no compliant central archive. It tempts because it frees SIEM capacity cheaply, but it fits only organisations with no mandated retention period, where short-term operational visibility outweighs long-term evidentiary needs.
- ✗
Only store alerts and drop raw logs.
Why it's wrong here
Discarding raw logs destroys the evidentiary record regulators require, so retention obligations go unmet even though alerts persist. It tempts because alerts are compact and searchable, but this strategy suits environments needing only triage signals, not one where the raw log itself must be preserved for a year.
- ✗
Increase SIEM storage without archiving.
Why it's wrong here
Retaining everything on primary SIEM storage indefinitely inflates cost and will not scale to a year of compliance data, whereas tiered archiving preserves the logs cheaply for the mandated period. Increasing raw storage suits short-term high-speed search needs, not long-term regulatory retention.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.