Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A company has a data retention policy that requires all security logs to be retained for 90 days. A security incident occurred 60 days ago, but when the incident response team tries to retrieve logs from that period, they find that the logs have been overwritten due to insufficient storage capacity. Which security principle has been most directly compromised?

⚠ Common exam trap

It's easy for candidates to confuse 'data loss' with 'integrity failure,' but integrity is about unauthorized modification, not the inability to access data due to insufficient storage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Availability

The security principle most directly compromised is availability, because the logs were overwritten and could not be accessed when needed for incident response. Availability ensures that data and systems are accessible to authorized users when required; here, insufficient storage capacity caused the logs to be destroyed before the 90-day retention period ended, making them unavailable for forensic analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Availability

    Why this is correct

    Availability requires that data remain accessible and usable whenever authorized users or processes need it. In this scenario, the security logs were overwritten due to the retention policy, making them unavailable during the incident investigation. Even though the overwriting was a legitimate policy action rather than a malicious one, the result was a direct violation of availability because the logs could not be accessed for their intended purpose.

  • ✗

    Integrity

    Why it's wrong here

    Integrity ensures data has not been tampered with. While overwriting logs could be seen as data loss, integrity typically refers to unauthorized modification. In this case, the logs were legitimately overwritten due to policy, not tampered with.

  • ✗

    Confidentiality

    Why it's wrong here

    Confidentiality focuses on preventing unauthorized disclosure or access to data. In this case, there is no indication that the logs were viewed, copied, or leaked to any unauthorized party; they were simply destroyed through routine retention. Therefore, the core security principle at stake is not confidentiality, as the data's secrecy was never compromised, only its existence over time.

  • ✗

    Non-repudiation

    Why it's wrong here

    Non-repudiation ensures that an individual cannot deny having performed an action, typically relying on audit logs or digital signatures. While the absence of these security logs would indeed hinder proving who did what during an incident, that is a downstream consequence rather than the fundamental failure. The direct violation is that the logs themselves were unavailable when needed, making availability the more accurate and immediate classification.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.