220-1102 Security Practice Question
A company has a data retention policy that requires all security logs to be retained for 90 days. A security incident occurred 60 days ago, but when the incident response team tries to retrieve logs from that period, they find that the logs have been overwritten due to insufficient storage capacity. Which security principle has been most directly compromised?
⚠ Common exam trap
It's easy for candidates to confuse 'data loss' with 'integrity failure,' but integrity is about unauthorized modification, not the inability to access data due to insufficient storage.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Availability
The security principle most directly compromised is availability, because the logs were overwritten and could not be accessed when needed for incident response. Availability ensures that data and systems are accessible to authorized users when required; here, insufficient storage capacity caused the logs to be destroyed before the 90-day retention period ended, making them unavailable for forensic analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Availability
Why this is correct
Availability requires that data remain accessible and usable whenever authorized users or processes need it. In this scenario, the security logs were overwritten due to the retention policy, making them unavailable during the incident investigation. Even though the overwriting was a legitimate policy action rather than a malicious one, the result was a direct violation of availability because the logs could not be accessed for their intended purpose.
- ✗
Integrity
Why it's wrong here
Integrity ensures data has not been tampered with. While overwriting logs could be seen as data loss, integrity typically refers to unauthorized modification. In this case, the logs were legitimately overwritten due to policy, not tampered with.
- ✗
Confidentiality
Why it's wrong here
Confidentiality focuses on preventing unauthorized disclosure or access to data. In this case, there is no indication that the logs were viewed, copied, or leaked to any unauthorized party; they were simply destroyed through routine retention. Therefore, the core security principle at stake is not confidentiality, as the data's secrecy was never compromised, only its existence over time.
- ✗
Non-repudiation
Why it's wrong here
Non-repudiation ensures that an individual cannot deny having performed an action, typically relying on audit logs or digital signatures. While the absence of these security logs would indeed hinder proving who did what during an incident, that is a downstream consequence rather than the fundamental failure. The direct violation is that the logs themselves were unavailable when needed, making availability the more accurate and immediate classification.
Go deeper
Related to this question
Learn chapter
MFA Types for Users
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Availability
Availability is the measure of how often a system or service is operational and accessible when needed, typically expressed as a percentage of uptime.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.