CAS-004 Security Engineering Practice Question
A security engineer must ensure that log data collected from production servers cannot be altered or deleted by an attacker who gains administrative access to those servers. The logs must remain verifiable for audit purposes. Which of the following designs BEST achieves this?
⚠ Common exam trap
The trap here is relying on local file permissions or encryption on the source host, when an attacker with administrative rights on that host controls the keys and the files.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Forward logs in real time to a centralized server that uses append-only storage and cryptographic hash chaining.
Sending logs off-host in real time and storing them on a separate system with append-only writes and hash chaining ensures that a compromised server cannot retroactively change the audit record. The chained hashes let auditors detect any insertion, deletion, or modification, so the logs remain trustworthy even if the source host is fully compromised.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure log rotation with a short retention window and compress older files to save space.
Why it's wrong here
Rotation and compression manage storage but do not protect integrity or availability. Short retention actually destroys evidence sooner, and compressed archives on the same host can be deleted or rewritten by an administrator. This approach makes the audit problem worse rather than providing tamper resistance.
- ✗
Encrypt log files at rest on each server using a key stored in the server's local keystore.
Why it's wrong here
Encryption at rest protects confidentiality if disks are stolen, but a host administrator can use the local key to decrypt, modify, and re-encrypt the files. There is no external anchor to detect the change, and the attacker can simply delete the ciphertext. This design does not prevent alteration by someone with administrative access to the server.
- ✓
Forward logs in real time to a centralized server that uses append-only storage and cryptographic hash chaining.
Why this is correct
Real-time forwarding removes logs from the source host before an attacker can tamper with them, and append-only storage with hash chaining makes any later modification detectable because each entry's hash depends on the previous one. An attacker with server administrative rights cannot rewrite records already transmitted to the hardened collector. This directly provides tamper evidence and verifiability.
- ✗
Store logs locally on each server with strict file permissions and enable file integrity monitoring.
Why it's wrong here
Local storage keeps the logs on the same host an attacker controls, so administrative access allows deletion or alteration regardless of file permissions. File integrity monitoring may detect changes, but only after the fact, and the attacker can also disable the monitoring agent. The logs are neither preserved nor reliably verifiable under the stated threat.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.