Courseiva
mediumMultiple Choice

CAS-004 Practice Question: Is required to retain logs for seven years per…

An organization is required to retain logs for seven years per regulatory requirement. Which of the following should be considered to ensure the integrity of these logs?

⚠ Common exam trap

A common pitfall is confusing integrity (preventing unauthorized modification) with confidentiality (preventing unauthorized access), leading candidates to mistakenly choose encryption when the question specifically asks about integrity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Write-once, read-many (WORM) storage

Write-once, read-many (WORM) storage ensures that once log data is written, it cannot be altered, overwritten, or deleted for the retention period. This immutability directly satisfies the regulatory requirement for log integrity over seven years, as it prevents both accidental modification and malicious tampering. WORM can be implemented via optical media, magnetic tape with WORM firmware, or object storage with retention policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Write-once, read-many (WORM) storage

    Why this is correct

    WORM storage prevents modification or deletion of objects for a defined retention period, so logs cannot be altered or tampered with during the seven-year regulatory window. This directly satisfies the stem's integrity requirement, which standard mutable blob or file storage cannot guarantee.

  • ✗

    Hashing each log entry

    Why it's wrong here

    Hashing proves a log entry has not altered, but an attacker with write access can simply recompute the hash after tampering, so it fails to guarantee integrity against that threat. It is tempting because hashing is genuinely used for tamper detection in append-only or externally anchored stores.

  • ✗

    Encryption of the logs

    Why it's wrong here

    Encryption protects confidentiality, preventing unauthorised reading, but ciphertext can still be altered undetectably, so it does not establish integrity. Encryption is correct for protecting data at rest or in transit; integrity requires hashing, digital signatures or immutable WORM storage.

  • ✗

    Compression to reduce storage space

    Why it's wrong here

    Compression shrinks storage footprint but does not prove logs are unaltered, so it cannot satisfy integrity. Compression is appropriate for cutting storage cost or transfer time; integrity over seven years instead needs hashing, write-once storage or immutable retention controls.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.