Courseiva
easyMultiple Select

CS0-003 Practice Question: Which TWO of the following are best practices for…

Which TWO of the following are best practices for secure log management? (Choose TWO)

⚠ Common exam trap

CompTIA often tests the misconception that 'common log format' is a security best practice, but it is actually an operational convenience; the trap is confusing operational efficiency with security controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable log encryption in transit and at rest

Encrypting logs in transit (e.g., using TLS/SSL for syslog over TCP 6514) and at rest (e.g., AES-256 encryption on the storage volume) ensures confidentiality and integrity, preventing unauthorized access or tampering. This aligns with security frameworks like NIST SP 800-92 and PCI DSS requirements for protecting log data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable log encryption in transit and at rest

    Why this is correct

    Encrypting logs in transit, typically with syslog over TLS, prevents an attacker on the network path from intercepting or tampering with events as they move to the collector, while encryption at rest protects stored log archives from unauthorized read access if the storage media or backup is stolen, together preserving both confidentiality and evidentiary integrity for later forensic use.

  • ✓

    Implement log aggregation from multiple sources

    Why this is correct

    Aggregating logs from firewalls, servers, and endpoints into a centralized SIEM enables cross-source correlation that reveals attack patterns invisible in any single log stream, and because logs are forwarded off the originating host in near real time, an attacker who later compromises and wipes that host's local logs cannot erase the copy already captured on the hardened collector.

  • ✗

    Disable logging on non-critical systems to save space

    Why it's wrong here

    Disabling logging on systems labeled non-critical to save storage directly creates blind spots, since attackers routinely pivot through lower-priority or forgotten systems specifically because they are under-monitored, and the resulting lack of audit trail can prevent an incident responder from reconstructing the full attack timeline during a later investigation.

  • ✗

    Store logs on the same server for easy access

    Why it's wrong here

    Keeping logs only on the originating server violates the principle of log separation because a successful compromise of that host gives the attacker direct access to delete or alter the very evidence that would reveal their activity, defeating the purpose of logging as a tamper-resistant record of what occurred.

  • ✗

    Use a common log format for all sources

    Why it's wrong here

    Standardizing on a common log format, such as CEF or JSON, makes parsing, searching, and correlation across a SIEM significantly easier and is genuinely valuable operationally, but format standardization by itself does nothing to protect log confidentiality, integrity, or availability, which is why it is classified as an operational efficiency gain rather than a security control.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.