easyMultiple Select
CS0-003 Practice Question: Which TWO of the following are best practices for…
Which TWO of the following are best practices for secure log management? (Choose TWO)
⚠ Common exam trap
CompTIA often tests the misconception that 'common log format' is a security best practice, but it is actually an operational convenience; the trap is confusing operational efficiency with security controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable log encryption in transit and at rest
Encrypting logs in transit (e.g., using TLS/SSL for syslog over TCP 6514) and at rest (e.g., AES-256 encryption on the storage volume) ensures confidentiality and integrity, preventing unauthorized access or tampering. This aligns with security frameworks like NIST SP 800-92 and PCI DSS requirements for protecting log data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable log encryption in transit and at rest
Why this is correct
Encrypting logs in transit, typically with syslog over TLS, prevents an attacker on the network path from intercepting or tampering with events as they move to the collector, while encryption at rest protects stored log archives from unauthorized read access if the storage media or backup is stolen, together preserving both confidentiality and evidentiary integrity for later forensic use.
- ✓
Implement log aggregation from multiple sources
Why this is correct
Aggregating logs from firewalls, servers, and endpoints into a centralized SIEM enables cross-source correlation that reveals attack patterns invisible in any single log stream, and because logs are forwarded off the originating host in near real time, an attacker who later compromises and wipes that host's local logs cannot erase the copy already captured on the hardened collector.
- ✗
Disable logging on non-critical systems to save space
Why it's wrong here
Disabling logging on systems labeled non-critical to save storage directly creates blind spots, since attackers routinely pivot through lower-priority or forgotten systems specifically because they are under-monitored, and the resulting lack of audit trail can prevent an incident responder from reconstructing the full attack timeline during a later investigation.
- ✗
Store logs on the same server for easy access
Why it's wrong here
Keeping logs only on the originating server violates the principle of log separation because a successful compromise of that host gives the attacker direct access to delete or alter the very evidence that would reveal their activity, defeating the purpose of logging as a tamper-resistant record of what occurred.
- ✗
Use a common log format for all sources
Why it's wrong here
Standardizing on a common log format, such as CEF or JSON, makes parsing, searching, and correlation across a SIEM significantly easier and is genuinely valuable operationally, but format standardization by itself does nothing to protect log confidentiality, integrity, or availability, which is why it is classified as an operational efficiency gain rather than a security control.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Privileged Access Management and PAM Tools
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Log management
Log management is the process of collecting, storing, analyzing, and disposing of log data generated by computer systems, networks, and applications to ensure security, compliance, and operational health.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.