Courseiva
Log Management and SIEM →easyMultiple Choice

GSEC Log Management and SIEM Practice Question

A security operations center (SOC) uses a SIEM to collect logs from various sources. The SOC manager wants to ensure that log data is retained for at least one year to meet regulatory requirements, but the SIEM's primary storage is expensive and limited. Which log management strategy should the SOC implement to meet the retention requirement cost-effectively?

⚠ Common exam trap

The trap here is assuming that all logs must remain on primary SIEM storage for the entire retention period, which leads to unnecessary cost and scalability issues.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the SIEM to compress and archive older logs to a secondary storage tier, such as a network-attached storage (NAS) or cloud object storage, after a defined period.

The most cost-effective way to meet long-term retention is to tier storage: keep recent logs on fast, expensive primary storage and archive older logs to cheaper secondary storage. This balances performance for active investigations with compliance retention, avoiding unnecessary primary storage expansion or risky reliance on source systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure the SIEM to compress and archive older logs to a secondary storage tier, such as a network-attached storage (NAS) or cloud object storage, after a defined period.

    Why this is correct

    Archiving older logs to cheaper secondary storage is a standard cost-effective approach for long-term retention. The SIEM keeps recent, frequently queried data on expensive primary storage, while older logs are moved to a lower-cost tier. This meets the one-year retention requirement without overprovisioning primary storage. It also allows retrieval for investigations or compliance audits, though search performance on archived data may be slower.

  • ✗

    Reduce the log retention period to 30 days and rely on the original log sources to retain their own logs for one year.

    Why it's wrong here

    Relying on source systems to retain logs for a year is risky because many sources have limited local storage and may overwrite logs quickly. It also complicates compliance audits, as logs are scattered and may not be tamper-evident. This approach does not ensure centralized retention and could lead to gaps if a source is compromised or decommissioned. It fails to meet the requirement cost-effectively and reliably.

  • ✗

    Increase the SIEM's primary storage capacity by adding more high-performance disks to accommodate one year of logs.

    Why it's wrong here

    Adding high-performance primary storage is expensive and unnecessary for older logs that are rarely accessed. It does not leverage cost-effective tiers and may not scale well as log volume grows. While it would meet retention, it is not the most cost-effective strategy. The scenario explicitly mentions that primary storage is expensive and limited, so expanding it contradicts the goal of cost-effectiveness.

  • ✗

    Disable logging for low-priority sources and keep only high-priority logs for one year on primary storage.

    Why it's wrong here

    Disabling logging for low-priority sources reduces visibility and may violate compliance requirements that mandate logging from all critical systems. It does not address the retention of logs from high-priority sources, which may still exceed primary storage capacity. This approach sacrifices security monitoring for cost savings and does not provide a scalable retention solution. It fails to meet the requirement without compromising security.

About these practice questions

This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.