Courseiva
Security Operations →hardMultiple Choice

ISC2 CC Security Operations Practice Question

A security administrator is implementing measures to protect log integrity. Which of the following is the most effective method to prevent tampering with logs after they are generated?

⚠ Common exam trap

The trap is conflating confidentiality with integrity—candidates pick encryption because it sounds like a strong security control, but the question asks specifically about preventing tampering, which only immutability (write-once) guarantees.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using write-once storage

Write-once storage (WORM—write once, read many) prevents any modification or deletion of log data after it is written, which directly addresses tampering by making alteration physically or logically impossible. This is the strongest control because it enforces immutability at the storage layer rather than relying on cryptographic or procedural safeguards that can be bypassed if keys or access are compromised.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rotating logs daily

    Why it's wrong here

    Rotating logs daily only starts new files; it neither prevents nor detects modification of existing entries, so an attacker can still alter them. Rotation is tempting because it limits file size and aids retention management, and it would be the right control for storage housekeeping, not for tamper prevention.

  • ✗

    Encrypting logs with a symmetric key

    Why it's wrong here

    Symmetric encryption hides content but the same key both encrypts and decrypts, so anyone holding it can re-encrypt altered records, leaving no detectable change. It is tempting because it protects confidentiality at rest, which suits data-privacy requirements, but integrity requires hashing or write-once remote storage.

  • ✗

    Storing logs on the local system drive

    Why it's wrong here

    A local drive offers no write-once protection: anyone with host access, including malware running as root, can edit or delete files directly. It is tempting for simplicity and speed of local writes, and suits transient troubleshooting logs, but tamper prevention demands shipping logs to a remote immutable store.

  • ✓

    Using write-once storage

    Why this is correct

    Write-once storage enforces immutability at the media or object layer, so once a log entry is committed it cannot be altered or deleted, even by privileged accounts. This directly satisfies the requirement to prevent post-generation tampering rather than merely detecting it.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.