ISC2 CC Security Operations Practice Question
A security administrator is implementing measures to protect log integrity. Which of the following is the most effective method to prevent tampering with logs after they are generated?
⚠ Common exam trap
The trap is conflating confidentiality with integrity—candidates pick encryption because it sounds like a strong security control, but the question asks specifically about preventing tampering, which only immutability (write-once) guarantees.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using write-once storage
Write-once storage (WORM—write once, read many) prevents any modification or deletion of log data after it is written, which directly addresses tampering by making alteration physically or logically impossible. This is the strongest control because it enforces immutability at the storage layer rather than relying on cryptographic or procedural safeguards that can be bypassed if keys or access are compromised.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rotating logs daily
Why it's wrong here
Rotating logs daily only starts new files; it neither prevents nor detects modification of existing entries, so an attacker can still alter them. Rotation is tempting because it limits file size and aids retention management, and it would be the right control for storage housekeeping, not for tamper prevention.
- ✗
Encrypting logs with a symmetric key
Why it's wrong here
Symmetric encryption hides content but the same key both encrypts and decrypts, so anyone holding it can re-encrypt altered records, leaving no detectable change. It is tempting because it protects confidentiality at rest, which suits data-privacy requirements, but integrity requires hashing or write-once remote storage.
- ✗
Storing logs on the local system drive
Why it's wrong here
A local drive offers no write-once protection: anyone with host access, including malware running as root, can edit or delete files directly. It is tempting for simplicity and speed of local writes, and suits transient troubleshooting logs, but tamper prevention demands shipping logs to a remote immutable store.
- ✓
Using write-once storage
Why this is correct
Write-once storage enforces immutability at the media or object layer, so once a log entry is committed it cannot be altered or deleted, even by privileged accounts. This directly satisfies the requirement to prevent post-generation tampering rather than merely detecting it.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Worm
A worm is a type of malicious software that can copy itself and spread to other computers over a network, often without any human action.
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.