hardMultiple Choice
ISC2 CC Practice Question: A security analyst notices that system logs are…
A security analyst notices that system logs are being overwritten before the retention period ends. What is the most likely cause?
⚠ Common exam trap
CC often tests log management; candidates may jump to security breaches or disk space, but misconfigured log rotation is a common cause of premature log loss.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Log rotation settings are misconfigured
The most likely cause is that log rotation settings are misconfigured. Log rotation is designed to archive and remove old logs based on size or time. If the rotation settings are too aggressive (e.g., rotating too frequently or keeping too few files), logs may be overwritten or deleted before the retention period ends. This is a common configuration issue, not necessarily malicious.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Malware is deleting logs
Why it's wrong here
Malware typically deletes or tampers with specific log entries to conceal activity, but it does not cause the systematic overwriting of older records that log rotation produces. It is tempting because anti-forensic log destruction is a genuine attacker technique, and it is the correct answer when individual log entries vanish selectively.
- ✗
SIEM is consuming logs too quickly
Why it's wrong here
A SIEM ingests copies of forwarded events; it does not delete or overwrite records on the source host, so its consumption rate cannot shorten retention. Fast SIEM ingestion is tempting because high log volume feels related to retention pressure, and it would be the answer if the question asked about collector throughput or indexing limits.
- ✓
Log rotation settings are misconfigured
Why this is correct
Misconfigured log rotation overwrites older entries once size or age thresholds trigger, directly violating the retention period the analyst expects. Rotation controls when files are archived or deleted, so incorrect limits cause premature loss before the required retention window elapses, matching the stem's overwriting symptom precisely.
- ✗
Disk space is insufficient
Why it's wrong here
Log rotation deletes old entries once a size or count threshold is hit, so a full disk is not what overwrites them; the retention window itself is being ignored. Insufficient disk space is tempting because it causes write failures and service outages, and would be the answer if logs stopped being written entirely rather than being replaced early.
About these practice questions
This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.