Courseiva
hardMultiple Choice

ISC2 CC Practice Question: A security analyst notices that system logs are…

A security analyst notices that system logs are being overwritten before the retention period ends. What is the most likely cause?

⚠ Common exam trap

CC often tests log management; candidates may jump to security breaches or disk space, but misconfigured log rotation is a common cause of premature log loss.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Log rotation settings are misconfigured

The most likely cause is that log rotation settings are misconfigured. Log rotation is designed to archive and remove old logs based on size or time. If the rotation settings are too aggressive (e.g., rotating too frequently or keeping too few files), logs may be overwritten or deleted before the retention period ends. This is a common configuration issue, not necessarily malicious.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Malware is deleting logs

    Why it's wrong here

    Malware typically deletes or tampers with specific log entries to conceal activity, but it does not cause the systematic overwriting of older records that log rotation produces. It is tempting because anti-forensic log destruction is a genuine attacker technique, and it is the correct answer when individual log entries vanish selectively.

  • ✗

    SIEM is consuming logs too quickly

    Why it's wrong here

    A SIEM ingests copies of forwarded events; it does not delete or overwrite records on the source host, so its consumption rate cannot shorten retention. Fast SIEM ingestion is tempting because high log volume feels related to retention pressure, and it would be the answer if the question asked about collector throughput or indexing limits.

  • ✓

    Log rotation settings are misconfigured

    Why this is correct

    Misconfigured log rotation overwrites older entries once size or age thresholds trigger, directly violating the retention period the analyst expects. Rotation controls when files are archived or deleted, so incorrect limits cause premature loss before the required retention window elapses, matching the stem's overwriting symptom precisely.

  • ✗

    Disk space is insufficient

    Why it's wrong here

    Log rotation deletes old entries once a size or count threshold is hit, so a full disk is not what overwrites them; the retention window itself is being ignored. Insufficient disk space is tempting because it causes write failures and service outages, and would be the answer if logs stopped being written entirely rather than being replaced early.

About these practice questions

This CC question is part of Courseiva's 989-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.