Courseiva
mediumMultiple Choice

ISC2 CC Is implementing a new logging policy Practice Question

An organization is implementing a new logging policy. Which type of data should be excluded from logs to comply with privacy regulations?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Personal identifiable information (PII)

Personal Identifiable Information (PII) should be excluded from logs to comply with privacy regulations like GDPR. Options A, B, and D are typically safe to log and important for security monitoring.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    System performance metrics

    Why it's wrong here

    System performance metrics contain no personal identifiers, so excluding them satisfies no privacy requirement and instead removes operational visibility. It is tempting because metrics are non-essential to security auditing, but the question asks what must be excluded under privacy regulation, which is personal data.

  • ✗

    User authentication attempts

    Why it's wrong here

    Authentication attempts record usernames, source addresses and timestamps, which are needed for intrusion detection and are not the personal data privacy rules target for exclusion. It is tempting because failed logins feel sensitive, but they are security telemetry, not regulated personal content.

  • ✓

    Personal identifiable information (PII)

    Why this is correct

    Excluding personally identifiable information satisfies privacy regulations because PII directly identifies individuals, such as names, addresses, or government identifiers. Logging such data creates regulatory exposure under GDPR and similar frameworks, so it must be filtered before ingestion. This directly meets the stem's compliance constraint rather than merely reducing storage or noise.

  • ✗

    Network traffic patterns

    Why it's wrong here

    Network traffic patterns are metadata used for anomaly and exfiltration detection, and they carry no regulated personal content requiring exclusion. It is tempting because traffic data can feel sensitive, but privacy rules target personal data such as credentials or identifiers, not flow statistics.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.