mediumMultiple Choice
ISC2 CC Is implementing a new logging policy Practice Question
An organization is implementing a new logging policy. Which type of data should be excluded from logs to comply with privacy regulations?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Personal identifiable information (PII)
Personal Identifiable Information (PII) should be excluded from logs to comply with privacy regulations like GDPR. Options A, B, and D are typically safe to log and important for security monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
System performance metrics
Why it's wrong here
System performance metrics contain no personal identifiers, so excluding them satisfies no privacy requirement and instead removes operational visibility. It is tempting because metrics are non-essential to security auditing, but the question asks what must be excluded under privacy regulation, which is personal data.
- ✗
User authentication attempts
Why it's wrong here
Authentication attempts record usernames, source addresses and timestamps, which are needed for intrusion detection and are not the personal data privacy rules target for exclusion. It is tempting because failed logins feel sensitive, but they are security telemetry, not regulated personal content.
- ✓
Personal identifiable information (PII)
Why this is correct
Excluding personally identifiable information satisfies privacy regulations because PII directly identifies individuals, such as names, addresses, or government identifiers. Logging such data creates regulatory exposure under GDPR and similar frameworks, so it must be filtered before ingestion. This directly meets the stem's compliance constraint rather than merely reducing storage or noise.
- ✗
Network traffic patterns
Why it's wrong here
Network traffic patterns are metadata used for anomaly and exfiltration detection, and they carry no regulated personal content requiring exclusion. It is tempting because traffic data can feel sensitive, but privacy rules target personal data such as credentials or identifiers, not flow statistics.
Go deeper
Related to this question
Key term
GDPR
The General Data Protection Regulation (GDPR) is a European Union law that sets strict rules for how organizations collect, store, process, and protect the personal data of individuals within the EU.
Key term
Privacy
Privacy in IT is the control over how personal data is collected, stored, used, and shared by systems and organizations.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.