hardMultiple Choice
CCSP Practice Question: A company uses a cloud-based SIEM to aggregate…
A company uses a cloud-based SIEM to aggregate logs from multiple sources. Recently, the SIEM stopped receiving logs from a critical application server. The server is running and the application is functioning normally. The security team has verified that the log forwarder service is running on the server and the network path to the SIEM is open. Which additional step should the team take to diagnose the issue?
⚠ Common exam trap
ISC2 often tests the misconception that network-level checks (firewall, connectivity) are sufficient, when the real issue is often an application-layer misconfiguration within the log forwarder itself, which candidates overlook because they assume a 'running' service is correctly configured.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inspect the log forwarder's configuration and recent log files for errors.
The most likely cause of logs not being received by the SIEM, when the server is running and the network path is open, is a misconfiguration or error within the log forwarder itself. Inspecting the forwarder's configuration (e.g., destination IP, port, protocol) and its local log files (e.g., syslog, Windows Event Forwarding logs) can reveal authentication failures, queue overflows, or parsing errors that prevent log transmission. This step directly addresses the log generation and forwarding pipeline, which is the remaining point of failure after verifying network connectivity and service status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check the server's CPU and memory utilization.
Why it's wrong here
The application is functioning normally, so CPU and memory exhaustion is not the cause; resource pressure would also have been visible in application performance. It tempts because overloaded hosts do drop log forwarding, but the stem's evidence points instead to forwarder configuration or SIEM-side ingestion.
- ✗
Review the firewall rules between the server and the SIEM.
Why it's wrong here
The stem already confirms the network path to the SIEM is open, so rechecking firewall rules repeats a verified fact and yields nothing. It tempts because firewalls commonly block log transport, but here the remaining suspects are forwarder configuration, credentials, or the SIEM's own ingestion pipeline.
- ✗
Restart the SIEM collector service.
Why it's wrong here
Restarting the collector is a blind remediation that discards evidence before diagnosis; the fault may lie in the forwarder's configuration or credentials, not the collector. It tempts because collector restarts often clear transient stalls, but the stem gives no indication the collector itself is failing.
- ✓
Inspect the log forwarder's configuration and recent log files for errors.
Why this is correct
With the service running and network path verified, the remaining likely cause is a misconfigured or failing forwarder. Inspecting its configuration and recent log files reveals errors such as changed credentials, wrong destination, or buffer failures.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.