CISSP Security Assessment and Testing Practice Question
A company is required to retain logs for regulatory compliance. Which factor primarily determines the log retention period?
⚠ Common exam trap
Watch out — candidates often confuse operational factors (storage capacity, log volume) with the primary driver (regulatory requirements), mistakenly thinking that if storage is limited, the retention period can be shortened—but compliance mandates are non-negotiable and must be met regardless of infrastructure constraints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Regulatory requirements
Regulatory compliance frameworks (e.g., PCI DSS, HIPAA, SOX, GDPR) explicitly mandate minimum log retention periods (e.g., PCI DSS Requirement 10.7 requires at least one year of logs, with three months immediately accessible). Storage capacity, incident response needs, and log volume are operational considerations that may influence implementation but do not override the legal or contractual obligation to retain logs for a specified duration. The primary factor is the regulatory requirement itself, as failure to comply can result in fines, legal liability, or loss of certification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Storage capacity
Why it's wrong here
Storage capacity is a practical constraint that influences the *implementation* of a log retention policy, dictating the infrastructure and resources required to store the data. However, it does not *determine* the retention period itself. Regulatory requirements mandate specific retention durations, and organizations must ensure they have sufficient capacity to meet these non-negotiable compliance obligations, potentially by expanding storage or optimizing log management solutions.
- ✗
Incident response needs
Why it's wrong here
While logs are indispensable for effective incident response, providing critical forensic data for detection, analysis, and containment of security incidents, these operational needs typically define *access* and *utility* rather than the *minimum retention period*. Regulatory compliance often mandates significantly longer retention durations to satisfy audit requirements, legal discovery, or long-term accountability, extending far beyond the immediate incident investigation window.
- ✓
Regulatory requirements
Why this is correct
Regulatory requirements are the primary driver for log retention policies because various compliance frameworks, such as HIPAA, PCI DSS, GDPR, and SOX, explicitly mandate specific types of logs and their minimum retention periods. These mandates ensure accountability, provide an audit trail, and support legal defensibility, with non-compliance leading to severe penalties, fines, and reputational damage. Organizations must align their log retention strategies directly with these external obligations.
- ✗
Log volume
Why it's wrong here
Log volume, which refers to the sheer quantity of data generated, primarily impacts the technical aspects of log management, such as storage infrastructure planning, archiving strategies, and associated costs. However, the *duration* for which these logs must be retained is not determined by how much data is produced. Instead, the retention period is dictated by external regulatory mandates or internal governance policies, irrespective of whether the volume is high or low.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Regulatory requirement
A regulatory requirement is a rule issued by a government or industry authority that organizations must follow, often to protect data, ensure safety, or maintain fair practices.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.