Courseiva
Security Assessment and TestingmediumMultiple ChoiceObjective-mapped

CISSP Security Assessment and Testing Practice Question

A company is required to retain logs for regulatory compliance. Which factor primarily determines the log retention period?

⚠ Common exam trap

Watch out — candidates often confuse operational factors (storage capacity, log volume) with the primary driver (regulatory requirements), mistakenly thinking that if storage is limited, the retention period can be shortened—but compliance mandates are non-negotiable and must be met regardless of infrastructure constraints.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Regulatory requirements

Regulatory compliance frameworks (e.g., PCI DSS, HIPAA, SOX, GDPR) explicitly mandate minimum log retention periods (e.g., PCI DSS Requirement 10.7 requires at least one year of logs, with three months immediately accessible). Storage capacity, incident response needs, and log volume are operational considerations that may influence implementation but do not override the legal or contractual obligation to retain logs for a specified duration. The primary factor is the regulatory requirement itself, as failure to comply can result in fines, legal liability, or loss of certification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Storage capacity

    Why it's wrong here

    Storage capacity is a practical constraint that influences the *implementation* of a log retention policy, dictating the infrastructure and resources required to store the data. However, it does not *determine* the retention period itself. Regulatory requirements mandate specific retention durations, and organizations must ensure they have sufficient capacity to meet these non-negotiable compliance obligations, potentially by expanding storage or optimizing log management solutions.

  • Incident response needs

    Why it's wrong here

    While logs are indispensable for effective incident response, providing critical forensic data for detection, analysis, and containment of security incidents, these operational needs typically define *access* and *utility* rather than the *minimum retention period*. Regulatory compliance often mandates significantly longer retention durations to satisfy audit requirements, legal discovery, or long-term accountability, extending far beyond the immediate incident investigation window.

  • Regulatory requirements

    Why this is correct

    Regulatory requirements are the primary driver for log retention policies because various compliance frameworks, such as HIPAA, PCI DSS, GDPR, and SOX, explicitly mandate specific types of logs and their minimum retention periods. These mandates ensure accountability, provide an audit trail, and support legal defensibility, with non-compliance leading to severe penalties, fines, and reputational damage. Organizations must align their log retention strategies directly with these external obligations.

  • Log volume

    Why it's wrong here

    Log volume, which refers to the sheer quantity of data generated, primarily impacts the technical aspects of log management, such as storage infrastructure planning, archiving strategies, and associated costs. However, the *duration* for which these logs must be retained is not determined by how much data is produced. Instead, the retention period is dictated by external regulatory mandates or internal governance policies, irrespective of whether the volume is high or low.

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.