CISSP Security Operations Practice Question
A security administrator is reviewing the logging configuration for a fleet of Linux servers that host a regulated payment application. An external auditor requires that the servers produce a tamper-evident record of all authentication events, including successful and failed logons, and that the record be retained for one year. Which action BEST satisfies the auditor's requirement?
⚠ Common exam trap
The trap here is assuming that stronger local file permissions or SELinux enforcement make logs tamper-evident, when only off-host, append-only storage actually prevents a compromised server from rewriting its own history.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure rsyslog to forward authpriv facility messages to a remote log server that stores them on WORM media.
Authentication events on Linux flow through the authpriv facility, so shipping those messages to a separate collector addresses both integrity and retention. Storing them on write-once media means a compromised server cannot alter history, and centralizing them satisfies the one-year retention demand. Local-only controls, SELinux auditing, and alerting tools each miss either the completeness or the tamper-evidence requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable SELinux in enforcing mode on each server and audit the resulting AVC denials daily.
Why it's wrong here
SELinux enforcing mode hardens the host and its audit log records mandatory access control denials, but it does not capture successful interactive logons or the full authentication event stream the auditor requested. AVC denials are a subset of policy violations, not a complete, tamper-evident authentication record with one-year retention.
- ✗
Deploy a host-based intrusion detection agent that alerts the SOC whenever a failed logon threshold is exceeded.
Why it's wrong here
An HIDS agent generates real-time alerts about suspicious behavior, but alerting is not the same as producing a complete, tamper-evident audit trail of every authentication event. Alerts may be summarized or discarded after acknowledgement, so they cannot demonstrate the continuous one-year evidentiary record the external auditor requires.
- ✗
Increase the local /var/log/secure rotation interval and set the file permissions to 600 on each server.
Why it's wrong here
Retaining more rotations locally still leaves the evidence on the same host the attacker may control, so a root-level intruder can edit or delete it. File permissions of 600 only restrict non-privileged readers and do nothing to make the record tamper-evident or to guarantee one-year retention if the disk fills or the host is rebuilt.
- ✓
Configure rsyslog to forward authpriv facility messages to a remote log server that stores them on WORM media.
Why this is correct
The authpriv facility carries authentication and authorization messages on Linux, so forwarding it to a hardened remote collector preserves the events. Writing to write-once media plus remote shipping makes the record tamper-evident and supports the one-year retention the auditor demands, because local compromise cannot silently rewrite already-archived entries.
Go deeper
Related to this question
Learn chapter
Physical Security and Environmental Controls
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.