Courseiva
hardMultiple Select

CISSP Secure Transmission of Logs Practice Question

A security analyst is reviewing log data from various sources. Which of the following are essential for effective security logging in accordance with best practices? (Select THREE.)

⚠ Common exam trap

The trap here is that candidates may mistakenly believe that log retention must always be at least one year, but the CISSP emphasizes that retention periods are policy-driven and vary by compliance requirements, not a fixed universal standard.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Secure transmission of logs to a central repository

Option B is correct because securely transmitting logs (e.g., via TLS, syslog over TLS, or an encrypted SIEM ingestion channel) to a central repository protects log integrity and confidentiality and enables correlation across sources. Option C is correct because time synchronization (e.g., via NTP) ensures events from different systems share a consistent timeline, which is essential for accurate correlation and forensic reconstruction. Option E is correct because including user identifiers (such as usernames, account IDs, or session identifiers) in log entries ties actions to specific principals, supporting accountability, attribution, and incident investigation. Option A is not correct because storing logs only in plaintext is not a best practice; logs should be protected with access controls and often encryption or hashing to preserve integrity. Option D is not correct because while retention is important, a fixed minimum of at least one year is not a universal best-practice requirement and depends on legal, regulatory, and organizational needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Storage of logs in plaintext format only

    Why it's wrong here

    Plaintext-only storage exposes log contents to anyone with file access and fails integrity and confidentiality expectations. Plaintext is acceptable only where logs contain no sensitive data and are protected by other controls such as strict access permissions and encryption at rest.

  • ✓

    Secure transmission of logs to a central repository

    Why this is correct

    Logs traversing the network in cleartext can be intercepted, altered or spoofed, undermining their evidential value. Encrypting transport to the central repository (for example TLS or syslog over TLS) preserves confidentiality and integrity, satisfying the best-practice requirement that collected log data remain trustworthy.

  • ✓

    Time synchronization across all log sources

    Why this is correct

    Correlating events across disparate sources requires a common time base; without synchronisation via NTP, timestamps drift and sequence reconstruction fails. This satisfies the best-practice requirement that logs be comparable, enabling accurate incident timelines and forensic analysis across the estate.

  • ✗

    Log retention of at least one year

    Why it's wrong here

    PCI DSS requires twelve months of retention with the most recent three months immediately available; a blanket one-year minimum ignores that availability requirement and other frameworks' differing periods. One year is defensible where a regulation explicitly mandates twelve months of storage.

  • ✓

    Inclusion of user identifiers in log entries

    Why this is correct

    Log entries must record who performed an action, so including user identifiers ties each event to an authenticated principal. This supports attribution, non-repudiation and forensic reconstruction, which are core expectations for effective security logging under best-practice frameworks such as ISO 27002 and NIST SP 800-92.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.