hardMultiple Select
CISSP Secure Transmission of Logs Practice Question
A security analyst is reviewing log data from various sources. Which of the following are essential for effective security logging in accordance with best practices? (Select THREE.)
⚠ Common exam trap
The trap here is that candidates may mistakenly believe that log retention must always be at least one year, but the CISSP emphasizes that retention periods are policy-driven and vary by compliance requirements, not a fixed universal standard.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Secure transmission of logs to a central repository
Option B is correct because securely transmitting logs (e.g., via TLS, syslog over TLS, or an encrypted SIEM ingestion channel) to a central repository protects log integrity and confidentiality and enables correlation across sources. Option C is correct because time synchronization (e.g., via NTP) ensures events from different systems share a consistent timeline, which is essential for accurate correlation and forensic reconstruction. Option E is correct because including user identifiers (such as usernames, account IDs, or session identifiers) in log entries ties actions to specific principals, supporting accountability, attribution, and incident investigation. Option A is not correct because storing logs only in plaintext is not a best practice; logs should be protected with access controls and often encryption or hashing to preserve integrity. Option D is not correct because while retention is important, a fixed minimum of at least one year is not a universal best-practice requirement and depends on legal, regulatory, and organizational needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Storage of logs in plaintext format only
Why it's wrong here
Plaintext-only storage exposes log contents to anyone with file access and fails integrity and confidentiality expectations. Plaintext is acceptable only where logs contain no sensitive data and are protected by other controls such as strict access permissions and encryption at rest.
- ✓
Secure transmission of logs to a central repository
Why this is correct
Logs traversing the network in cleartext can be intercepted, altered or spoofed, undermining their evidential value. Encrypting transport to the central repository (for example TLS or syslog over TLS) preserves confidentiality and integrity, satisfying the best-practice requirement that collected log data remain trustworthy.
- ✓
Time synchronization across all log sources
Why this is correct
Correlating events across disparate sources requires a common time base; without synchronisation via NTP, timestamps drift and sequence reconstruction fails. This satisfies the best-practice requirement that logs be comparable, enabling accurate incident timelines and forensic analysis across the estate.
- ✗
Log retention of at least one year
Why it's wrong here
PCI DSS requires twelve months of retention with the most recent three months immediately available; a blanket one-year minimum ignores that availability requirement and other frameworks' differing periods. One year is defensible where a regulation explicitly mandates twelve months of storage.
- ✓
Inclusion of user identifiers in log entries
Why this is correct
Log entries must record who performed an action, so including user identifiers ties each event to an authenticated principal. This supports attribution, non-repudiation and forensic reconstruction, which are core expectations for effective security logging under best-practice frameworks such as ISO 27002 and NIST SP 800-92.
Go deeper
Related to this question
Learn chapter
Physical Security and Environmental Controls
Key term
Hashing
Hashing is a one-way mathematical function that converts any input data into a fixed-length string of characters, called a hash or digest, which is used to verify data integrity and store passwords securely.
Key term
IDS
An IDS is a security system that monitors network or system traffic for suspicious activity and alerts administrators to potential threats, but does not actively block them.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.