Courseiva

CISSP Security Assessment and Testing Practice Question

A security analyst is reviewing logs from multiple systems in a centralized log management platform. Which TWO of the following are primary benefits of centralized log management?

⚠ Common exam trap

CISSP often tests the misconception that centralizing logs automatically reduces log volume or eliminates policy needs, when in fact it increases the importance of retention policies and does not change source log generation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Simplifies compliance with log retention requirements

Option A is correct because a centralized log management platform applies uniform retention settings and storage policies across all ingested sources, which directly simplifies demonstrating compliance with regulatory log retention requirements (e.g., PCI DSS 10.7, HIPAA, SOX). Option B is correct because aggregating logs from multiple systems into one platform allows the SIEM/log manager to correlate events across hosts, applications, and network devices, enabling detection of multi-stage or distributed attacks that would be invisible in isolated logs. Option C is wrong because centralization does not remove the need for retention policies; it actually requires well-defined retention rules to manage storage and compliance. Option D is wrong because centralization aggregates and stores logs, typically increasing rather than reducing total log volume, though it may improve analysis efficiency. Option E is wrong because log management platforms collect and analyze logs; they do not automatically patch vulnerabilities, which is the role of patch management or vulnerability management tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Simplifies compliance with log retention requirements

    Why this is correct

    Centralized log management consolidates logs from disparate sources into a single repository, which significantly streamlines the process of applying uniform retention policies. This approach ensures data integrity and facilitates audit readiness for various regulatory compliance mandates, such as HIPAA, PCI DSS, or GDPR. Instead of managing retention across numerous individual systems, administrators can enforce policies consistently from a central point, simplifying evidence collection during audits and demonstrating adherence to legal requirements.

  • ✓

    Enables correlation of events across systems

    Why this is correct

    Centralizing logs from various network devices, servers, and applications into a Security Information and Event Management (SIEM) system is crucial for effective event correlation. This aggregation allows security analysts to analyze seemingly disparate events, such as a failed login on a web server followed by a successful login from an unusual IP on a database server. By correlating these events, sophisticated attack sequences or insider threats that would be invisible when reviewing individual system logs can be identified and investigated.

  • ✗

    Eliminates the need for log retention policies

    Why it's wrong here

    Centralizing logs does not negate the fundamental requirement for robust log retention policies; rather, it often makes the enforcement of these policies more critical and efficient. Regulatory and internal compliance mandates still dictate how long specific types of logs must be stored, protected, and made available for forensic analysis or auditing. The centralized system merely provides a more effective mechanism for implementing and managing these essential policies, ensuring compliance rather than eliminating the need for the policies themselves.

  • ✗

    Reduces the volume of logs generated

    Why it's wrong here

    Centralized log management systems are designed to collect and aggregate logs from various sources, not to reduce the inherent volume of data being generated by those systems. While some Security Information and Event Management (SIEM) solutions might offer filtering or normalization capabilities to reduce storage footprint or noise post-collection, the initial generation rate of logs by individual systems remains unchanged. The primary goal is consolidation for comprehensive analysis, not source-level volume reduction.

  • ✗

    Automatically patches vulnerabilities

    Why it's wrong here

    Log management systems, including Security Information and Event Management (SIEM) solutions, are analytical tools designed to collect, store, and analyze security event data to detect potential threats and anomalies. Their function is to provide visibility into system activities and security posture, not to actively remediate or patch vulnerabilities within the monitored systems. Patch management is a separate, proactive process involving vulnerability scanning, patch deployment, and configuration management, which is distinct from log analysis.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.