Courseiva
Security Assessment and TestinghardMultiple SelectObjective-mapped

CISSP Security Assessment and Testing Practice Question

A security analyst is reviewing logs from multiple systems in a centralized log management platform. Which TWO of the following are primary benefits of centralized log management?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Simplifies compliance with log retention requirements

Centralized log management facilitates correlation across systems and simplifies compliance by providing a single source for log retention and review.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Simplifies compliance with log retention requirements

    Why this is correct

    Centralized log management consolidates logs from disparate sources into a single repository, which significantly streamlines the process of applying uniform retention policies. This approach ensures data integrity and facilitates audit readiness for various regulatory compliance mandates, such as HIPAA, PCI DSS, or GDPR. Instead of managing retention across numerous individual systems, administrators can enforce policies consistently from a central point, simplifying evidence collection during audits and demonstrating adherence to legal requirements.

  • Enables correlation of events across systems

    Why this is correct

    Centralizing logs from various network devices, servers, and applications into a Security Information and Event Management (SIEM) system is crucial for effective event correlation. This aggregation allows security analysts to analyze seemingly disparate events, such as a failed login on a web server followed by a successful login from an unusual IP on a database server. By correlating these events, sophisticated attack sequences or insider threats that would be invisible when reviewing individual system logs can be identified and investigated.

  • Eliminates the need for log retention policies

    Why it's wrong here

    Centralizing logs does not negate the fundamental requirement for robust log retention policies; rather, it often makes the enforcement of these policies more critical and efficient. Regulatory and internal compliance mandates still dictate how long specific types of logs must be stored, protected, and made available for forensic analysis or auditing. The centralized system merely provides a more effective mechanism for implementing and managing these essential policies, ensuring compliance rather than eliminating the need for the policies themselves.

  • Reduces the volume of logs generated

    Why it's wrong here

    Centralized log management systems are designed to collect and aggregate logs from various sources, not to reduce the inherent volume of data being generated by those systems. While some Security Information and Event Management (SIEM) solutions might offer filtering or normalization capabilities to reduce storage footprint or noise post-collection, the initial generation rate of logs by individual systems remains unchanged. The primary goal is consolidation for comprehensive analysis, not source-level volume reduction.

  • Automatically patches vulnerabilities

    Why it's wrong here

    Log management systems, including Security Information and Event Management (SIEM) solutions, are analytical tools designed to collect, store, and analyze security event data to detect potential threats and anomalies. Their function is to provide visibility into system activities and security posture, not to actively remediate or patch vulnerabilities within the monitored systems. Patch management is a separate, proactive process involving vulnerability scanning, patch deployment, and configuration management, which is distinct from log analysis.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.