CISSP Security Assessment and Testing Practice Question
A security analyst is reviewing logs from multiple systems in a centralized log management platform. Which TWO of the following are primary benefits of centralized log management?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Simplifies compliance with log retention requirements
Centralized log management facilitates correlation across systems and simplifies compliance by providing a single source for log retention and review.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Simplifies compliance with log retention requirements
Why this is correct
Centralized log management consolidates logs from disparate sources into a single repository, which significantly streamlines the process of applying uniform retention policies. This approach ensures data integrity and facilitates audit readiness for various regulatory compliance mandates, such as HIPAA, PCI DSS, or GDPR. Instead of managing retention across numerous individual systems, administrators can enforce policies consistently from a central point, simplifying evidence collection during audits and demonstrating adherence to legal requirements.
- ✓
Enables correlation of events across systems
Why this is correct
Centralizing logs from various network devices, servers, and applications into a Security Information and Event Management (SIEM) system is crucial for effective event correlation. This aggregation allows security analysts to analyze seemingly disparate events, such as a failed login on a web server followed by a successful login from an unusual IP on a database server. By correlating these events, sophisticated attack sequences or insider threats that would be invisible when reviewing individual system logs can be identified and investigated.
- ✗
Eliminates the need for log retention policies
Why it's wrong here
Centralizing logs does not negate the fundamental requirement for robust log retention policies; rather, it often makes the enforcement of these policies more critical and efficient. Regulatory and internal compliance mandates still dictate how long specific types of logs must be stored, protected, and made available for forensic analysis or auditing. The centralized system merely provides a more effective mechanism for implementing and managing these essential policies, ensuring compliance rather than eliminating the need for the policies themselves.
- ✗
Reduces the volume of logs generated
Why it's wrong here
Centralized log management systems are designed to collect and aggregate logs from various sources, not to reduce the inherent volume of data being generated by those systems. While some Security Information and Event Management (SIEM) solutions might offer filtering or normalization capabilities to reduce storage footprint or noise post-collection, the initial generation rate of logs by individual systems remains unchanged. The primary goal is consolidation for comprehensive analysis, not source-level volume reduction.
- ✗
Automatically patches vulnerabilities
Why it's wrong here
Log management systems, including Security Information and Event Management (SIEM) solutions, are analytical tools designed to collect, store, and analyze security event data to detect potential threats and anomalies. Their function is to provide visibility into system activities and security posture, not to actively remediate or patch vulnerabilities within the monitored systems. Patch management is a separate, proactive process involving vulnerability scanning, patch deployment, and configuration management, which is distinct from log analysis.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.