CISSP Security Assessment and Testing Practice Question
An organization is reviewing its log management practices. Which THREE of the following are key considerations for effective log review?
⚠ Common exam trap
Many exam-takers think reviewing logs only after an incident is sufficient, but the CISSP emphasizes proactive, continuous monitoring as a key security control, not just reactive forensics.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Log retention policies that comply with legal and regulatory requirements
Option B is correct because log retention policies must satisfy legal, regulatory, and contractual requirements (e.g., GDPR, HIPAA, PCI DSS, SOX), ensuring logs are kept for the mandated period and disposed of securely afterward. Option D is correct because effective log review requires regularly scheduled reviews, not just reactive ones, so that anomalies, trends, and indicators of compromise can be detected proactively before they escalate. Option E is correct because centralized log management (e.g., via a SIEM or syslog server) aggregates logs from disparate sources, enabling correlation across systems and time synchronization for accurate event reconstruction. Option A is not appropriate because reviewing logs only after an incident is reactive and misses ongoing threats, while option C is wrong because storing logs in plaintext without access controls exposes sensitive data and violates integrity and confidentiality requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reviewing logs only after a security incident
Why it's wrong here
Reviewing logs only after a security incident is a reactive approach that severely limits an organization's ability to detect and prevent threats proactively. This practice means potential breaches or system anomalies could go unnoticed for extended periods, increasing the impact and cost of an eventual incident response. Effective security requires continuous, periodic log analysis to identify suspicious patterns and indicators of compromise before they escalate.
- ✓
Log retention policies that comply with legal and regulatory requirements
Why this is correct
Establishing log retention policies that strictly comply with all applicable legal and regulatory requirements is fundamental for maintaining an organization's security posture and legal standing. These policies ensure that critical audit trails are preserved for forensic investigations, e-discovery, and regulatory audits, demonstrating due diligence and accountability. Proper retention periods prevent premature deletion of evidence while also managing storage costs and data privacy obligations.
- ✗
Storing logs in plaintext without access controls
Why it's wrong here
Storing logs in plaintext without robust access controls creates a critical security vulnerability, compromising the confidentiality and integrity of vital security information. Unauthorized individuals could easily read sensitive event data, modify logs to cover their tracks, or delete them entirely, hindering incident detection and forensic analysis. Essential log data must be protected with encryption at rest and in transit, alongside strict role-based access controls.
- ✓
Regularly scheduled review of logs for anomalies
Why this is correct
Regularly scheduled review of logs for anomalies is a proactive security measure that enables early detection of deviations from normal system behavior. This systematic analysis, whether manual or automated, helps identify potential security incidents, misconfigurations, or operational issues before they can cause significant harm. Establishing a baseline of normal activity is crucial for effectively pinpointing unusual events that warrant further investigation.
- ✓
Centralized log management for aggregation and correlation
Why this is correct
Centralized log management facilitates the aggregation of log data from diverse sources into a single repository, significantly improving an organization's ability to correlate events across its entire infrastructure. This consolidation is essential for gaining a holistic view of security events, enabling more efficient analysis, threat hunting, and incident response. A centralized system supports the implementation of Security Information and Event Management (SIEM) solutions for automated correlation and alerting.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
PCI DSS
The Payment Card Industry Data Security Standard is a set of security requirements designed to protect credit card data during storage, processing, and transmission.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.