Courseiva

CISSP Security Assessment and Testing Practice Question

An organization is reviewing its log management practices. Which THREE of the following are key considerations for effective log review?

⚠ Common exam trap

Many exam-takers think reviewing logs only after an incident is sufficient, but the CISSP emphasizes proactive, continuous monitoring as a key security control, not just reactive forensics.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Log retention policies that comply with legal and regulatory requirements

Option B is correct because log retention policies must satisfy legal, regulatory, and contractual requirements (e.g., GDPR, HIPAA, PCI DSS, SOX), ensuring logs are kept for the mandated period and disposed of securely afterward. Option D is correct because effective log review requires regularly scheduled reviews, not just reactive ones, so that anomalies, trends, and indicators of compromise can be detected proactively before they escalate. Option E is correct because centralized log management (e.g., via a SIEM or syslog server) aggregates logs from disparate sources, enabling correlation across systems and time synchronization for accurate event reconstruction. Option A is not appropriate because reviewing logs only after an incident is reactive and misses ongoing threats, while option C is wrong because storing logs in plaintext without access controls exposes sensitive data and violates integrity and confidentiality requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reviewing logs only after a security incident

    Why it's wrong here

    Reviewing logs only after a security incident is a reactive approach that severely limits an organization's ability to detect and prevent threats proactively. This practice means potential breaches or system anomalies could go unnoticed for extended periods, increasing the impact and cost of an eventual incident response. Effective security requires continuous, periodic log analysis to identify suspicious patterns and indicators of compromise before they escalate.

  • ✓

    Log retention policies that comply with legal and regulatory requirements

    Why this is correct

    Establishing log retention policies that strictly comply with all applicable legal and regulatory requirements is fundamental for maintaining an organization's security posture and legal standing. These policies ensure that critical audit trails are preserved for forensic investigations, e-discovery, and regulatory audits, demonstrating due diligence and accountability. Proper retention periods prevent premature deletion of evidence while also managing storage costs and data privacy obligations.

  • ✗

    Storing logs in plaintext without access controls

    Why it's wrong here

    Storing logs in plaintext without robust access controls creates a critical security vulnerability, compromising the confidentiality and integrity of vital security information. Unauthorized individuals could easily read sensitive event data, modify logs to cover their tracks, or delete them entirely, hindering incident detection and forensic analysis. Essential log data must be protected with encryption at rest and in transit, alongside strict role-based access controls.

  • ✓

    Regularly scheduled review of logs for anomalies

    Why this is correct

    Regularly scheduled review of logs for anomalies is a proactive security measure that enables early detection of deviations from normal system behavior. This systematic analysis, whether manual or automated, helps identify potential security incidents, misconfigurations, or operational issues before they can cause significant harm. Establishing a baseline of normal activity is crucial for effectively pinpointing unusual events that warrant further investigation.

  • ✓

    Centralized log management for aggregation and correlation

    Why this is correct

    Centralized log management facilitates the aggregation of log data from diverse sources into a single repository, significantly improving an organization's ability to correlate events across its entire infrastructure. This consolidation is essential for gaining a holistic view of security events, enabling more efficient analysis, threat hunting, and incident response. A centralized system supports the implementation of Security Information and Event Management (SIEM) solutions for automated correlation and alerting.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.