SSCP Risk Identification, Monitoring, and Analysis Practice Question
A company is implementing a new SIEM. Which THREE factors are most important to ensure log integrity and usefulness for forensic investigations? (Choose THREE.)
⚠ Common exam trap
A common trap on the SSCP exam is to select 'centralized aggregation' (Option E) as a key factor for log integrity, but aggregation alone does not protect against modification. The correct factors focus on preserving log authenticity and immutability, such as write-once storage and digital signatures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Write-once storage to prevent modification
Option A (write-once storage to prevent modification) is correct because WORM (Write Once Read Many) media or immutable storage ensures that once log data is written it cannot be altered or deleted, preserving evidentiary integrity for forensics. Option B (digital signing of logs to verify authenticity) is correct because cryptographic signatures or hashes let investigators prove logs were not tampered with and confirm their origin, supporting non-repudiation and chain-of-custody requirements. Option D (ensuring logs are retained for a period consistent with legal and regulatory requirements) is correct because forensic usefulness depends on having the relevant logs still available when an investigation occurs, and retention periods are often mandated by laws such as HIPAA, PCI DSS, or GDPR. Option C is not correct because minimizing retention to cut storage costs directly undermines forensic and compliance needs by destroying potentially critical evidence prematurely. Option E is not correct because centralizing logs improves correlation and management but does not by itself guarantee integrity or forensic usefulness, and it can even concentrate risk if the repository is not protected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Write-once storage to prevent modification
Why this is correct
Write-once storage prevents logs from being altered or deleted after capture, preserving evidential integrity. This directly satisfies the forensic requirement that records remain tamper-evident and unmodified, ensuring investigators can trust that what they review reflects the original event data.
- ✓
Digital signing of logs to verify authenticity
Why this is correct
Digital signing lets investigators verify that logs originated from the claimed source and were not forged or altered in transit. This satisfies the authenticity requirement, complementing integrity controls by proving provenance, which is essential when log evidence must withstand scrutiny.
- ✗
Minimizing log retention to reduce storage costs
Why it's wrong here
Short retention destroys the historical evidence forensic investigations depend on, since incidents are often discovered months after the event. It tempts because storage cost reduction is a real operational pressure, and would be correct if the question asked how to lower SIEM storage expenditure rather than preserve forensic usefulness.
- ✓
Ensuring logs are retained for a period consistent with legal and regulatory requirements
Why this is correct
Retention aligned to legal and regulatory requirements preserves logs long enough for forensic reconstruction and satisfies chain-of-custody and evidentiary obligations. Without adequate retention, evidence may be destroyed before an investigation concludes, undermining both admissibility and the SIEM's investigative usefulness.
- ✗
Aggregating logs from all sources into one centralized repository
Why it's wrong here
Centralising logs improves correlation and search, but aggregation alone neither preserves integrity nor proves usefulness for forensics; hashing, time synchronisation, and tamper-evident storage do. It tempts because a single repository is a genuine SIEM design goal, and would be correct if the question asked about correlation efficiency rather than forensic integrity.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.