SSCP Risk Identification, Monitoring, and Analysis Practice Question
A company's security policy requires that all logs be stored in a write-once, read-many (WORM) format. What is the primary security objective of this requirement?
⚠ Common exam trap
Watch out — candidates often confuse integrity with availability or cost, as candidates might think WORM ensures logs are always accessible or saves money, but the core security objective is preventing unauthorized modification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To maintain log integrity
WORM (write-once, read-many) storage prevents any modification or deletion of log data after it is written, directly preserving the integrity of the logs. This ensures that log entries remain an accurate and unaltered record of events, which is critical for forensic investigations, compliance audits, and legal admissibility. The primary security objective is therefore to maintain log integrity, not availability, speed, or cost.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
To maintain log integrity
Why this is correct
WORM storage prevents modification or deletion of existing records, so attackers or rogue insiders cannot alter or erase evidence after intrusion. This preserves the log's evidential value and supports non-repudiation, directly satisfying the policy's objective of maintaining log integrity.
- ✗
To ensure log availability
Why it's wrong here
WORM prevents modification and deletion, which addresses integrity, not availability; an immutable store can still be unavailable. It tempts because immutability supports recovery and retention, and it would be correct if the requirement were resilience against ransomware or accidental deletion rather than tamper-evidence.
- ✗
To improve log review speed
Why it's wrong here
WORM governs whether records can be changed, not how quickly analysts read them; review speed depends on indexing, search tooling and log format. It tempts because immutable logs are trustworthy inputs to analysis, and it would be correct if the requirement were about ensuring reviewers cannot alter evidence while investigating.
- ✗
To reduce storage costs
Why it's wrong here
WORM storage typically costs more, not less, because immutable media and retention management add expense; the objective is integrity, preventing alteration or deletion of log records. It tempts because retention policies can reduce duplicated storage, and it would be correct if the requirement were about tiering or archiving older logs.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.