SSCP Security Operations and Administration Practice Question
A security administrator at a healthcare company must ensure that audit logs from a critical patient-record system are retained for seven years and cannot be altered even by system administrators. Which solution BEST meets these requirements?
⚠ Common exam trap
The trap here is assuming that restricting permissions or using RBAC is sufficient to make logs tamper-proof, when in fact only WORM or similar immutable storage guarantees that even administrators cannot alter the data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a write-once read-many (WORM) storage solution for log archival with a seven-year retention policy.
WORM storage ensures that once audit logs are written, they cannot be modified or deleted, even by users with administrative privileges, directly meeting the immutability and seven-year retention requirements. Other options focus on access control or encryption but do not provide the non-repudiation and tamper-evidence needed for compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a SIEM with role-based access control (RBAC) to limit who can view or delete logs.
Why it's wrong here
RBAC restricts access based on roles but does not make logs immutable; an administrator with sufficient privileges can still alter or delete them. The requirement is that logs cannot be altered even by system administrators, which RBAC alone cannot guarantee. Retention is also not enforced by access control.
- ✗
Enable local logging with daily log rotation and store the logs on a separate encrypted volume.
Why it's wrong here
Encrypting a separate volume protects confidentiality at rest but does not prevent an administrator with access to the encryption keys from altering or deleting the logs. Local logging is also vulnerable if the host is compromised. This does not meet the immutability or long-term retention requirement.
- ✗
Configure the system to send logs to a remote syslog server with file permissions restricted to root.
Why it's wrong here
A remote syslog server with restricted permissions still allows a privileged administrator to modify or delete logs, so it does not guarantee immutability. The scenario explicitly requires that logs cannot be altered even by system administrators, which this approach fails to satisfy. Additionally, retention for seven years is not enforced by permissions alone.
- ✓
Implement a write-once read-many (WORM) storage solution for log archival with a seven-year retention policy.
Why this is correct
WORM storage physically or logically prevents modification or deletion of data once written, directly satisfying the immutability requirement even against privileged administrators. A seven-year retention policy ensures compliance with the stated retention period. This is the standard approach for tamper-evident audit log archiving in regulated industries.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.