SSCP Risk Identification, Monitoring, and Analysis Practice Question
A security engineer is reviewing system logs and notices that the log file size has not changed for several days, despite high system activity. Which log management concern does this indicate?
⚠ Common exam trap
ISC2 SSCP often tests the misconception that a static log file size is due to log rotation, but rotation actually creates a new active log file with new entries, not a file that remains unchanged for days.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Log tampering or disabled logging
The log file size remaining static despite high system activity strongly indicates that logging has been disabled or the log files have been tampered with (e.g., truncated or replaced with empty files). Under normal operation, a busy system generates continuous log entries, causing the log file size to increase. A complete lack of size change over several days is a classic red flag for log integrity compromise, not a benign administrative action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Incorrect time synchronization
Why it's wrong here
Time synchronisation affects timestamps, not file growth; unsynchronised clocks misorder events but still write entries. It is tempting because clock drift is a recognised log integrity issue, yet it would be the answer if timestamps were inconsistent rather than the file size remaining static.
- ✗
Normal log rotation
Why it's wrong here
Rotation archives or truncates logs, so size resets periodically, but it does not freeze growth indefinitely while activity continues. It is tempting because rotation explains a size that appears static at a glance, yet the stem describes no new entries accumulating at all, indicating logging failure.
- ✗
Insufficient storage capacity
Why it's wrong here
Insufficient storage stops new writes once the volume fills, which is plausible, but the stem gives no capacity alert and the file size would typically plateau at a maximum rather than remain unchanged from the outset. It is tempting because disk exhaustion is a common cause of lost logging.
- ✓
Log tampering or disabled logging
Why this is correct
Static log size despite high activity indicates logging has been halted or the file altered, satisfying the stem's concern about missing audit records. Tampering or disabled logging removes the evidence trail entirely, unlike rotation or retention issues, which still produce new entries.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.