Courseiva
mediumMultiple Choice

SSCP SIEM Practice Question

An IT auditor reports that firewall logs are not being reviewed regularly. Which control should be implemented to address this finding?

⚠ Common exam trap

SSCP often tests the difference between log retention, archiving, and active monitoring; candidates may confuse preserving logs with reviewing them, leading to selection of options A or C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a Security Information and Event Management (SIEM) system

A SIEM system centralizes log collection, correlation, and alerting, enabling regular review and automated detection of security events. It directly addresses the finding that firewall logs are not reviewed regularly by providing continuous monitoring and analysis. Unlike simple archiving or retention changes, a SIEM actively processes logs to generate actionable insights.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Archive logs to a read-only medium

    Why it's wrong here

    Archiving preserves logs for later retrieval but does not cause anyone to examine them, so the review gap persists. It is tempting because read-only archiving is a genuine integrity control, and it would be correct where the requirement is tamper-evident retention rather than active monitoring.

  • ✗

    Disable logging for low-priority events

    Why it's wrong here

    Suppressing low-priority logging reduces the data available for review, worsening the audit finding rather than creating a review process. It is tempting because log-volume reduction is a legitimate tuning activity, and it would be the right choice when storage or performance constraints make full logging unsustainable.

  • ✗

    Increase the log retention period to 12 months

    Why it's wrong here

    Extending retention keeps records available for longer but schedules no examination, leaving the finding unaddressed. It is tempting because retention periods are a standard audit remediation, and it would be correct where logs are being discarded before an investigation or compliance window can complete.

  • ✓

    Deploy a Security Information and Event Management (SIEM) system

    Why this is correct

    A SIEM system centralises firewall logs and applies correlation rules to generate real-time alerts, directly satisfying the audit finding that logs are not reviewed regularly. Unlike manual review, automated monitoring provides continuous oversight and auditable evidence of detection, addressing the control gap the auditor identified.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.