Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

An organization is required to maintain audit logs for at least one year for compliance purposes. Which log management practice best ensures the integrity of these logs?

⚠ Common exam trap

Many exam-takers choose restricted permissions (Option C) thinking access control is sufficient, but the SSCP exam emphasizes that integrity requires cryptographic proof and immutability, not just authorization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using write-once storage and digitally signing each log entry

Write-once storage (e.g., WORM media or append-only filesystems) prevents any modification or deletion of log entries after they are written. Digitally signing each log entry ensures that any tampering can be detected by verifying the signature against the log data. Together, these provide non-repudiation and integrity, meeting compliance requirements for immutable audit logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encrypting logs during transmission only

    Why it's wrong here

    Encrypting only in transit leaves stored logs alterable and undetectable, so integrity over the retention year is unproven. It is tempting because transport encryption is a familiar control. Hashing or write-once storage with restricted access preserves log integrity at rest.

  • ✗

    Compressing logs to save space

    Why it's wrong here

    Compression reduces storage consumption but provides no integrity protection; logs can still be altered or deleted undetectably. It is tempting because compression is a genuine log-management practise for retention cost control, yet the requirement here is tamper evidence, which hashing or write-once storage delivers.

  • ✗

    Storing logs on a standard file server with restricted permissions

    Why it's wrong here

    Restricted permissions rely on access control alone, so a compromised administrator account or filesystem-level tampering leaves no cryptographic evidence of modification. It is tempting as low-cost centralised storage, and would be correct for non-repudiation-free retention where the threat model excludes privileged insiders.

  • ✓

    Using write-once storage and digitally signing each log entry

    Why this is correct

    Write-once storage prevents alteration or deletion of log records for the full retention period, while digital signatures let auditors verify each entry's authenticity and detect tampering. Together they satisfy the one-year integrity requirement, unlike practices that merely centralise, encrypt, or back up logs without guaranteeing immutability.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.