C100DBA Server Administration Practice Question
A security audit requires that sensitive document data contained in query parameters must not be written to the MongoDB system logs. Which server configuration setting should be enabled?
⚠ Common exam trap
Candidates often confuse log redaction configuration parameters with general verbosity settings or audit filters, failing to recall the exact setting name.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
security.redactClientLogData: true
Security administration involves protecting data at rest, in transit, and in logs. Log redaction is a feature that prevents sensitive information, like the contents of a 'find' filter or an 'insert' document, from appearing in the server logs. This is essential for compliance with regulations like GDPR, HIPAA, or PCI-DSS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
security.authorization: enabled
Why it's wrong here
This setting enables Role-Based Access Control (RBAC), which requires users to authenticate before accessing data. While it is a fundamental security practice, it does not affect the content of the logs. Sensitive data could still be logged by the profiler or system logs if other settings are not adjusted.
- ✓
security.redactClientLogData: true
Why this is correct
Enabling 'redactClientLogData' ensures that the mongod process removes potentially sensitive information from log messages before they are written to disk. This specifically targets the data within commands, such as query filters or document fields, replacing them with placeholders to prevent data leaks through log files.
- ✗
operationProfiling.mode: off
Why it's wrong here
Disabling the profiler prevents slow queries from being recorded in the 'system.profile' collection, but it does not stop the general system log (mongod.log) from recording error messages or other diagnostic info that might contain sensitive data. Redaction is a more comprehensive approach for log security across the entire system.
- ✗
storage.wiredTiger.collectionConfig.blockCompressor: zlib
Why it's wrong here
This configuration defines the compression algorithm used for data stored on disk within the collection files. It has no impact on the visibility of data within the server's plain-text log files. Log redaction and disk compression are unrelated administrative tasks serving completely different purposes in a MongoDB environment.
About these practice questions
One of 222 original C100DBA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official MongoDB exam blueprint
This C100DBA practice question is part of Courseiva's free MongoDB certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C100DBA exam.