C100DBA Server Administration Practice Question
An administrator wants to audit all authentication attempts on a MongoDB Enterprise instance. Which feature should be configured to track these events?
⚠ Common exam trap
Examinees frequently confuse profiling with auditing, incorrectly selecting the database profiler when the question specifically demands tracking security and authentication events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set up an 'auditLog' destination in the YAML configuration.
The auditing system in MongoDB Enterprise is essential for compliance and security monitoring. By configuring the audit log to capture events related to authentication and authorization, administrators gain visibility into who is accessing the database and what actions they are performing. This is crucial for forensic analysis, detecting unauthorized access attempts, and satisfying regulatory requirements that mandate detailed record-keeping for all database interactions within a production environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable 'logLevel' to 5 in the configuration.
Why it's wrong here
Increasing the log level to 5 provides extremely verbose diagnostic information about internal processes. While it might include some security info, it is not a structured or reliable way to track authentication and authorization events, and it can negatively impact performance due to the overwhelming volume of data.
- ✓
Set up an 'auditLog' destination in the YAML configuration.
Why this is correct
The 'auditLog' configuration is the designated feature for recording database activities, including authentication successes and failures. By specifying a destination like a file or syslog and defining the filter, administrators can ensure that all relevant security events are recorded in a structured JSON format for easy analysis.
- ✗
Use the 'mongostat' utility.
Why it's wrong here
The 'mongostat' utility is a command-line tool for monitoring real-time performance metrics like inserts, updates, and deletes. It is not designed for security auditing and cannot track authentication attempts or record historical logs of user access, making it unsuitable for security and compliance monitoring needs.
- ✗
Enable 'net.ssl.mode' to 'requireSSL'.
Why it's wrong here
Requiring SSL ensures that the connection between the client and server is encrypted. While this is a critical security practice, it does not provide an audit log of who is authenticating or what actions they take. It is a transport security feature, not a monitoring or logging feature.
About these practice questions
One of 222 original C100DBA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official MongoDB exam blueprint
This C100DBA practice question is part of Courseiva's free MongoDB certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the C100DBA exam.