A security audit requires that sensitive document data contained in query parameters must not be written to the MongoDB system logs. Which server configuration setting should be enabled?
Enabling 'redactClientLogData' ensures that the mongod process removes potentially sensitive information from log messages before they are written to disk. This specifically targets the data within commands, such as query filters or document fields, replacing them with placeholders to prevent data leaks through log files.
Why this answer
Security administration involves protecting data at rest, in transit, and in logs. Log redaction is a feature that prevents sensitive information, like the contents of a 'find' filter or an 'insert' document, from appearing in the server logs. This is essential for compliance with regulations like GDPR, HIPAA, or PCI-DSS.
Exam trap
Candidates often confuse log redaction configuration parameters with general verbosity settings or audit filters, failing to recall the exact setting name.