Certified Information Systems Security Professional CISSP · Free Practice Question Medium
Question 110
An auditor reviewing an organization’s security policies finds that security logs are not retained for the required period under regulatory guidelines. What should be the NEXT step?
- A Immediately delete old logs that exceed storage limits to free up space for new logs.
- B Justify the current retention period by demonstrating that no recent incidents have required older logs for investigation.
- C Increase log storage capacity to meet retention requirements, even if budget constraints delay implementation.
- D Develop and implement a log retention policy that aligns with compliance requirements.
Reveal correct answer
Correct answer: D
Explanation
OBJ. 6.5 - Implementing a log retention policy that meets regulatory requirements ensures compliance and supports forensic investigations. Deleting old logs may violate compliance regulations. Increasing storage capacity without addressing retention policies does not solve the issue. Ignoring the finding could result in legal penalties and hinder future investigations. A properly defined retention policy ensures security logs are available for audits and incident response. For support or reporting issues, include Question ID: 67d9692c16b973cef867fcfc in your ticket. Thank you.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
