CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 90


Which of the following ensures old log data is not overwritten?

Show Answer
Correct Answer: A

Log retention ensures that old log data is not overwritten by configuring the system to preserve logs for a specified duration. This practice helps organizations maintain historical logs for analysis, troubleshooting, compliance, and other needs. By defining and implementing log retention policies, logs are systematically stored and protected from being overwritten or automatically deleted, ensuring availability for future reference.

Discussion

17 comments
Sign in to comment
DERCHEF2009Option: D
Sep 4, 2022

shoud be D

jackdryan
May 11, 2023

D is correct

CoolwaterOption: D
Oct 24, 2022

For those who are saying "Retention " = retention is something which we define as a date or week or month or year for saving logs or any other kind of data . after the defined period, the data will be overwritten . lets take CCTV data storage as an example. if we are configuring the storage settings for 1 moth , it will only keep 1 month of recent video footage , the old footages will be overwritten . Ans is D

georgegeorge125487Option: A
Aug 16, 2023

Only log retention exists in CISSP study guide.

Dee83Option: A
Jan 24, 2023

A. Log retention Log retention is the practice of keeping log data for a certain period of time. It ensures that old log data is not overwritten, and it can be used for analysis, troubleshooting, and compliance purposes. The retention period can be set according to the organization's needs, and it can be defined as a number of days, weeks, or months.

InclusiveSTEAMOption: A
Oct 9, 2023

The correct answer is A The answer that best ensures old log data is not overwritten is log retention, option A. Log retention policies and procedures specifically preserve and archive logs for compliance and analysis needs, preventing them from being purged or overwritten. Syslog may provide centralized logging but does not itself retain old logs. Increasing log file size allows storing more events but does not guarantee retaining old data. While log preservation is close, log retention is the most precise term for maintaining archives of old log data.

FiredragonOption: D
Nov 11, 2022

D. https://csrc.nist.gov/glossary/term/log_preservation https://csrc.nist.gov/glossary/term/log_retention

byndOption: C
Nov 16, 2022

Log retention and preservation is more concept. But C is the solution.

Bach1968Option: A
Jul 5, 2023

i have to go with A. Log retention. Log retention refers to the practice of storing log data for a specified period of time. It ensures that old log data is not overwritten or deleted, allowing for historical analysis, forensic investigations, compliance requirements, and detection of security incidents. By defining and implementing log retention policies, organizations can establish guidelines for how long log data should be retained based on regulatory requirements, business needs, and security considerations. This helps in preserving log data for future reference and maintaining a comprehensive audit trail of system activities. this is why ? Increasing the log file size does not ensure that old log data is not overwritten. It simply allows for a larger storage capacity for log data. However, once the log file reaches its maximum size, new log entries may still overwrite the oldest entries. On the other hand, log retention is a specific practice of preserving log data for a specified period of time, ensuring that it is not overwritten or deleted. This allows for the availability of historical logs for analysis, compliance, and security purposes. Therefore, log retention is the appropriate answer to ensure that old log data is not overwritten.

JamatiOption: D
Nov 8, 2022

Answer is D. As already stated, retention has an end date. Preservation can be forever. Implementing a Syslog falls under both log retention and preservation. As a CISO, we don't care whether it's Syslog, Qradar, Splunk, or Slack, as long as it meets the objectives and business requirements.

Bach1968Option: A
Jul 5, 2023

forgot to choose

LalithW
Oct 3, 2023

It says about log overwritten. SO increasing log file size is correct.

KyankaOption: A
Mar 4, 2024

Think like a manager/policy creator: Answer is A.

janvandermerwerOption: A
Jul 20, 2023

A is correct

MShaabanOption: A
Aug 5, 2023

I would go with A

HongjunOption: D
Mar 3, 2024

The organization’s policies and procedures should also address the preservation of original logs. Many organizations send copies of network traffic logs to centralized devices, as well as use tools that analyze and interpret network traffic. So D is correct.

john_boogiemanOption: A
Mar 27, 2024

From OSG: 16. Gavin is considering altering his organization’s 'log retention' policy to delete logs at the end of each day. What is the most important reason that he should avoid this approach? A. An incident may not be discovered for several days and valuable evidence could be lost.

MP26Option: A
Apr 20, 2024

Log retention prevents to logs to be overwritten. If retention time is to short than preservation will not help because it keeps overwritten and not completer. Other advantage. It is easier and cheaper. A: is my answer