nerdexam
(ISC)2

CCSP · Question #44

Log data should be protected ____________.

The correct answer is B. At least at the same sensitivity level as the systems from which it was collected. Log data should be protected at least at the same sensitivity level as the systems from which it was collected to prevent unauthorized access or tampering with critical security information.

Submitted by satoshi_tk· Apr 18, 2026Cloud Data Security

Question

Log data should be protected ____________.

Options

  • AOne level below the sensitivity level of the systems from which it was collected
  • BAt least at the same sensitivity level as the systems from which it was collected
  • CWith encryption in transit, at rest, and in use
  • DAccording to NIST guidelines

How the community answered

(37 responses)
  • B
    92% (34)
  • C
    3% (1)
  • D
    5% (2)

Why each option

Log data should be protected at least at the same sensitivity level as the systems from which it was collected to prevent unauthorized access or tampering with critical security information.

AOne level below the sensitivity level of the systems from which it was collected

Protecting log data at a lower sensitivity level than the source systems would make it a weaker link, allowing attackers to potentially access or tamper with logs more easily, undermining security monitoring and incident response.

BAt least at the same sensitivity level as the systems from which it was collectedCorrect

Log data often contains sensitive information about system activities, security events, and user actions, which can be as sensitive as, or even more sensitive than, the data on the systems themselves. Protecting it at least at the same sensitivity level ensures that adversaries cannot easily compromise the logs to hide their tracks or gain insights into system weaknesses.

CWith encryption in transit, at rest, and in use

While encryption in transit, at rest, and in use is an important method of protection, it describes a technical control rather than the sensitivity level requirement for protection, and it might not be universally required for all log data across all sensitivity levels.

DAccording to NIST guidelines

'According to NIST guidelines' is too general; while NIST provides excellent guidance, the most specific and accurate principle among the choices for log data protection sensitivity is comparing it to the source system's sensitivity.

Concept tested: Log data protection sensitivity

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-92.pdf

Topics

#Log data protection#Data sensitivity#Data classification

Community Discussion

No community discussion yet for this question.

Full CCSP Practice