nerdexam
CompTIA

CV0-002 · Question #464

A law firm wants to limit log retention to the minimum required by law and regulation. Which of the following is the engineer most likely to do FIRST?

The correct answer is B. Configure all systems in scope to log activities in support of company policies.. To limit log retention to the minimum required by law, the engineer must first configure systems to log activities based on established company policies and legal obligations.

Security

Question

A law firm wants to limit log retention to the minimum required by law and regulation. Which of the following is the engineer most likely to do FIRST?

Options

  • ACreate a 2GB external hard drive to log all activities.
  • BConfigure all systems in scope to log activities in support of company policies.
  • CConfigure a daily rotation on all workstations to limit the logs' discovery scope.
  • DDeduplicate, compress, and encrypt all logs before archiving them.

How the community answered

(36 responses)
  • A
    8% (3)
  • B
    75% (27)
  • C
    3% (1)
  • D
    14% (5)

Why each option

To limit log retention to the minimum required by law, the engineer must first configure systems to log activities based on established company policies and legal obligations.

ACreate a 2GB external hard drive to log all activities.

Creating a small, external hard drive is an insecure, non-scalable, and inadequate logging solution for a law firm, and it does not define the necessary log content for compliance.

BConfigure all systems in scope to log activities in support of company policies.Correct

Before an organization can limit log retention, it must first define *what* information needs to be logged to meet legal and regulatory requirements. Configuring all in-scope systems to capture these specific activities according to company policies provides the foundational data set that will then be subject to retention guidelines.

CConfigure a daily rotation on all workstations to limit the logs' discovery scope.

Configuring daily log rotation on workstations addresses log volume and disk space, but it does not establish *what* logs are needed for compliance or provide a centralized, auditable log management strategy.

DDeduplicate, compress, and encrypt all logs before archiving them.

Deduplicating, compressing, and encrypting logs are optimization and security measures applied *after* logs have been collected and identified for archiving, not the initial step in defining retention requirements.

Concept tested: Establishing logging requirements based on compliance

Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-92.pdf

Topics

#Log management#Compliance#Data retention#Security logging

Community Discussion

No community discussion yet for this question.

Full CV0-002 Practice