CompTIA Security+ (SY0-701)Security OperationsMedium
A compliance officer requires that all authentication logs be retained for a minimum of seven years to satisfy regulatory audit requirements, even though the SIEM's active storage only holds 90 days of searchable data. Which practice should the organization implement to meet this requirement?
- AReduce the SIEM alert threshold to generate fewer logs
- BDisable logging for low-risk systems to save storage space
- CArchive logs to long-term cold storage per a defined retention policy
- DConfigure the SIEM to overwrite logs older than 90 days
Show answer & explanationAnswer & explanation
Correct answer: C. Archive logs to long-term cold storage per a defined retention policy
A log retention policy defines how long logs must be kept and where, requiring older logs be archived to durable long-term storage to meet compliance timeframes beyond the SIEM's active retention window.
Why the other options are wrong
- A. Reducing alert thresholds affects alert volume, not log retention duration.
- B. Disabling logging would violate the retention and audit requirements entirely.
- D. Overwriting logs after 90 days directly violates the 7-year retention mandate.
Log Retention Policy
A documented policy defining how long log data must be preserved and how it is stored, often driven by regulatory or legal requirements.
- Active SIEM storage is typically short-term for fast search
- Long-term retention often uses cheaper cold/archive storage
- Retention periods driven by regulations like PCI DSS, HIPAA, or legal hold
Memory trick: Old logs don't die, they retire to the archive vault.