ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A healthcare provider is moving its patient records system to the public cloud. Regulations require that every data-access event be auditable for seven years and that the organization be able to prove the logs have not been altered after they were written. Which cloud logging design BEST satisfies the requirements for auditability, traceability, chain of custody, and non-repudiation?
Keep verbose application logs on each virtual machine's encrypted local disks for the full retention period.
Replicate logs to an in-memory cache cluster to accelerate forensic analysis queries.
Forward all audit events to a provider-managed logging service that digitally signs each log file and stores it in write-once object-lock storage.
Send logs to a self-hosted virtual machine, rotate them daily, and restrict SSH access to administrators only.
Storing logs in a cloud-native service that automatically timestamps, cryptographically signs each file, and places it in immutable (write-once) storage provides strong evidence that the records are complete and unmodified. The digital signature and hash enable later verification for non-repudiation, while immutability enforces chain of custody. Merely rotating logs on a VM, using an in-memory cache, or relying solely on disk encryption protects availability or confidentiality but does not give the same level of integrity assurance or legal defensibility.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is object-lock storage in the context of cloud logging?
Open an interactive chat with Bash
How does digital signing enhance the integrity of audit logs?
Open an interactive chat with Bash
Why is immutability crucial for audit logs in regulated environments?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .