ISC2 Governance, Risk and Compliance (CGRC) Practice Question
A project team requests a configuration change that would enable previously disabled debug-level logging on an Internet-facing application to assist with troubleshooting. While evaluating the request, which consideration best addresses how the change could negatively affect the current security and privacy posture of the system?
Operations staff will require extra training to interpret the more verbose log format.
Nightly backups may take longer because of the increased log archive size.
Debug output may capture authentication tokens or sensitive user data that could be exposed in log files.
Additional storage hardware might be needed to accommodate the larger volume of log data.
When debug-level logging is enabled, applications frequently record detailed information such as full URLs, session identifiers, authentication tokens, input parameters, and user-supplied data. If those logs are stored insecurely or made accessible to attackers, the additional detail can disclose credentials or personally identifiable information, directly weakening confidentiality and privacy controls. The other considerations focus on operational impact-such as storage capacity, backup windows, or staff training-without presenting a primary threat to the system's security or privacy posture.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why does debug-level logging capture sensitive information like authentication tokens and user data?
Open an interactive chat with Bash
What measures can be taken to secure debug-level logs containing sensitive data?
Open an interactive chat with Bash
How does enabling debug-level logging affect a system's risk posture?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .