Compliance requires the city to keep authentication logs for a defined period and then delete them. What should ops configure to balance that mandate with cost and privacy?
Select an answer to reveal the explanation.
Short Explanation
Retention is the library due-date for logs: keep them long enough for auditors, then clear the shelf so cost and privacy don’t explode. A retention policy encodes that keep-then-delete rule for authentication logs instead of hoping someone remembers. Forever-and-hopeful storage is neither compliant nor cheap.
Full Explanation
Log retention policies define how long observability data is stored and when it is deleted or moved, balancing compliance, cost, and privacy. Authentication logs often have explicit regulatory retention windows; indefinite retention increases storage spend and exposure risk. Operators should configure retention (and related lifecycle rules) so required evidence exists for the mandate and is removed afterward.