Courseiva
mediumMultiple Choice

CS0-003 Practice Question: Implementing a security monitoring solution for…

A company is implementing a security monitoring solution for its cloud infrastructure. The security team wants to detect attempts to disable logging on critical instances. Which of the following should be configured?

⚠ Common exam trap

The CS0-004 exam often tests the distinction between data plane monitoring (VPC Flow Logs) and control plane monitoring (CloudTrail), leading candidates to choose VPC Flow Logs because they think 'logging' refers to network logs rather than API activity logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CloudTrail (API logging)

CloudTrail (API logging) is the correct choice because it records all API calls made to the cloud provider's control plane, including actions that modify logging configurations such as disabling or stopping logging on critical instances. By monitoring CloudTrail events, the security team can detect attempts to disable logging via API calls like `StopLogging` or `UpdateTrail`, enabling timely alerting and response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs record IP traffic information for network interfaces within a Virtual Private Cloud (VPC), detailing source/destination IP addresses, ports, protocols, and traffic volume. While crucial for network forensics and security group analysis, they specifically monitor data plane network activity. They do not log control plane actions, such as administrative API calls that modify cloud service configurations like logging settings.

  • ✓

    CloudTrail (API logging)

    Why this is correct

    CloudTrail is a critical service designed to record API calls made to the cloud provider's services, whether by users, roles, or other services. It provides a comprehensive audit trail of management plane activities, including creating, modifying, or deleting resources and configurations. This makes it ideal for detecting unauthorized changes to security monitoring solutions, such as disabling or altering logging configurations, as these actions are performed via API calls.

  • ✗

    Host-based intrusion detection (HIDS)

    Why it's wrong here

    Host-based Intrusion Detection Systems (HIDS) operate by monitoring activity directly on individual servers or endpoints, analyzing system logs, file integrity, and process execution. While effective for detecting local compromises, unauthorized file modifications, or suspicious processes on a specific virtual machine, HIDS are confined to the operating system level. They lack visibility into the cloud provider's underlying infrastructure or the API calls made to manage cloud services, which occur at a higher abstraction layer.

  • ✗

    Scheduled vulnerability scans

    Why it's wrong here

    Scheduled vulnerability scans are proactive security assessments designed to identify known security weaknesses, misconfigurations, or outdated software versions within systems and applications. These scans are typically performed periodically and focus on identifying potential attack vectors. They are not real-time monitoring solutions and therefore cannot detect immediate, dynamic changes to cloud service configurations, such as an attacker disabling or modifying logging settings as they happen.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.