easyMultiple Choice
CCSP Practice Question: A cloud security administrator needs to ensure…
A cloud security administrator needs to ensure that all API calls to the cloud provider's management plane are logged for audit purposes. Which service should be enabled?
⚠ Common exam trap
CCSP often tests the confusion between audit logging (CloudTrail) and monitoring (CloudWatch) or configuration (Config); candidates must select the service specifically for API audit logging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud audit logging service
The cloud audit logging service should be enabled to log all API calls to the management plane for audit purposes. This service captures API activity, including who made the call, when, and from where, providing an audit trail. It is specifically designed for compliance and security auditing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud configuration service
Why it's wrong here
Configuration services record resource state and drift, not the API call history the auditor needs. They are the right tool for detecting unauthorised setting changes, but management-plane audit logging requires a dedicated trail service capturing caller identity, timestamp and request parameters.
- ✗
Cloud threat detection service
Why it's wrong here
Threat detection analyses activity for malicious patterns but consumes logs rather than producing the complete, immutable audit record required. It is the correct choice when the goal is identifying compromised credentials or anomalous behaviour, not satisfying an audit requirement for every management-plane call.
- ✓
Cloud audit logging service
Why this is correct
Cloud audit logging captures control-plane API activity, recording who invoked which management operation, when and from where. Enabling it satisfies the audit requirement because management-plane calls are logged natively, unlike data-plane or application-level logging services.
- ✗
Cloud monitoring service
Why it's wrong here
Monitoring services track metrics, availability and performance thresholds; they do not retain per-call API audit records with caller identity. Monitoring is correct for alerting on resource health, whereas audit logging demands a dedicated trail capturing every management-plane request.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.