easyMultiple ChoiceObjective-mapped
CCSP Practice Question: A cloud security administrator needs to ensure…
A cloud security administrator needs to ensure that all API calls to the cloud provider's management plane are logged for audit purposes. Which service should be enabled?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud audit logging service
The cloud audit logging service (e.g., AWS CloudTrail) records API calls for auditing. Option A (monitoring) focuses on performance metrics. Option B (configuration) tracks resource changes but not all API calls. Option D (threat detection) is for security threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud configuration service
Why it's wrong here
Configuration services track resource state, not all API actions.
- ✗
Cloud threat detection service
Why it's wrong here
Threat detection services analyze logs for threats, they do not generate the logs.
- ✓
Cloud audit logging service
Why this is correct
Audit logs capture all management plane API calls.
- ✗
Cloud monitoring service
Why it's wrong here
Monitoring services track performance, not API calls.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.