CCSP Cloud Security Operations Practice Question
A cloud security engineer needs to ensure that logs from multiple AWS accounts are centrally stored in a security account for analysis. Which TWO services can be used to aggregate logs across accounts? (Choose two.)
⚠ Common exam trap
A common trap is mixing up services that aggregate raw logs (CloudWatch Logs, S3) with those that aggregate security findings or metadata (Security Hub, GuardDuty). Candidates may incorrectly select Security Hub or GuardDuty for log aggregation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch Logs with cross-account subscription filters
Amazon CloudWatch Logs supports cross-account subscription filters, which allow you to stream log data from log groups in multiple source accounts to a single destination (e.g., a Kinesis stream or Lambda function) in a central security account. This enables real-time aggregation of logs across accounts. Amazon S3 with cross-account bucket policies allows you to write logs from multiple accounts to a central S3 bucket by granting write permissions to source accounts via bucket policies. Both services can aggregate logs across accounts, while AWS Config, Security Hub, and GuardDuty aggregate configuration items and security findings, not raw logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon CloudWatch Logs with cross-account subscription filters
Why this is correct
CloudWatch Logs can forward log events to a central account via subscription filters.
- ✗
AWS Config
Why it's wrong here
Config records configuration changes, not logs.
- ✗
AWS Security Hub
Why it's wrong here
Security Hub aggregates findings, not raw logs.
- ✓
Amazon S3 with cross-account bucket policies
Why this is correct
S3 buckets can be configured to accept log deliveries from multiple accounts.
- ✗
Amazon GuardDuty
Why it's wrong here
GuardDuty generates findings, not logs.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.