Courseiva

CCSP Cloud Security Operations Practice Question

A cloud security engineer needs to ensure that logs from multiple AWS accounts are centrally stored in a security account for analysis. Which TWO services can be used to aggregate logs across accounts? (Choose two.)

⚠ Common exam trap

A common trap is mixing up services that aggregate raw logs (CloudWatch Logs, S3) with those that aggregate security findings or metadata (Security Hub, GuardDuty). Candidates may incorrectly select Security Hub or GuardDuty for log aggregation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Amazon CloudWatch Logs with cross-account subscription filters

Option A is correct because CloudWatch Logs supports cross-account subscription filters, which allow a destination account (the security account) to receive real-time log events from source accounts via a destination Logs resource policy and a subscription filter, enabling centralized log aggregation. Option D is correct because Amazon S3 with cross-account bucket policies lets multiple accounts write their logs (e.g., via PutObject permissions in the bucket policy) into a single central bucket owned by the security account, which is a common pattern for centralized log storage and analysis. Option B (AWS Config) is a configuration compliance and resource inventory service, not a cross-account log aggregation mechanism. Option C (AWS Security Hub) aggregates security findings and compliance checks across accounts, not raw logs. Option E (Amazon GuardDuty) is a threat detection service that generates findings, not a general log aggregation service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Amazon CloudWatch Logs with cross-account subscription filters

    Why this is correct

    CloudWatch Logs cross-account subscription filters stream log events in near real time from source accounts to a Kinesis Data Streams or Lambda destination in the security account, satisfying the centralised aggregation requirement without polling. This native mechanism avoids duplicating log groups per account, unlike resource-policy-based sharing.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config records resource configuration changes and evaluates compliance against rules; it does not aggregate CloudTrail or service logs into a central account. It is tempting because it provides cross-account, multi-region visibility of resource state, which suits configuration drift auditing — not the log centralisation this scenario requires.

  • ✗

    AWS Security Hub

    Why it's wrong here

    AWS Security Hub aggregates security findings and compliance posture across accounts, not raw log data. It cannot centralise CloudTrail or VPC flow logs for analysis. It is tempting because it provides cross-account visibility, and would be correct when the requirement is consolidated findings from GuardDuty, Inspector or Config, rather than log storage.

  • ✓

    Amazon S3 with cross-account bucket policies

    Why this is correct

    Amazon S3 with cross-account bucket policies satisfies the centralised storage constraint: each source account writes its logs directly into a bucket owned by the security account, with the bucket policy granting cross-account `s3:PutObject` permission. This aggregates logs without duplicating infrastructure, and the security account retains sole ownership and control of the collected data.

  • ✗

    Amazon GuardDuty

    Why it's wrong here

    Amazon GuardDuty generates threat findings from sources such as CloudTrail, VPC Flow Logs and DNS logs; it does not aggregate raw logs into a central security account. It is tempting because GuardDuty is a cross-account security service, and it would be the right choice when the requirement is centralised threat detection rather than log storage.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.