CCSP Cloud Security Operations Practice Question
A cloud security engineer needs to ensure that logs from multiple AWS accounts are centrally stored in a security account for analysis. Which TWO services can be used to aggregate logs across accounts? (Choose two.)
⚠ Common exam trap
A common trap is mixing up services that aggregate raw logs (CloudWatch Logs, S3) with those that aggregate security findings or metadata (Security Hub, GuardDuty). Candidates may incorrectly select Security Hub or GuardDuty for log aggregation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Amazon CloudWatch Logs with cross-account subscription filters
Option A is correct because CloudWatch Logs supports cross-account subscription filters, which allow a destination account (the security account) to receive real-time log events from source accounts via a destination Logs resource policy and a subscription filter, enabling centralized log aggregation. Option D is correct because Amazon S3 with cross-account bucket policies lets multiple accounts write their logs (e.g., via PutObject permissions in the bucket policy) into a single central bucket owned by the security account, which is a common pattern for centralized log storage and analysis. Option B (AWS Config) is a configuration compliance and resource inventory service, not a cross-account log aggregation mechanism. Option C (AWS Security Hub) aggregates security findings and compliance checks across accounts, not raw logs. Option E (Amazon GuardDuty) is a threat detection service that generates findings, not a general log aggregation service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Amazon CloudWatch Logs with cross-account subscription filters
Why this is correct
CloudWatch Logs cross-account subscription filters stream log events in near real time from source accounts to a Kinesis Data Streams or Lambda destination in the security account, satisfying the centralised aggregation requirement without polling. This native mechanism avoids duplicating log groups per account, unlike resource-policy-based sharing.
- ✗
AWS Config
Why it's wrong here
AWS Config records resource configuration changes and evaluates compliance against rules; it does not aggregate CloudTrail or service logs into a central account. It is tempting because it provides cross-account, multi-region visibility of resource state, which suits configuration drift auditing — not the log centralisation this scenario requires.
- ✗
AWS Security Hub
Why it's wrong here
AWS Security Hub aggregates security findings and compliance posture across accounts, not raw log data. It cannot centralise CloudTrail or VPC flow logs for analysis. It is tempting because it provides cross-account visibility, and would be correct when the requirement is consolidated findings from GuardDuty, Inspector or Config, rather than log storage.
- ✓
Amazon S3 with cross-account bucket policies
Why this is correct
Amazon S3 with cross-account bucket policies satisfies the centralised storage constraint: each source account writes its logs directly into a bucket owned by the security account, with the bucket policy granting cross-account `s3:PutObject` permission. This aggregates logs without duplicating infrastructure, and the security account retains sole ownership and control of the collected data.
- ✗
Amazon GuardDuty
Why it's wrong here
Amazon GuardDuty generates threat findings from sources such as CloudTrail, VPC Flow Logs and DNS logs; it does not aggregate raw logs into a central security account. It is tempting because GuardDuty is a cross-account security service, and it would be the right choice when the requirement is centralised threat detection rather than log storage.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.