hardMultiple Choice
CCSP Practice Question: A cloud security team needs to implement a…
A cloud security team needs to implement a logging strategy that captures user activity, API calls, and resource changes across multiple cloud services. The logs must be tamper-proof and retained for at least one year. Which combination of actions best meets these requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Centralize logs into a dedicated log archive account with write-once-read-many (WORM) storage and enable anomaly detection alerts.
Centralizing logs into a dedicated log archive account with WORM (write-once-read-many) storage ensures tamper-proof retention for at least one year, and enabling anomaly detection alerts provides real-time security monitoring. Option A is incorrect because while streaming to a SIEM is good practice, retaining raw logs on standard storage does not guarantee immutability; logs could be modified or deleted. Option B is incorrect because encrypting logs at rest only protects confidentiality, not integrity; a centralized log management system without WORM may allow tampering. Option C is incorrect because using separate logging accounts for each service creates silos, increases management complexity, and does not inherently provide tamper-proof storage; logs could be altered within individual accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stream all logs to a Security Information and Event Management (SIEM) system and retain raw logs for one year on standard storage.
Why it's wrong here
Streaming to a SIEM gives near-real-time detection, but raw logs on standard storage remain mutable and deletable, so tamper-proofing fails. It is tempting because SIEM ingestion is the usual answer for cross-service visibility, and it would be correct if the requirement were correlation and alerting rather than immutability.
- ✗
Enable logging for all services, encrypt logs at rest, and store them in a centralized log management system.
Why it's wrong here
Encrypting logs at rest and centralising them does not make them tamper-proof; a privileged actor with write access can still alter or delete them, and retention is not enforced. It is tempting because encryption and centralisation are standard hardening steps, and it would be correct if the requirement were confidentiality rather than immutability.
- ✗
Use separate logging accounts for each cloud service and retain logs in their native format.
Why it's wrong here
Separate logging accounts per service fragment the audit trail and native-format retention provides no cryptographic immutability or enforced one-year lifecycle. It is tempting because account isolation limits blast radius, and it would be correct when regulatory separation of duties, not tamper-proofing, is the driver.
- ✓
Centralize logs into a dedicated log archive account with write-once-read-many (WORM) storage and enable anomaly detection alerts.
Why this is correct
WORM storage enforces immutability, so archived logs cannot be altered or deleted, satisfying tamper-proofing, while a dedicated archive account isolates them from production credentials. Centralisation plus one-year retention meets the stated scope across multiple cloud services.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.