CCSP Cloud Audit Logging Practice Question
A security engineer needs to ensure that all API calls made to cloud resources are logged for auditing. Which cloud auditing feature should be enabled to capture management and data events?
⚠ Common exam trap
CCSP often tests the confusion between monitoring/logging services (operational) and audit logging services (compliance/auditing), so candidates who pick monitoring or threat detection fall into the trap.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud audit logging service
Cloud audit logging service (e.g., AWS CloudTrail, Azure Activity Log, GCP Cloud Audit Logs) is the correct feature because it captures API calls made to cloud resources, including management and data events, for auditing purposes. It records who made the call, when, from where, and what was done, providing the necessary audit trail. This is the standard service for logging API activity across cloud providers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud monitoring and logging service
Why it's wrong here
Generic monitoring and logging captures metrics and platform logs, not the per-API-call audit trail of management and data events the scenario requires. CloudTrail-style auditing is the correct choice; monitoring suits performance visibility and alerting rather than recording who invoked which resource API.
- ✗
Configuration management service
Why it's wrong here
Configuration management services enforce and track resource state, such as desired settings and drift, rather than recording API invocations. Auditing management and data events needs an audit trail service; configuration management would be chosen to remediate or detect configuration drift, not to log every API call.
- ✗
Threat detection service
Why it's wrong here
Threat detection services analyse activity for malicious patterns and raise findings, but they do not themselves provide the complete, queryable record of management and data events required for auditing. An audit trail service is correct; threat detection fits identifying compromised credentials or anomalous behaviour, not evidentiary logging.
- ✓
Cloud audit logging service
Why this is correct
A cloud audit logging service records API activity, capturing both management events (control-plane operations) and data events (object-level reads and writes) with caller identity, timestamp and source IP. Enabling it satisfies the requirement to log all API calls for auditing.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.