Courseiva

CCSP Cloud Audit Logging Practice Question

A security engineer needs to ensure that all API calls made to cloud resources are logged for auditing. Which cloud auditing feature should be enabled to capture management and data events?

⚠ Common exam trap

CCSP often tests the confusion between monitoring/logging services (operational) and audit logging services (compliance/auditing), so candidates who pick monitoring or threat detection fall into the trap.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud audit logging service

Cloud audit logging service (e.g., AWS CloudTrail, Azure Activity Log, GCP Cloud Audit Logs) is the correct feature because it captures API calls made to cloud resources, including management and data events, for auditing purposes. It records who made the call, when, from where, and what was done, providing the necessary audit trail. This is the standard service for logging API activity across cloud providers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud monitoring and logging service

    Why it's wrong here

    Generic monitoring and logging captures metrics and platform logs, not the per-API-call audit trail of management and data events the scenario requires. CloudTrail-style auditing is the correct choice; monitoring suits performance visibility and alerting rather than recording who invoked which resource API.

  • ✗

    Configuration management service

    Why it's wrong here

    Configuration management services enforce and track resource state, such as desired settings and drift, rather than recording API invocations. Auditing management and data events needs an audit trail service; configuration management would be chosen to remediate or detect configuration drift, not to log every API call.

  • ✗

    Threat detection service

    Why it's wrong here

    Threat detection services analyse activity for malicious patterns and raise findings, but they do not themselves provide the complete, queryable record of management and data events required for auditing. An audit trail service is correct; threat detection fits identifying compromised credentials or anomalous behaviour, not evidentiary logging.

  • ✓

    Cloud audit logging service

    Why this is correct

    A cloud audit logging service records API activity, capturing both management events (control-plane operations) and data events (object-level reads and writes) with caller identity, timestamp and source IP. Enabling it satisfies the requirement to log all API calls for auditing.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.