CCSP Cloud Security Operations Practice Question
After a security incident involving a compromised access key, a security engineer needs to collect forensic evidence from the cloud environment. Which of the following actions would be most useful for determining the timeline of the compromise?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reviewing cloud audit logs for the compromised key
Cloud audit logs contain detailed records of all API calls, including the identity, timestamp, and source IP. Analyzing these logs helps establish the timeline of when the key was used.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Taking a memory dump of the compute instance
Why it's wrong here
A memory dump captures volatile process state on one instance, not the credential's API activity across the account, so it cannot date the compromise. It tempts for host-level malware forensics, but access logs establish when the key was used.
- ✓
Reviewing cloud audit logs for the compromised key
Why this is correct
Cloud audit logs record every API call made with the compromised access key, including timestamps, source IPs and requested actions. This chronological record directly establishes when the key was first misused and the sequence of attacker activity, satisfying the need to determine the compromise timeline.
- ✗
Analyzing network flow logs for data exfiltration
Why it's wrong here
Flow logs show traffic metadata such as volumes and destinations, revealing exfiltration but not the credential's authentication events that mark compromise onset. They tempt for network forensics, yet access logging supplies the timeline of key usage.
- ✗
Checking configuration management logs for resource changes
Why it's wrong here
Configuration management logs record resource changes, not API calls made with the compromised key, so they cannot establish when the credential was used. They tempt for change auditing, but CloudTrail-style access logs provide the authentication timeline.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.