Courseiva

CCSP Cloud Security Operations Practice Question

After a security incident involving a compromised access key, a security engineer needs to collect forensic evidence from the cloud environment. Which of the following actions would be most useful for determining the timeline of the compromise?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reviewing cloud audit logs for the compromised key

Cloud audit logs contain detailed records of all API calls, including the identity, timestamp, and source IP. Analyzing these logs helps establish the timeline of when the key was used.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Taking a memory dump of the compute instance

    Why it's wrong here

    A memory dump captures volatile process state on one instance, not the credential's API activity across the account, so it cannot date the compromise. It tempts for host-level malware forensics, but access logs establish when the key was used.

  • ✓

    Reviewing cloud audit logs for the compromised key

    Why this is correct

    Cloud audit logs record every API call made with the compromised access key, including timestamps, source IPs and requested actions. This chronological record directly establishes when the key was first misused and the sequence of attacker activity, satisfying the need to determine the compromise timeline.

  • ✗

    Analyzing network flow logs for data exfiltration

    Why it's wrong here

    Flow logs show traffic metadata such as volumes and destinations, revealing exfiltration but not the credential's authentication events that mark compromise onset. They tempt for network forensics, yet access logging supplies the timeline of key usage.

  • ✗

    Checking configuration management logs for resource changes

    Why it's wrong here

    Configuration management logs record resource changes, not API calls made with the compromised key, so they cannot establish when the credential was used. They tempt for change auditing, but CloudTrail-style access logs provide the authentication timeline.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.