Courseiva
Cloud Security Operations →mediumMultiple Choice

CCSP Cloud Security Operations Practice Question

An organization ingests AWS CloudTrail logs into a centralized SIEM for correlation. They want to detect an attacker who exfiltrates data by downloading large volumes from an S3 bucket. Which SIEM correlation rule would best detect this?

⚠ Common exam trap

This exam often tests the distinction between detection of the exfiltration action itself (high volume of GetObject requests) versus precursor or unrelated events (failed logins, root usage, IAM creation), leading candidates to choose a rule that detects a different phase of the attack chain.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Alert on high volume of GetObject requests from a single IP

Exfiltration of data from S3 typically involves a high volume of GetObject API calls from a single source IP. A SIEM correlation rule that triggers on a threshold of GetObject requests from the same IP address directly detects this anomalous download behavior, which is a key indicator of data exfiltration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Alert on multiple failed login attempts

    Why it's wrong here

    Failed-login alerting targets authentication attacks such as brute force, not S3 object downloads; CloudTrail GetObject events carry no login failures. It is tempting because repeated failed logins are a classic SIEM rule, but detecting bulk data exfiltration requires correlating S3 data-access event volume per identity.

  • ✓

    Alert on high volume of GetObject requests from a single IP

    Why this is correct

    GetObject requests represent actual object downloads, so alerting when a single IP generates an abnormally high volume of them detects bulk data retrieval. Aggregating by source IP over a time window satisfies the exfiltration scenario, distinguishing sustained mass downloading from routine sporadic access.

  • ✗

    Alert on root account usage

    Why it's wrong here

    Root account usage flags privileged console or API activity, not bulk S3 object retrieval, so it cannot surface the exfiltration pattern. It is tempting because root activity is high-severity and rare, making it a valid rule for detecting account takeover or unauthorised administrative actions, but it does not correlate GetObject volume.

  • ✗

    Alert when a new IAM user is created

    Why it's wrong here

    IAM user creation detects persistence or privilege setup, not the data-download behaviour itself, so it misses the exfiltration event entirely. It is tempting because new identities often precede attacks, making it a valid rule for detecting account creation abuse, but it does not correlate S3 GetObject volume or byte counts.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.