CCSP Cloud Security Operations Practice Question
An organization ingests AWS CloudTrail logs into a centralized SIEM for correlation. They want to detect an attacker who exfiltrates data by downloading large volumes from an S3 bucket. Which SIEM correlation rule would best detect this?
⚠ Common exam trap
This exam often tests the distinction between detection of the exfiltration action itself (high volume of GetObject requests) versus precursor or unrelated events (failed logins, root usage, IAM creation), leading candidates to choose a rule that detects a different phase of the attack chain.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Alert on high volume of GetObject requests from a single IP
Exfiltration of data from S3 typically involves a high volume of GetObject API calls from a single source IP. A SIEM correlation rule that triggers on a threshold of GetObject requests from the same IP address directly detects this anomalous download behavior, which is a key indicator of data exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Alert on multiple failed login attempts
Why it's wrong here
Failed-login alerting targets authentication attacks such as brute force, not S3 object downloads; CloudTrail GetObject events carry no login failures. It is tempting because repeated failed logins are a classic SIEM rule, but detecting bulk data exfiltration requires correlating S3 data-access event volume per identity.
- ✓
Alert on high volume of GetObject requests from a single IP
Why this is correct
GetObject requests represent actual object downloads, so alerting when a single IP generates an abnormally high volume of them detects bulk data retrieval. Aggregating by source IP over a time window satisfies the exfiltration scenario, distinguishing sustained mass downloading from routine sporadic access.
- ✗
Alert on root account usage
Why it's wrong here
Root account usage flags privileged console or API activity, not bulk S3 object retrieval, so it cannot surface the exfiltration pattern. It is tempting because root activity is high-severity and rare, making it a valid rule for detecting account takeover or unauthorised administrative actions, but it does not correlate GetObject volume.
- ✗
Alert when a new IAM user is created
Why it's wrong here
IAM user creation detects persistence or privilege setup, not the data-download behaviour itself, so it misses the exfiltration event entirely. It is tempting because new identities often precede attacks, making it a valid rule for detecting account creation abuse, but it does not correlate S3 GetObject volume or byte counts.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.