Courseiva

CCSP Cloud Security Operations Practice Question

An organization is using GCP and wants to collect audit logs for all API calls made within the project. Which GCP service should be enabled to capture these logs?

⚠ Common exam trap

CCSP often tests the confusion between network-level logging (VPC Flow Logs) and API-level auditing (Cloud Audit Logs), so candidates must remember that audit logs capture control plane and data plane API calls, not packet flows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Audit Logs

Cloud Audit Logs is the correct GCP service because it automatically records API calls and administrative activities within a GCP project. It captures Admin Activity, Data Access, System Event, and Policy Denied logs, providing a comprehensive audit trail of who did what, where, and when. This is essential for security, compliance, and forensic investigations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC Flow Logs

    Why it's wrong here

    VPC Flow Logs record network traffic metadata for subnets or instances, not the identity and action of API callers. It is tempting because flow logs are a familiar network-monitoring control, and would be correct where the requirement is analysing IP-level connectivity or traffic patterns rather than administrative and data-access API activity.

  • ✓

    Cloud Audit Logs

    Why this is correct

    Cloud Audit Logs captures Admin Activity and Data Access entries for every API call in the project, satisfying the requirement to record all API activity. Enabling it at project level provides the audit trail directly, unlike Cloud Logging, which aggregates logs but does not itself generate API audit records.

  • ✗

    Cloud Monitoring

    Why it's wrong here

    Cloud Monitoring collects metrics, uptime checks and alerts on resource performance; it does not record API call audit events. It is tempting because it provides operational visibility across the project, and would be correct where the requirement is alerting on thresholds or latency rather than capturing who called which API and when.

  • ✗

    Cloud Security Command Center

    Why it's wrong here

    Security Command Center aggregates findings, vulnerabilities and asset inventory; it does not itself capture API call audit records. It is tempting because it is a central security visibility service, and would be correct where the requirement is threat detection and posture reporting rather than collecting audit log entries.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.