CCSP Cloud Security Operations Practice Question
An organization uses a cloud security monitoring service for threat detection. A finding indicates that a virtual machine instance is communicating with a known cryptocurrency mining pool. What type of threat does this represent?
⚠ Common exam trap
Test-takers frequently confuse crypto mining with ransomware or credential theft, but the key differentiator is the specific network communication pattern to a mining pool, not data encryption or API abuse.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Crypto mining on a virtual machine
A cloud security monitoring service detects threats by analyzing network traffic logs, DNS logs, and API call logs. A finding of communication with a known cryptocurrency mining pool indicates that the virtual machine instance is likely compromised and running crypto mining software, which consumes excessive compute resources and represents a malicious activity type known as crypto mining.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reconnaissance port scanning
Why it's wrong here
Port scanning is discovery activity against hosts or services; the finding instead shows an established outbound session to a mining pool, indicating active resource abuse rather than probing. Reconnaissance would be the correct classification when traffic consists of sequential connection attempts across many ports with no completed session.
- ✗
Ransomware activity
Why it's wrong here
Ransomware encrypts data and typically presents as file modification, shadow-copy deletion or extortion traffic; a mining-pool connection is unauthorised compute consumption, not encryption activity. Ransomware would be the correct classification when the monitoring service detects mass file encryption or ransom-note creation.
- ✗
Compromised credentials exfiltration
Why it's wrong here
Exfiltration describes unauthorised data transfer out of the environment; the finding names outbound connections to a mining pool, which is resource abuse, not credential theft. Credential exfiltration would be the correct classification when logs show stolen secrets or tokens leaving to an attacker-controlled destination.
- ✓
Crypto mining on a virtual machine
Why this is correct
Communication with a known cryptocurrency mining pool indicates the instance's compute resources have been hijacked to mine cryptocurrency, typically via malware or a compromised workload. This unauthorised resource consumption is classified as crypto mining on a virtual machine.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.