Courseiva

CCSP Cloud Security Operations Practice Question

An organization uses a cloud security monitoring service for threat detection. A finding indicates that a virtual machine instance is communicating with a known cryptocurrency mining pool. What type of threat does this represent?

⚠ Common exam trap

Test-takers frequently confuse crypto mining with ransomware or credential theft, but the key differentiator is the specific network communication pattern to a mining pool, not data encryption or API abuse.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Crypto mining on a virtual machine

A cloud security monitoring service detects threats by analyzing network traffic logs, DNS logs, and API call logs. A finding of communication with a known cryptocurrency mining pool indicates that the virtual machine instance is likely compromised and running crypto mining software, which consumes excessive compute resources and represents a malicious activity type known as crypto mining.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reconnaissance port scanning

    Why it's wrong here

    Port scanning is discovery activity against hosts or services; the finding instead shows an established outbound session to a mining pool, indicating active resource abuse rather than probing. Reconnaissance would be the correct classification when traffic consists of sequential connection attempts across many ports with no completed session.

  • ✗

    Ransomware activity

    Why it's wrong here

    Ransomware encrypts data and typically presents as file modification, shadow-copy deletion or extortion traffic; a mining-pool connection is unauthorised compute consumption, not encryption activity. Ransomware would be the correct classification when the monitoring service detects mass file encryption or ransom-note creation.

  • ✗

    Compromised credentials exfiltration

    Why it's wrong here

    Exfiltration describes unauthorised data transfer out of the environment; the finding names outbound connections to a mining pool, which is resource abuse, not credential theft. Credential exfiltration would be the correct classification when logs show stolen secrets or tokens leaving to an attacker-controlled destination.

  • ✓

    Crypto mining on a virtual machine

    Why this is correct

    Communication with a known cryptocurrency mining pool indicates the instance's compute resources have been hijacked to mine cryptocurrency, typically via malware or a compromised workload. This unauthorised resource consumption is classified as crypto mining on a virtual machine.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.