CCSP SIEM Practice Question
An organization uses a cloud-based SIEM solution. Which cloud service provides native integration to stream audit logs into the SIEM?
⚠ Common exam trap
CCSP often tests the confusion between log aggregation services and detection or policy services, so candidates must pick the service whose primary purpose is collecting and streaming logs, not one that analyzes or recommends.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Centralized logging service
A centralized logging service is the cloud service that natively aggregates audit logs from multiple sources and can stream them into a SIEM, because its core function is to collect, store, and forward log data. Native integration to stream audit logs into a SIEM is a defining capability of centralized logging services such as AWS CloudTrail with CloudWatch Logs, Azure Monitor Logs, or Google Cloud Logging. The other options describe different security functions that do not provide the log-streaming pipeline the SIEM needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security monitoring service
Why it's wrong here
A security monitoring service consumes and analyses events; it does not itself provide the native log-streaming integration into a third-party SIEM. It tempts because it sounds security-focused, and it would be correct when the goal is built-in threat detection rather than exporting audit records to an external platform.
- ✓
Centralized logging service
Why this is correct
A centralised logging service natively collects and forwards audit trails from cloud resources, providing the direct streaming integration the SIEM consumes. It removes the need for custom agents or polling, satisfying the native-integration constraint in the stem.
- ✗
Policy management service
Why it's wrong here
A policy management service enforces organisational rules and compliance guardrails; it does not emit the platform audit trail that a SIEM ingests. It is tempting because policy and audit both concern governance, but it would be the right choice for constraining resource configurations, whereas audit log streaming comes from the cloud logging service.
- ✗
Recommendation service
Why it's wrong here
A recommendation service suggests products or content; it has no role in exporting audit logs. It is tempting because cloud providers offer such engines for personalisation, and they would be the right pick when the requirement is generating tailored suggestions rather than feeding telemetry into a SIEM.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.