Courseiva

CCSP SIEM Practice Question

An organization uses a cloud-based SIEM solution. Which cloud service provides native integration to stream audit logs into the SIEM?

⚠ Common exam trap

CCSP often tests the confusion between log aggregation services and detection or policy services, so candidates must pick the service whose primary purpose is collecting and streaming logs, not one that analyzes or recommends.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Centralized logging service

A centralized logging service is the cloud service that natively aggregates audit logs from multiple sources and can stream them into a SIEM, because its core function is to collect, store, and forward log data. Native integration to stream audit logs into a SIEM is a defining capability of centralized logging services such as AWS CloudTrail with CloudWatch Logs, Azure Monitor Logs, or Google Cloud Logging. The other options describe different security functions that do not provide the log-streaming pipeline the SIEM needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security monitoring service

    Why it's wrong here

    A security monitoring service consumes and analyses events; it does not itself provide the native log-streaming integration into a third-party SIEM. It tempts because it sounds security-focused, and it would be correct when the goal is built-in threat detection rather than exporting audit records to an external platform.

  • ✓

    Centralized logging service

    Why this is correct

    A centralised logging service natively collects and forwards audit trails from cloud resources, providing the direct streaming integration the SIEM consumes. It removes the need for custom agents or polling, satisfying the native-integration constraint in the stem.

  • ✗

    Policy management service

    Why it's wrong here

    A policy management service enforces organisational rules and compliance guardrails; it does not emit the platform audit trail that a SIEM ingests. It is tempting because policy and audit both concern governance, but it would be the right choice for constraining resource configurations, whereas audit log streaming comes from the cloud logging service.

  • ✗

    Recommendation service

    Why it's wrong here

    A recommendation service suggests products or content; it has no role in exporting audit logs. It is tempting because cloud providers offer such engines for personalisation, and they would be the right pick when the requirement is generating tailored suggestions rather than feeding telemetry into a SIEM.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.