Courseiva
Cloud Security Operations →mediumMultiple Choice

CCSP Cloud Security Operations Practice Question

An organization uses GCP and wants to monitor for threats in real-time, including detecting malicious activity from compromised service accounts. Which GCP service should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Event Threat Detection

Event Threat Detection is part of GCP Security Command Center and provides real-time threat detection for IAM anomalies, including compromised service accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud Audit Logs

    Why it's wrong here

    Cloud Audit Logs record administrative and data-access events for later review; they are not a real-time threat-detection engine and do not correlate service-account behaviour into alerts. They are tempting because they capture service-account activity, and would be correct for compliance auditing or retrospective investigation.

  • ✗

    Cloud Security Scanner

    Why it's wrong here

    Cloud Security Scanner crawls App Engine, Compute Engine and GKE web applications for common vulnerabilities such as cross-site scripting and outdated libraries; it does not analyse IAM or service-account behaviour. It is tempting as a GCP security tool, and would be correct for finding application vulnerabilities before deployment.

  • ✗

    Container Threat Detection

    Why it's wrong here

    Container Threat Detection monitors GKE container workloads for runtime anomalies such as unexpected binaries or reverse shells; it does not cover service-account misuse elsewhere in the project. It is tempting as a real-time GCP detection service, and would be correct if the threat were confined to containerised workloads.

  • ✓

    Event Threat Detection

    Why this is correct

    Event Threat Detection continuously analyses Cloud Audit Logs and VPC flow logs using threat intelligence to surface compromised service accounts, cryptomining and data exfiltration in near real-time. Security Command Center Premium surfaces these findings, satisfying the real-time monitoring requirement that Cloud Logging alone cannot provide.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.