CCSP Cloud Security Operations Practice Question
An organization uses GCP and wants to monitor for threats in real-time, including detecting malicious activity from compromised service accounts. Which GCP service should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Event Threat Detection
Event Threat Detection is part of GCP Security Command Center and provides real-time threat detection for IAM anomalies, including compromised service accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Audit Logs
Why it's wrong here
Cloud Audit Logs record administrative and data-access events for later review; they are not a real-time threat-detection engine and do not correlate service-account behaviour into alerts. They are tempting because they capture service-account activity, and would be correct for compliance auditing or retrospective investigation.
- ✗
Cloud Security Scanner
Why it's wrong here
Cloud Security Scanner crawls App Engine, Compute Engine and GKE web applications for common vulnerabilities such as cross-site scripting and outdated libraries; it does not analyse IAM or service-account behaviour. It is tempting as a GCP security tool, and would be correct for finding application vulnerabilities before deployment.
- ✗
Container Threat Detection
Why it's wrong here
Container Threat Detection monitors GKE container workloads for runtime anomalies such as unexpected binaries or reverse shells; it does not cover service-account misuse elsewhere in the project. It is tempting as a real-time GCP detection service, and would be correct if the threat were confined to containerised workloads.
- ✓
Event Threat Detection
Why this is correct
Event Threat Detection continuously analyses Cloud Audit Logs and VPC flow logs using threat intelligence to surface compromised service accounts, cryptomining and data exfiltration in near real-time. Security Command Center Premium surfaces these findings, satisfying the real-time monitoring requirement that Cloud Logging alone cannot provide.
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.