Courseiva

CCSP · domain

Cloud Security Operations

This domain covers operating and monitoring cloud environments securely, including logging, incident response, forensics, and vulnerability management. Questions present realistic scenarios across AWS, Azure, and GCP, asking you to select the correct log source, tool, or configuration for tasks like tracing data exfiltration, preserving evidence, or automating image scanning.

77 questions22 easy39 medium16 hard

Focused practice

Practice Cloud Security Operations questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Cloud Security Operations

You must be able to map cloud logging and security services to incident response needs, such as choosing the right log for network forensics or automating vulnerability scans. The critical skill is knowing which service provides the required granularity and how to enable it.

Selecting CloudTrail, VPC Flow Logs, or S3 access logs for AWS forensic analysis

Using GCP Cloud Audit Logs and IAM policy change history for timeline reconstruction

Automating Amazon ECR image scanning with Amazon Inspector or native scan-on-push

Applying incident response and evidence preservation procedures in cloud environments

Watch out for

Common Cloud Security Operations exam traps

  • ▸Confusing VPC Flow Logs with application-level logs; Flow Logs capture IP traffic metadata, not HTTP GET request details or payloads.
  • ▸Assuming CloudTrail logs data plane operations by default; data events like S3 object GETs require explicit configuration.
  • ▸Believing ECR basic scanning is automatic on push; it must be enabled per repository or via registry settings.

Question index

All Cloud Security Operations questions (77)

Click any question to see the full explanation, or start a practice session above.

1

A cloud engineer is configuring logging for an AWS Lambda function that processes sensitive data. The security team requires that all invocations are logged, including the request and response payloads, and that logs are retained for 90 days. Which action should the engineer take?

Easy
2

A security engineer needs to automate the remediation of any S3 bucket that is publicly accessible. The solution should work within a single AWS account and not require manual intervention. Which combination of services is MOST appropriate?

Medium
3

A security analyst is investigating a potential breach and needs to verify the integrity of audit logs stored in cloud storage. Which feature should the analyst rely on to confirm that logs have not been tampered with?

Hard
4

A cloud security engineer is deploying a web application on Google Cloud Platform (GCP) and needs to protect it from common web exploits like SQL injection and cross-site scripting. The engineer wants a managed service that can be configured with security policies. Which GCP service should be used?

Easy
5

A cloud security team is building an incident response runbook for compromised compute instances in a public cloud. They need to preserve volatile evidence and maintain chain of custody while minimizing service disruption. Which TWO actions should be included in the runbook? (Choose two.)

Hard
6

Which AWS service uses machine learning to detect threats such as crypto mining activity on EC2 instances and compromised IAM credentials?

Easy
7

An organization uses a cloud security monitoring service for threat detection. A finding indicates that a virtual machine instance is communicating with a known cryptocurrency mining pool. What type of threat does this represent?

Easy
8

A security operations centre uses AWS CloudTrail and wants to detect when an IAM access key belonging to a privileged role is used from an unrecognized IP address outside business hours. The team already has CloudTrail management events delivered to Amazon CloudWatch Logs. Which approach best detects this behaviour with the LEAST operational overhead?

Hard
9

During a security incident in GCP, a forensic analyst needs to determine the exact timeline of events leading to a credential compromise. Which log source provides the most detailed information about IAM policy changes and authentication events?

Hard
10

A security engineer needs to scan all container images stored in Amazon Elastic Container Registry (ECR) for vulnerabilities. The scan must be automated whenever a new image is pushed. Which solution meets this requirement?

Medium
11

A cloud operations team runs a production Kubernetes cluster on Amazon EKS. During a security review, they discover that the cluster's control plane audit logs are not being captured, preventing investigation of suspicious API server activity. The team must enable audit logging with the least operational overhead while retaining logs for 90 days. Which action should they take?

Medium
12

During incident response in a cloud environment, a team needs to collect evidence from a compromised EC2 instance without altering the system. Which of the following is the best method to obtain a forensic memory dump?

Hard
13

An organization uses a cloud-based SIEM solution. Which cloud service provides native integration to stream audit logs into the SIEM?

Easy
14

An organization uses Azure Defender for Cloud to protect their hybrid environment. They want to receive alerts about suspicious activities on their Azure Key Vault. Which Defender plan should they enable?

Medium
15

An incident response playbook for a cloud environment includes containment steps. For a compromised IAM user in AWS, which action is least likely to be effective for containment?

Medium
16

A cloud operations team is deploying a new web application on Google Cloud Platform (GCP). They need to ensure that all incoming traffic to their Compute Engine instances is inspected for common web attacks such as SQL injection and cross-site scripting. They also want to minimize latency and management overhead. Which GCP service should they use?

Easy
17

A security engineer is evaluating vulnerability management options for cloud workloads and wants to identify vulnerabilities without installing agents on the operating system. Which approach should be used?

Medium
18

A company runs a regulated workload in Microsoft Azure and must retain all administrative activity logs for seven years to satisfy an auditor. The logs must be immutable and retrievable even if the original resource is deleted. Which Azure capability should the team implement?

Easy
19

A cloud security team must harden the management plane for a Kubernetes cluster running on Google Kubernetes Engine. They want to limit who can reach the control plane endpoint and ensure that any administrative action taken against the cluster is attributable to a named identity. (Choose two.)

Medium
20

During a forensic investigation of a suspected data exfiltration incident in AWS, a security team needs to analyze network traffic to identify the destination IP addresses and volume of data transferred. Which data source is most appropriate for this analysis?

Hard
21

A financial services company uses Azure and must ensure that all administrative actions in their Azure subscription are logged and that logs are stored in an immutable storage account for 7 years. They also need to be able to alert on specific critical operations, such as deletion of a resource group. Which combination of Azure services should they implement?

Hard
22

A security operations team at a healthcare company running workloads on AWS needs to ensure that all API activity in their production account is recorded and retained for 12 months, with the ability to search for specific events during a forensic investigation. The compliance officer mandates that logs must be protected from deletion by any user, including administrators. Which AWS service and configuration should the team implement to meet these requirements?

Medium
23

A cloud security engineer needs to ensure that logs from multiple AWS accounts are centrally stored in a security account for analysis. Which TWO services can be used to aggregate logs across accounts? (Choose two.)

Easy
24

A cloud operations team manages 200 Amazon EC2 instances spread across three AWS accounts. They must continuously assess the instances for missing OS patches and misconfigured software, and they want findings aggregated in a single console with severity ratings and remediation runbooks. Which AWS service should the team deploy to meet these requirements?

Medium
25

A cloud security engineer needs to review who created or modified IAM policies in an Azure subscription over the past 90 days, and must retain that evidence for compliance. Which Azure-native capability should be used to collect and store these records?

Easy
26

During a cloud incident response, a security team needs to collect memory from a compromised EC2 instance for forensic analysis. Which method is most appropriate for acquiring a memory dump?

Hard
27

Which of the following is a primary purpose of a SOAR (Security Orchestration, Automation and Response) platform in cloud security operations?

Easy
28

A security team is investigating a potential data exfiltration incident where a large volume of data was downloaded from a cloud storage bucket. Which log source would provide the most granular details about the GET requests, including the requester identity and source IP?

Hard
29

An organization is implementing a cloud SIEM solution to centralize security monitoring across multiple AWS accounts. Which service should be used to aggregate security findings and send them to a third-party SIEM like Splunk?

Medium
30

A cloud operations team runs a Kubernetes cluster on Google Kubernetes Engine (GKE). A recent audit found that several pods were scheduled onto nodes that do not meet the organization's hardened baseline, and the team wants to enforce that only nodes with specific labels are eligible for certain workloads. Which Kubernetes mechanism should the team implement?

Medium
31

What is the primary purpose of cloud security posture management (CSPM) tools?

Easy
32

A cloud security team is implementing a centralized logging solution for AWS. They need to ensure that all API activity in their production account is logged and that the logs are stored immutably for 7 years to meet compliance requirements. Which service should they use to capture the API activity?

Medium
33

An organization is using GCP and wants to collect audit logs for all API calls made within the project. Which GCP service should be enabled to capture these logs?

Easy
34

An organization wants to ensure that all resources are compliant with CIS benchmarks. Which cloud service provides a unified view of compliance posture and recommendations?

Medium
35

A security engineer is implementing automated incident response for common cloud threats. Which TWO cloud services can be used together to create a serverless orchestration workflow for incident response? (Choose two.)

Easy
36

An organization uses GCP and wants to detect container threats such as privilege escalation attempts within Kubernetes Engine. Which GCP service is designed specifically for this purpose?

Hard
37

A security analyst is investigating a potential compromise of an AWS EC2 instance. Which step should be taken FIRST to contain the incident and prevent further damage?

Medium
38

An organization wants to implement a cloud security automation solution that can automatically remediate non-compliant resources in Azure. Which Azure service should be used to create remediation tasks?

Easy
39

An organization ingests AWS CloudTrail logs into a centralized SIEM for correlation. They want to detect an attacker who exfiltrates data by downloading large volumes from an S3 bucket. Which SIEM correlation rule would best detect this?

Medium
40

A company uses Azure Policy with remediation tasks to automatically fix non-compliant resources. Which scenario can be automatically remediated using a built-in policy?

Medium
41

A security engineer is investigating a potential data exfiltration incident involving an Amazon S3 bucket. Which set of logs would provide the most relevant information to identify the source IP and API calls made to the bucket?

Medium
42

A cloud security engineer is responsible for securing a Kubernetes cluster running on Google Kubernetes Engine (GKE). They need to detect and respond to runtime threats such as cryptomining and reverse shell attempts. They want a solution that integrates natively with GKE and provides detailed container-level visibility. Which GCP service should they use?

Hard
43

A healthcare company stores regulated data in Amazon S3. An auditor requires proof that objects are protected against accidental deletion or overwrite for a fixed period, and that the protection cannot be removed even by the root account. Which S3 feature should the security team implement?

Easy
44

A company uses Microsoft Azure and wants to implement just-in-time (JIT) virtual machine access to reduce the attack surface. They need to ensure that only authorized users can access VMs on specific management ports, and that access is granted for a limited time. Which Azure service should they use?

Medium
45

A security team needs to implement automated remediation for non-compliant resources in a cloud environment. They want to automatically fix public object storage bucket policies. Which combination of services should be used?

Medium
46

A security team is enhancing logging in AWS to capture detailed data events for S3 buckets. Which TWO of the following should be enabled to achieve comprehensive monitoring of S3 data access? (Choose two.)

Medium
47

A security team is using AWS and wants to monitor for changes to security groups that could expose resources to the internet. They need to receive an alert when a security group rule is modified to allow inbound traffic from 0.0.0.0/0 on port 22. Which AWS service should they use to detect this change?

Medium
48

A cloud operations team runs a mission-critical application on Amazon EC2 instances behind an Application Load Balancer. The security policy requires that the instances be patched monthly, but the team wants to minimize downtime and avoid manual patching. They decide to use AWS Systems Manager Patch Manager. Which configuration should they implement to meet the patching requirement while maintaining availability?

Medium
49

A security operations team is using AWS Security Hub to aggregate findings from multiple AWS accounts. They want to automatically create a ticket in their IT service management (ITSM) system for any new critical finding. The ITSM system exposes a REST API. Which AWS service should they use to invoke the ITSM API when a critical finding is generated?

Medium
50

A security operations center (SOC) uses AWS GuardDuty and wants to automatically isolate an Amazon EC2 instance that generates a high-severity finding. The isolation must block all network traffic except for forensic analysis traffic from a specific security subnet. Which combination of actions should be taken?

Hard
51

A cloud operations team runs a fleet of Amazon EC2 instances behind an Application Load Balancer. After a recent penetration test, the team must ensure that only HTTP and HTTPS traffic reaches the instances from the load balancer, and that no instance can accept SSH from the internet. The instances currently have a security group named 'web-sg' that allows all inbound traffic from 0.0.0.0/0. Which action should the team take to meet these requirements with the LEAST administrative effort while following AWS best practices?

Medium
52

A cloud security team wants to automatically remediate misconfigured S3 buckets that are publicly accessible. Which combination of AWS services can be used to detect and automatically fix this issue?

Medium
53

A cloud operations team is deploying a containerized workload on a managed Kubernetes service. They need to ensure that if a container image is discovered to contain a critical vulnerability, the running pods using that image are automatically replaced with a non-vulnerable version. Which mechanism BEST achieves this?

Medium
54

A security engineer needs to ensure that all API calls made to cloud resources are logged for auditing. Which cloud auditing feature should be enabled to capture management and data events?

Easy
55

A company uses Azure Defender for Cloud to protect its hybrid environment. Which of the following is a feature of Azure Defender that provides vulnerability assessment for virtual machines?

Medium
56

An organization is using Azure and wants to centrally collect activity logs from multiple subscriptions into a single Log Analytics workspace for cross-account analysis and retention management. What is the best approach?

Medium
57

A cloud security architect is evaluating vulnerability management solutions for a hybrid cloud environment. The team needs to scan both on-premises servers and cloud workloads without installing agents on every system. Which approach is most suitable for cloud workloads?

Medium
58

An organization wants to detect potential crypto mining activity on their AWS EC2 instances. Which AWS service uses machine learning to identify such threats?

Easy
59

A security analyst reviews GCP Security Command Center findings and sees a high-severity alert for Event Threat Detection indicating that a service account key was used from an unexpected location. What is the best immediate action to contain the threat?

Easy
60

A cloud security team is building an incident response runbook for workloads on AWS. They need to ensure that when a compromised EC2 instance is detected, responders can preserve volatile evidence and prevent further malicious activity without destroying forensic artifacts. (Choose two.)

Medium
61

A company uses Azure Sentinel as its SIEM. To ingest Azure Activity Logs and correlate with other data sources, which connector should be configured?

Easy
62

A security analyst is investigating a potential security incident in a Microsoft Azure environment. The analyst needs to review the history of role assignments and changes to Azure resources over the past 90 days. Which Azure service should the analyst use?

Hard
63

An organization uses GCP and wants to monitor for threats in real-time, including detecting malicious activity from compromised service accounts. Which GCP service should be used?

Medium
64

An organization is using GCP Security Command Center with Event Threat Detection. Which type of event is most likely to generate a finding for 'exfiltration'?

Medium
65

A SOC analyst notices an alert for 'impossible travel' where a user logged in from New York and then from London within 15 minutes. The SIEM correlation rule likely compares which log fields?

Medium
66

Which of the following is a benefit of enabling log file validation for cloud audit logs?

Easy
67

A company is implementing a SIEM solution and needs to ingest security logs from multiple AWS accounts into a centralized security account. Which AWS service can best aggregate findings from all accounts?

Medium
68

A cloud security team is designing a detective control strategy for a multi-account AWS organization. The team wants to continuously evaluate resource configurations against CIS AWS Foundations Benchmark controls across all accounts and receive alerts when a resource drifts from the desired state. The team also wants to automatically remediate noncompliant resources where possible. Which TWO AWS services should be combined to meet these requirements? (Choose two.)

Hard
69

A cloud security engineer is tasked with ensuring that all API calls made to AWS resources are logged for audit purposes. Which AWS service should be enabled to capture management events such as creating or deleting EC2 instances?

Easy
70

A security analyst notices that an IAM user from a cloud account has logged in from two different countries within a span of 10 minutes. Which type of detection mechanism is most likely to flag this activity as suspicious?

Medium
71

A financial services company stores regulated data in Amazon S3 and must prove to auditors that objects cannot be deleted or overwritten for seven years, even by a compromised root account. The security team needs the strongest native control that preserves the data for the retention period. Which S3 feature should they enable?

Hard
72

A security architect is designing a logging strategy for a multi-cloud environment using AWS and Azure. Which TWO practices should be implemented to ensure log integrity and prevent tampering? (Choose two.)

Medium
73

After a security incident involving a compromised access key, a security engineer needs to collect forensic evidence from the cloud environment. Which of the following actions would be most useful for determining the timeline of the compromise?

Hard
74

A cloud security team needs to ensure that all AWS API activity across a multi-account organization is captured in a tamper-evident, immutable log that can be queried later for forensic analysis. The organization uses AWS Organizations with a dedicated security account. Which approach BEST meets these requirements?

Medium
75

A security engineer needs to ensure that all API calls made to AWS resources are logged for auditing purposes. Which AWS service should be enabled to capture management events, data events, and provide log file validation?

Easy
76

A cloud operations team at a healthcare company runs a multi-account AWS organization. Compliance requires that all Amazon S3 server access logs and AWS CloudTrail management events are retained for 7 years and cannot be altered or deleted by any account administrator, including the account that owns the bucket. The security architect must design a storage solution that enforces write-once-read-many (WORM) immutability at the storage layer. Which approach BEST satisfies these requirements?

Medium
77

A cloud security operations team is configuring AWS Security Hub to automatically send all findings to a third-party ticketing system. They need a solution that requires minimal custom code and supports filtering by severity. Which AWS service should they use to route the findings?

Medium

Frequently asked questions

What does the Cloud Security Operations domain cover on the CCSP exam?
You must be able to map cloud logging and security services to incident response needs, such as choosing the right log for network forensics or automating vulnerability scans. The critical skill is knowing which service provides the required granularity and how to enable it.
How many questions are in this domain?
This page lists all 77 Cloud Security Operations questions in the CCSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Cloud Security Operations questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-ccsp ISC2-CCSP ccsp security ops Practice Questions