Courseiva

CCNA Ccsp Security Ops Questions

75 of 77 questions · Page 1/2 · Ccsp Security Ops topic · Answers revealed

1
MCQeasy

A cloud engineer is configuring logging for an AWS Lambda function that processes sensitive data. The security team requires that all invocations are logged, including the request and response payloads, and that logs are retained for 90 days. Which action should the engineer take?

A.Enable AWS X-Ray tracing for the Lambda function and configure a 90-day retention for X-Ray traces.
B.Use AWS Config to record Lambda function configurations and set a 90-day retention for configuration history.
C.Configure the Lambda function to log to Amazon CloudWatch Logs and set the log group retention to 90 days.
D.Enable AWS CloudTrail logging for the Lambda function and configure a CloudWatch Logs retention policy of 90 days.
AnswerC

Lambda automatically logs to CloudWatch Logs if the function's execution role has permissions. By adding logging statements in the function code, the engineer can log request and response payloads. Setting the CloudWatch Logs retention policy to 90 days meets the retention requirement. This is the standard way to capture detailed invocation logs, including payloads, for Lambda functions.

Why this answer

To log all invocations with request and response payloads, the Lambda function must write logs to CloudWatch Logs. This is done by including logging statements in the function code. CloudWatch Logs allows setting a retention policy of 90 days.

CloudTrail, X-Ray, and AWS Config do not capture full payloads, so they are not suitable.

Exam trap

The trap here is assuming that CloudTrail or X-Ray can capture full request and response payloads for Lambda invocations.

2
MCQmedium

A security engineer needs to automate the remediation of any S3 bucket that is publicly accessible. The solution should work within a single AWS account and not require manual intervention. Which combination of services is MOST appropriate?

A.AWS Config rule + AWS Lambda auto-remediation
B.Amazon GuardDuty + AWS Step Functions
C.AWS CloudTrail + Amazon SNS
D.AWS Trusted Advisor + AWS Systems Manager
AnswerA

AWS Config continuously evaluates bucket policies and ACLs against a rule flagging public access, then triggers Lambda for automatic remediation. This satisfies the no-manual-intervention constraint within one account, because Config detects drift and Lambda removes the public grant without human approval.

Why this answer

AWS Config can continuously evaluate S3 bucket settings against a custom or managed rule (e.g., s3-bucket-public-read-prohibited). When the rule detects a noncompliant bucket, it triggers an AWS Lambda function via auto-remediation, which can modify the bucket's ACL or policy to remove public access. This combination provides fully automated, event-driven remediation without manual steps.

Exam trap

In the CCSP exam context, candidates often confuse detection services (GuardDuty, CloudTrail) with configuration enforcement services (AWS Config), leading them to select a solution that only detects but does not remediate public S3 buckets.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty is a threat detection service that identifies malicious activity (e.g., unusual API calls), not a configuration compliance tool; it cannot directly enforce S3 bucket policies. Option C is wrong because AWS CloudTrail records API activity but does not evaluate or remediate configurations, and Amazon SNS only sends notifications, not automated fixes. Option D is wrong because AWS Trusted Advisor provides best-practice checks and recommendations, but it does not offer native auto-remediation; AWS Systems Manager can automate actions but requires custom runbooks and is not designed for real-time S3 bucket compliance enforcement.

3
MCQhard

A security analyst is investigating a potential breach and needs to verify the integrity of audit logs stored in cloud storage. Which feature should the analyst rely on to confirm that logs have not been tampered with?

A.Server-side encryption of logs
B.Log file integrity validation
C.Anomaly detection on logs
D.Immutable storage for logs
AnswerB

Log file integrity validation produces cryptographic hashes that let the analyst confirm stored audit logs have not been altered or deleted. It directly satisfies the tamper-detection requirement, unlike versioning or retention locks, which prevent deletion but do not prove integrity.

Why this answer

Log file integrity validation is the cloud-native feature (e.g., AWS CloudTrail log file integrity validation) that uses cryptographic hashing and digital signatures to prove that log files have not been altered or deleted after delivery. It produces a digest file for each log delivery containing SHA-256 hashes and a signature, allowing the analyst to verify tamper-evidence. This directly answers the requirement to 'confirm logs have not been tampered with.'

Exam trap

CCSP often tests the difference between encryption (confidentiality), immutability (prevention of change), and integrity validation (detection of change) — candidates pick encryption or immutability when the question specifically asks to 'verify' or 'confirm' integrity.

How to eliminate wrong answers

Option A is wrong because server-side encryption protects logs at rest from unauthorized reading but does not provide any mechanism to detect whether the log contents were modified after being written. Option C is wrong because anomaly detection identifies suspicious activity patterns in log data but cannot cryptographically prove the logs themselves are unaltered. Option D is wrong because immutable storage (e.g., S3 Object Lock) prevents future modification or deletion but does not provide a verification mechanism to confirm integrity of logs that were written before the lock or to detect tampering that occurred prior to immutability being applied.

4
MCQeasy

A cloud security engineer is deploying a web application on Google Cloud Platform (GCP) and needs to protect it from common web exploits like SQL injection and cross-site scripting. The engineer wants a managed service that can be configured with security policies. Which GCP service should be used?

A.Google Cloud Armor
B.Google Cloud Load Balancing
C.Google Cloud VPN
D.Google Cloud Identity-Aware Proxy (IAP)
AnswerA

Google Cloud Armor is a managed web application firewall (WAF) that provides protection against common web vulnerabilities such as SQL injection and cross-site scripting. It integrates with HTTP(S) load balancing and allows you to define security policies with rules to filter traffic. This matches the requirement for a managed service to protect the web application.

Why this answer

Google Cloud Armor is the correct service because it is a managed WAF that can be configured with security policies to protect against web exploits. It integrates with load balancing to filter malicious traffic. The other services provide identity control, network connectivity, or load distribution, but none offer WAF functionality.

Exam trap

The trap here is assuming that Cloud Load Balancing includes WAF capabilities, but it requires Cloud Armor for that purpose.

5
Multi-Selecthard

A cloud security team is building an incident response runbook for compromised compute instances in a public cloud. They need to preserve volatile evidence and maintain chain of custody while minimizing service disruption. Which TWO actions should be included in the runbook? (Choose two.)

Select 2 answers
A.Disable all logging on the instance to prevent the attacker from tampering with logs, then re-enable after remediation.
B.Capture a memory dump of the running instance before shutting it down, storing the dump in a write-once location with a documented hash.
C.Immediately terminate the instance to prevent further malicious activity and rely on the cloud provider's internal logs for evidence.
D.Create a snapshot of the instance's volumes and copy it to a restricted forensic account, recording the snapshot ID and creation time.
E.Reboot the instance into safe mode to clear malicious processes, then continue using it for production traffic.
AnswersB, D

Volatile evidence such as memory contents is lost on shutdown or reboot, so capturing a memory dump first preserves critical artifacts like running processes and network connections. Storing it in a write-once location and recording a cryptographic hash establishes integrity and chain of custody, which are essential for forensic validity and later legal or disciplinary use.

Why this answer

Preserving volatile memory before any shutdown and snapshotting persistent volumes into an isolated forensic account together capture the full evidence set while maintaining integrity. Both actions record identifiers and hashes for chain of custody, and they allow the original instance to be contained or rebuilt without losing forensic artifacts, which is the core of a defensible cloud incident response runbook.

Exam trap

The trap here is believing that terminating or rebooting a compromised instance is the safest first step, when doing so destroys volatile evidence and breaks chain of custody before memory and disk artifacts can be captured.

6
MCQeasy

Which AWS service uses machine learning to detect threats such as crypto mining activity on EC2 instances and compromised IAM credentials?

A.AWS Shield
B.AWS WAF
C.AWS Inspector
D.Amazon GuardDuty
AnswerD

Amazon GuardDuty continuously analyses CloudTrail, VPC Flow Logs and DNS logs with managed machine learning and threat intelligence to surface findings including cryptocurrency mining on EC2 instances and compromised IAM credentials. It satisfies the stem's requirement for an AWS-native, ML-driven threat detection service without deploying agents.

Why this answer

Amazon GuardDuty is a threat detection service that uses machine learning and anomaly detection to identify malicious activity.

7
MCQeasy

An organization uses a cloud security monitoring service for threat detection. A finding indicates that a virtual machine instance is communicating with a known cryptocurrency mining pool. What type of threat does this represent?

A.Reconnaissance port scanning
B.Ransomware activity
C.Compromised credentials exfiltration
D.Crypto mining on a virtual machine
AnswerD

Communication with a known cryptocurrency mining pool indicates the instance's compute resources have been hijacked to mine cryptocurrency, typically via malware or a compromised workload. This unauthorised resource consumption is classified as crypto mining on a virtual machine.

Why this answer

A cloud security monitoring service detects threats by analyzing network traffic logs, DNS logs, and API call logs. A finding of communication with a known cryptocurrency mining pool indicates that the virtual machine instance is likely compromised and running crypto mining software, which consumes excessive compute resources and represents a malicious activity type known as crypto mining.

Exam trap

The trap here is that candidates confuse crypto mining with ransomware or credential theft, but the key differentiator is the specific network communication pattern to a mining pool, not data encryption or API abuse.

How to eliminate wrong answers

Option A is wrong because reconnaissance port scanning involves probing for open ports or services, not communication with a known mining pool, which is a specific outbound connection to a malicious IP/domain. Option B is wrong because ransomware activity typically involves encrypting data and demanding payment, not the sustained CPU usage and network traffic to mining pools characteristic of crypto mining. Option C is wrong because compromised IAM credentials exfiltration would manifest as unauthorized API calls or access to sensitive resources, not direct outbound connections to mining infrastructure.

8
MCQhard

A security operations centre uses AWS CloudTrail and wants to detect when an IAM access key belonging to a privileged role is used from an unrecognized IP address outside business hours. The team already has CloudTrail management events delivered to Amazon CloudWatch Logs. Which approach best detects this behaviour with the LEAST operational overhead?

A.Write a CloudWatch Logs Insights query and schedule it hourly to email matching events to the security team
B.Create a CloudWatch Logs metric filter that matches the access key event and an alarm that triggers when the source IP is outside an allowlist
C.Configure an AWS Config custom rule that evaluates IAM access key metadata against approved CIDR ranges
D.Enable Amazon GuardDuty and rely on its IAM finding types for anomalous access key usage
AnswerD

GuardDuty continuously analyzes CloudTrail management events, VPC Flow Logs, and DNS logs with machine learning and threat intelligence, producing findings such as anomalous IAM access key usage from unusual geolocations or IP addresses. It requires no custom rule authoring, delivers findings automatically, and integrates with EventBridge for response, making it the lowest-overhead option.

Why this answer

Detecting anomalous use of privileged access keys from unfamiliar IPs outside normal hours is a behavioural threat-detection problem. Amazon GuardDuty ingests CloudTrail management events continuously and applies anomaly detection and threat intelligence to surface findings like anomalous access key usage, requiring no custom filters or scheduled queries, which minimizes operational overhead for the SOC.

Exam trap

The trap here is reaching for custom CloudWatch metric filters or Logs Insights queries to detect suspicious access key use, when a managed threat-detection service already performs this behavioural analysis with no rule maintenance.

9
MCQhard

During a security incident in GCP, a forensic analyst needs to determine the exact timeline of events leading to a credential compromise. Which log source provides the most detailed information about IAM policy changes and authentication events?

A.VPC Flow Logs
B.Cloud Audit Logs
C.Cloud DNS logs
D.Cloud Monitoring metrics
AnswerB

Cloud Audit Logs capture Admin Activity entries recording IAM policy changes and authentication events, with timestamps and actor identities. This gives the forensic analyst the precise chronology of the credential compromise, which other log sources such as VPC Flow Logs or firewall logs cannot provide.

Why this answer

GCP Cloud Audit Logs record all admin activities and data access, including IAM changes and authentication, making them the best source for timeline reconstruction.

10
MCQmedium

A security engineer needs to scan all container images stored in Amazon Elastic Container Registry (ECR) for vulnerabilities. The scan must be automated whenever a new image is pushed. Which solution meets this requirement?

A.Use Amazon Macie for image scanning.
B.Configure AWS Security Hub to scan images.
C.Use AWS Lambda to invoke Clair on each push.
D.Enable Amazon Inspector continuous scanning for ECR repositories.
AnswerD

Amazon Inspector's continuous scanning integrates natively with Amazon ECR, automatically re-evaluating repositories when new images are pushed, which satisfies the automation constraint without custom orchestration. Unlike basic ECR scan-on-push, Inspector provides ongoing vulnerability assessment across the repository, detecting newly disclosed CVEs in existing images as well as fresh pushes.

Why this answer

Amazon Inspector continuous scanning for Amazon ECR automatically scans container images for software vulnerabilities whenever a new image is pushed to the repository. This feature is natively integrated with ECR, requires no additional infrastructure, and provides findings directly in the Inspector console and via AWS Security Hub. Option D is correct because it is the only AWS-native, automated, and fully managed solution that meets the requirement.

Exam trap

Many candidates mistakenly think that any security service (like Macie or Security Hub) can perform vulnerability scanning, when in fact only Inspector has the native capability to scan ECR images continuously and automatically.

How to eliminate wrong answers

Option A is wrong because Amazon Macie is designed for discovering and protecting sensitive data (e.g., PII, credentials) in S3 buckets, not for scanning container images for vulnerabilities. Option B is wrong because AWS Security Hub is a centralized security findings aggregator and does not perform image scanning itself; it can consume findings from Inspector but cannot initiate scans. Option C is wrong because while AWS Lambda can invoke Clair (an open-source vulnerability scanner), this approach requires custom code, management of the Clair infrastructure, and is not a native AWS managed service; it also does not automatically trigger on every push without additional event wiring (e.g., S3 events or ECR push notifications), making it less reliable and more complex than the native solution.

11
MCQmedium

A cloud operations team runs a production Kubernetes cluster on Amazon EKS. During a security review, they discover that the cluster's control plane audit logs are not being captured, preventing investigation of suspicious API server activity. The team must enable audit logging with the least operational overhead while retaining logs for 90 days. Which action should they take?

A.Install the Amazon CloudWatch agent on each worker node and configure it to tail the kubelet and container runtime logs, then set a 90-day retention policy on the log group.
B.Modify the EKS cluster configuration to enable control plane logging for the 'audit' log type, and configure a CloudWatch Logs retention policy of 90 days on the resulting log group.
C.Enable AWS CloudTrail data events for the EKS cluster and set a 90-day retention period in the S3 bucket that receives the trails.
D.Deploy a DaemonSet that runs a Fluent Bit container on every node to collect /var/log/kube-apiserver/audit.log and forward it to CloudWatch Logs.
AnswerB

EKS control plane logging can be enabled per log type, including 'audit', directly from the cluster configuration or via the AWS CLI/API. Logs are delivered to CloudWatch Logs, where a retention policy can be set to 90 days. This requires no agents on nodes and is the native, lowest-overhead method for capturing Kubernetes API server audit events.

Why this answer

The native way to capture Kubernetes API server audit events on EKS is to enable the 'audit' control plane log type on the cluster, which streams events to CloudWatch Logs. Setting a retention policy of 90 days satisfies the retention requirement without deploying agents or managing additional infrastructure. Node-based collection and CloudTrail do not capture control plane audit data.

Exam trap

The trap here is assuming worker nodes host the Kubernetes API server and its audit logs, when on EKS the control plane is fully managed by AWS.

12
MCQhard

During incident response in a cloud environment, a team needs to collect evidence from a compromised EC2 instance without altering the system. Which of the following is the best method to obtain a forensic memory dump?

A.Create an AMI of the instance
B.Enable detailed billing reports
C.Use the AWS CLI to execute a memory dump script on the instance (e.g., via AWS Systems Manager Run Command)
D.Take a snapshot of the root EBS volume
AnswerC

AWS Systems Manager Run Command executes the dump script remotely through the agent, so no interactive login, SSH session or local tooling alters the instance's volatile state. The memory image is written to an attached EBS volume, preserving evidence integrity for later analysis.

Why this answer

Using AWS Systems Manager Run Command to execute a memory dump script on the instance allows the team to capture volatile memory (RAM) while the instance is still running, preserving the system state. This method does not require stopping or modifying the instance, and it can be done remotely via the AWS CLI, making it the best option for forensic memory acquisition.

Exam trap

The trap is selecting disk-based methods (AMI, EBS snapshot) for memory capture; candidates must remember that AMIs and snapshots only capture disk, not RAM, and that memory forensics requires live acquisition.

How to eliminate wrong answers

Option A is wrong because creating an AMI captures the disk state, not memory, and may require stopping the instance, altering its state. Option B is wrong because detailed billing reports are for cost tracking, not forensic evidence. Option D is wrong because an EBS snapshot captures disk data, not volatile memory, and does not preserve running processes or network connections.

13
MCQeasy

An organization uses a cloud-based SIEM solution. Which cloud service provides native integration to stream audit logs into the SIEM?

A.Security monitoring service
B.Centralized logging service
C.Policy management service
D.Recommendation service
AnswerB

A centralised logging service natively collects and forwards audit trails from cloud resources, providing the direct streaming integration the SIEM consumes. It removes the need for custom agents or polling, satisfying the native-integration constraint in the stem.

Why this answer

A centralized logging service is the cloud service that natively aggregates audit logs from multiple sources and can stream them into a SIEM, because its core function is to collect, store, and forward log data. Native integration to stream audit logs into a SIEM is a defining capability of centralized logging services such as AWS CloudTrail with CloudWatch Logs, Azure Monitor Logs, or Google Cloud Logging. The other options describe different security functions that do not provide the log-streaming pipeline the SIEM needs.

Exam trap

CCSP often tests the confusion between log aggregation services and detection or policy services, so candidates must pick the service whose primary purpose is collecting and streaming logs, not one that analyzes or recommends.

How to eliminate wrong answers

Option A is wrong because a security monitoring service focuses on detecting threats and generating findings (for example, Amazon GuardDuty or Security Hub), not on being the native log aggregation and streaming source for a SIEM. Option C is wrong because a policy management service enforces and audits configuration and compliance rules (for example, AWS Config or Azure Policy); it evaluates resource state rather than streaming raw audit logs. Option D is wrong because a recommendation service provides best-practice suggestions (for example, AWS Trusted Advisor or Azure Advisor) and has no role in log ingestion or SIEM integration.

14
MCQmedium

An organization uses Azure Defender for Cloud to protect their hybrid environment. They want to receive alerts about suspicious activities on their Azure Key Vault. Which Defender plan should they enable?

A.Defender for Databases
B.Defender for Containers
C.Defender for Servers
D.Defender for Key Vault
AnswerD

Defender for Key Vault monitors Azure Key Vault control-plane and data-plane operations, detecting anomalous access, suspicious secret retrieval and unusual vault activity. It satisfies the stem's requirement for alerts on suspicious Key Vault activity within the hybrid environment, unlike plans scoped to servers, storage or containers.

Why this answer

Defender for Key Vault is the specific plan designed to provide advanced threat protection for Azure Key Vault. It monitors access patterns and operations on the vault to detect suspicious activities such as unauthorized access attempts, credential theft, or anomalous secret retrieval, and generates security alerts accordingly.

Exam trap

A common trap is that candidates may assume a general plan like Defender for Servers covers all Azure services, but each Defender plan is scoped to a specific service category, such as Defender for Key Vault for Key Vault security.

How to eliminate wrong answers

Option A is wrong because Defender for Databases protects Azure SQL, SQL Server on VMs, and other database services, not Key Vault. Option B is wrong because Defender for Containers secures containerized environments like AKS, ACR, and Kubernetes workloads, not Key Vault. Option C is wrong because Defender for Servers provides threat detection for virtual machines and on-premises servers, not for Key Vault.

15
MCQmedium

An incident response playbook for a cloud environment includes containment steps. For a compromised IAM user in AWS, which action is least likely to be effective for containment?

A.Disable the IAM user
B.Change the IAM user's password
C.Attach a DenyAll policy to the user
D.Disable the IAM user's access keys
AnswerB

Changing the password does not revoke existing credentials. An attacker holding active access keys or session tokens continues operating, so this containment step fails. Deactivating the user, deleting access keys and revoking sessions are required to actually cut off access.

Why this answer

Changing the IAM user's password does not invalidate existing authenticated sessions or tokens (such as temporary credentials from STS or access keys). An attacker who has already established a session or obtained access keys can continue to use them until they expire or are explicitly revoked. Therefore, password change alone is ineffective for immediate containment.

Exam trap

The misconception that changing a password is a universal containment action is common, but in cloud environments with multiple credential types (access keys, STS tokens), password changes alone are insufficient to stop ongoing abuse.

How to eliminate wrong answers

Option A is wrong because disabling the IAM user immediately revokes all permissions and terminates any active sessions, making it a highly effective containment step. Option C is wrong because attaching a DenyAll policy explicitly denies all actions for that user, effectively blocking any further malicious activity even if the user remains enabled. Option D is wrong because disabling the user's access keys prevents any API calls signed with those keys, cutting off a common attack vector for programmatic access.

16
MCQeasy

A cloud operations team is deploying a new web application on Google Cloud Platform (GCP). They need to ensure that all incoming traffic to their Compute Engine instances is inspected for common web attacks such as SQL injection and cross-site scripting. They also want to minimize latency and management overhead. Which GCP service should they use?

A.VPC Service Controls
B.Cloud Armor
C.Identity-Aware Proxy (IAP)
D.Cloud IDS
AnswerB

Cloud Armor is GCP's web application firewall (WAF) and DDoS protection service. It provides preconfigured WAF rules to mitigate OWASP Top 10 risks like SQL injection and XSS. It integrates with HTTP(S) load balancing, inspecting traffic at the edge, which minimizes latency. It is fully managed, reducing operational overhead.

Why this answer

Cloud Armor is the GCP service designed to protect web applications from application-layer attacks. It provides WAF rules that can block SQL injection and XSS, and it integrates with load balancing to inspect traffic at the edge. This minimizes latency and is fully managed, meeting the requirements for security and low overhead.

Exam trap

The trap here is confusing network-level security services like Cloud IDS or access control services like IAP with a web application firewall, which operates at the application layer.

17
MCQmedium

A security engineer is evaluating vulnerability management options for cloud workloads and wants to identify vulnerabilities without installing agents on the operating system. Which approach should be used?

A.Network-based vulnerability scanning
B.Agentless scanning using cloud API-based assessment
C.Agent-based scanning using a cloud-specific vulnerability scanner
D.Container image scanning in a registry
AnswerB

Agentless scanning queries the cloud provider's APIs to enumerate resources and compare their configurations against vulnerability and patch baselines, so no software is installed on the guest OS. This directly satisfies the stem's constraint of identifying vulnerabilities without deploying agents.

Why this answer

Agentless scanning leverages cloud provider APIs (e.g., for configuration and asset inventory) to assess the configuration and patch state of cloud workloads without requiring an OS-level agent. This approach directly meets the requirement of identifying vulnerabilities without installing agents on the operating system, as it reads metadata and configuration snapshots from the cloud control plane.

Exam trap

The trap here is that candidates often confuse 'agentless scanning' with 'network-based scanning,' assuming that any scan without an OS agent must be network-based, but the CCSP exam specifically tests the cloud-native API-driven assessment model as the correct agentless approach for cloud workloads.

How to eliminate wrong answers

Option A is wrong because network-based vulnerability scanning (e.g., Nmap, Nessus) requires network connectivity and often relies on OS fingerprinting or banner grabbing, but it cannot reliably assess internal OS-level vulnerabilities (e.g., missing patches, registry misconfigurations) without agent-based or authenticated access, and it still does not avoid the need for some form of OS interaction. Option C is wrong because agent-based scanning using AWS Inspector explicitly requires installing an agent on the EC2 instance to collect OS-level telemetry, which contradicts the requirement to avoid agents. Option D is wrong because container image scanning in a registry (e.g., Amazon ECR scanning, Trivy) only analyzes static images at rest, not running cloud workloads, and does not address vulnerabilities in the OS of running instances or virtual machines.

18
MCQeasy

A company runs a regulated workload in Microsoft Azure and must retain all administrative activity logs for seven years to satisfy an auditor. The logs must be immutable and retrievable even if the original resource is deleted. Which Azure capability should the team implement?

A.Azure Storage immutable blob storage with a time-based retention policy
B.Azure Event Hubs streaming activity logs to a third-party SIEM
C.A Log Analytics workspace with a 30-day interactive retention and archive tier
D.Azure Monitor activity log with the default 90-day retention setting
AnswerA

Immutable blob storage with a time-based retention policy written in legal-hold or locked policy mode prevents modification or deletion of blobs for the specified interval, and the policy can be set to seven years. Diagnostic settings can export activity logs to the storage account, meeting the immutability and retrievability requirements.

Why this answer

The requirement combines long retention, immutability, and availability after resource deletion. Azure Storage immutable blob storage with a locked time-based retention policy holds blobs unalterable for the configured interval, and diagnostic settings can route activity logs there. That pairing meets the seven-year immutability mandate in a way plain log retention or streaming pipelines cannot.

Exam trap

The trap here is treating long Log Analytics retention or Event Hubs streaming as equivalent to immutability, when only a locked immutability policy on blob storage actually prevents deletion or alteration of the retained logs.

19
Multi-Selectmedium

A cloud security team must harden the management plane for a Kubernetes cluster running on Google Kubernetes Engine. They want to limit who can reach the control plane endpoint and ensure that any administrative action taken against the cluster is attributable to a named identity. (Choose two.)

Select 2 answers
A.Enable network policy enforcement on the cluster's node pools
B.Use Binary Authorization to require attestations before workloads deploy
C.Apply PodSecurity admission with the restricted profile to all namespaces
D.Enable Cloud Audit Logs for the GKE cluster's Admin Activity and Data Access logs
E.Configure authorized networks on the cluster to restrict control plane access to approved CIDR ranges
AnswersD, E

Cloud Audit Logs capture administrative actions against the cluster and its resources, recording the calling identity, the API method, and the timestamp. Enabling Admin Activity and Data Access audit logs provides the attribution the team needs to trace any administrative action to a named principal.

Why this answer

Restricting control plane reachability is accomplished with authorized networks, which constrain the source CIDRs permitted to contact the API server. Attribution of administrative actions requires Cloud Audit Logs, specifically Admin Activity and Data Access logs, which record the identity and method for each call. Together they harden the management plane and provide accountability.

Exam trap

The trap here is confusing data-plane hardening controls such as network policy, PodSecurity admission, and Binary Authorization with management-plane controls that limit API server reachability and record administrative identity.

20
MCQhard

During a forensic investigation of a suspected data exfiltration incident in AWS, a security team needs to analyze network traffic to identify the destination IP addresses and volume of data transferred. Which data source is most appropriate for this analysis?

A.VPC Flow Logs
B.AWS Config configuration history
C.AWS CloudTrail management events
D.Amazon S3 access logs
AnswerA

VPC Flow Logs capture IP-level metadata for traffic traversing elastic network interfaces, including source and destination addresses, ports, protocol and bytes transferred. This directly satisfies the requirement to identify exfiltration destinations and quantify transferred volume, which CloudTrail management events cannot provide.

Why this answer

VPC Flow Logs capture metadata about IP traffic flowing to and from network interfaces in a VPC, including source/destination IP addresses, ports, protocols, and the number of bytes transferred. This makes them the ideal data source for identifying the destination IP addresses and volume of data exfiltrated, as they provide per-flow byte counts and packet-level details without requiring packet capture.

Exam trap

ISC2 CCSP often tests the distinction between logs that capture API-level activity (CloudTrail) versus network-level metadata (Flow Logs), and candidates mistakenly choose CloudTrail because they think 'management events' includes network traffic, but it only records control plane operations, not data plane flows.

How to eliminate wrong answers

Option B (AWS Config configuration history) is wrong because it records resource configuration changes (e.g., security group rules, instance types) over time, not network traffic or data transfer volumes. Option C (AWS CloudTrail management events) is wrong because it logs API calls that modify AWS resources (e.g., CreateInstance, AuthorizeSecurityGroupIngress), not the actual network packets or byte counts flowing through the VPC. Option D (Amazon S3 access logs) is wrong because they only log requests made to S3 buckets (e.g., GET, PUT, DELETE operations) and do not capture general VPC network traffic or destination IP addresses for exfiltration outside of S3 interactions.

21
MCQhard

A financial services company uses Azure and must ensure that all administrative actions in their Azure subscription are logged and that logs are stored in an immutable storage account for 7 years. They also need to be able to alert on specific critical operations, such as deletion of a resource group. Which combination of Azure services should they implement?

A.Azure Monitor activity log, Azure Event Hubs, and Azure Stream Analytics.
B.Azure Security Center (now Microsoft Defender for Cloud), Azure SQL Database auditing, and Azure Logic Apps.
C.Azure Monitor activity log, Azure Storage with immutable blob storage, and Azure Monitor alerts.
D.Azure Log Analytics workspace, Azure Monitor alerts, and Azure Automation runbooks.
AnswerC

The Azure Monitor activity log captures subscription-level control plane operations, including resource group deletions. Exporting to a storage account with immutable blob storage (using time-based retention policies) ensures logs cannot be altered or deleted for the specified period. Azure Monitor alerts can trigger on specific events from the activity log, such as Delete Resource Group, providing real-time notification.

Why this answer

The Azure Monitor activity log is the source for subscription-level administrative events. To achieve immutability, logs must be exported to a storage account configured with immutable blob storage policies. Azure Monitor alerts can be set up to trigger on specific operations like resource group deletion.

This trio meets logging, retention, and alerting requirements.

Exam trap

The trap here is assuming that Log Analytics or Event Hubs provide immutable long-term storage, when they are designed for analysis and transient processing, not compliance-grade retention.

22
MCQmedium

A security operations team at a healthcare company running workloads on AWS needs to ensure that all API activity in their production account is recorded and retained for 12 months, with the ability to search for specific events during a forensic investigation. The compliance officer mandates that logs must be protected from deletion by any user, including administrators. Which AWS service and configuration should the team implement to meet these requirements?

A.Enable AWS CloudTrail with a multi-region trail, deliver logs to a CloudWatch Logs log group with a 12-month retention policy, and set up a subscription filter to S3.
B.Enable AWS Config to record configuration changes and deliver snapshots to an S3 bucket with a lifecycle policy to retain for 12 months.
C.Enable VPC Flow Logs to capture all traffic, store them in CloudWatch Logs with a 12-month retention policy, and restrict access using IAM policies.
D.Enable AWS CloudTrail with a multi-region trail, deliver logs to an S3 bucket with versioning and MFA delete enabled, and apply a bucket policy that denies deletion.
AnswerD

CloudTrail records API activity across regions. Delivering to an S3 bucket with versioning and MFA delete prevents accidental or malicious deletion. A bucket policy explicitly denying s3:DeleteObject for all principals, including administrators, enforces immutability. This combination meets retention and forensic search needs, as logs are stored durably and accessible via Athena or CloudTrail Lake.

Why this answer

CloudTrail is the AWS service that records API activity. To meet retention and immutability, logs should be stored in S3 with versioning and MFA delete, and a bucket policy that denies deletion for all principals. This ensures logs cannot be tampered with, even by administrators, and can be queried for forensic purposes.

Other services like AWS Config or VPC Flow Logs capture different data types and lack the required protection mechanisms.

Exam trap

The trap here is confusing AWS Config or VPC Flow Logs with CloudTrail for API activity logging, and assuming that IAM policies or lifecycle rules alone can prevent deletion by administrators.

23
Multi-Selecteasy

A cloud security engineer needs to ensure that logs from multiple AWS accounts are centrally stored in a security account for analysis. Which TWO services can be used to aggregate logs across accounts? (Choose two.)

Select 2 answers
A.Amazon CloudWatch Logs with cross-account subscription filters
B.AWS Config
C.AWS Security Hub
D.Amazon S3 with cross-account bucket policies
E.Amazon GuardDuty
AnswersA, D

CloudWatch Logs cross-account subscription filters stream log events in near real time from source accounts to a Kinesis Data Streams or Lambda destination in the security account, satisfying the centralised aggregation requirement without polling. This native mechanism avoids duplicating log groups per account, unlike resource-policy-based sharing.

Why this answer

Option A is correct because CloudWatch Logs supports cross-account subscription filters, which allow a destination account (the security account) to receive real-time log events from source accounts via a destination Logs resource policy and a subscription filter, enabling centralized log aggregation. Option D is correct because Amazon S3 with cross-account bucket policies lets multiple accounts write their logs (e.g., via PutObject permissions in the bucket policy) into a single central bucket owned by the security account, which is a common pattern for centralized log storage and analysis. Option B (AWS Config) is a configuration compliance and resource inventory service, not a cross-account log aggregation mechanism.

Option C (AWS Security Hub) aggregates security findings and compliance checks across accounts, not raw logs. Option E (Amazon GuardDuty) is a threat detection service that generates findings, not a general log aggregation service.

Exam trap

A common trap is mixing up services that aggregate raw logs (CloudWatch Logs, S3) with those that aggregate security findings or metadata (Security Hub, GuardDuty). Candidates may incorrectly select Security Hub or GuardDuty for log aggregation.

24
MCQmedium

A cloud operations team manages 200 Amazon EC2 instances spread across three AWS accounts. They must continuously assess the instances for missing OS patches and misconfigured software, and they want findings aggregated in a single console with severity ratings and remediation runbooks. Which AWS service should the team deploy to meet these requirements?

A.AWS Trusted Advisor
B.AWS Config
C.Amazon GuardDuty
D.Amazon Inspector
AnswerD

Amazon Inspector continuously scans EC2 instances using the Systems Manager agent to detect software vulnerabilities and unintended network exposure, then assigns severity ratings and aggregates findings centrally across accounts via AWS Organizations and delegated administrator. This directly matches the requirement for ongoing OS patch and misconfiguration assessment with consolidated findings and remediation guidance.

Why this answer

Continuous detection of missing OS patches and software misconfigurations inside EC2 instances requires a vulnerability management service with host-level visibility. Amazon Inspector uses the SSM agent to inventory packages and network reachability, assigns severity, and supports multi-account aggregation through a delegated administrator, so findings from all three accounts appear in one console with remediation runbooks.

Exam trap

The trap here is assuming configuration-compliance services such as AWS Config or Trusted Advisor can see inside the guest operating system, when only a host-based vulnerability scanner like Amazon Inspector inventories installed packages and patches.

25
MCQeasy

A cloud security engineer needs to review who created or modified IAM policies in an Azure subscription over the past 90 days, and must retain that evidence for compliance. Which Azure-native capability should be used to collect and store these records?

A.Microsoft Defender for Cloud secure score
B.Azure Activity Log with a diagnostic setting to a Log Analytics workspace
C.Azure Policy compliance reports
D.Azure Monitor metrics
AnswerB

The Azure Activity Log records subscription-level control-plane operations including role assignment and policy changes, with the caller identity and timestamp. Routing it through a diagnostic setting to a Log Analytics workspace enables long-term retention and querying, satisfying the 90-day review and compliance retention needs.

Why this answer

The Azure Activity Log is the subscription's control-plane audit record and captures write operations such as role assignment and policy edits along with the calling identity. Exporting it via a diagnostic setting to a Log Analytics workspace provides queryable, retainable evidence, which is exactly what is needed to review IAM changes over 90 days.

Exam trap

The trap here is assuming that posture or compliance tooling like secure score or Azure Policy provides an audit trail of who made a change.

26
MCQhard

During a cloud incident response, a security team needs to collect memory from a compromised EC2 instance for forensic analysis. Which method is most appropriate for acquiring a memory dump?

A.Analyze CloudTrail logs for the instance's API calls.
B.Take a snapshot of the EBS volumes attached to the instance.
C.Review VPC Flow Logs for network traffic.
D.Use AWS Systems Manager to run a memory acquisition script on the instance.
AnswerD

AWS Systems Manager Run Command executes a memory acquisition script directly on the running EC2 instance, preserving volatile memory contents. This avoids rebooting or stopping the instance, which would destroy the RAM evidence needed for forensic analysis.

Why this answer

Memory acquisition on a running EC2 instance requires executing a tool on the instance itself, and AWS Systems Manager (SSM) Run Command allows the security team to run a memory acquisition script remotely without SSH access or opening inbound ports. This preserves the volatile memory contents while maintaining an auditable, IAM-controlled execution path. It is the most appropriate method for capturing RAM from a live instance.

Exam trap

CCSP often tests cloud forensic order of volatility, and candidates may pick EBS snapshots or logs because they are familiar AWS artifacts — the trap is forgetting that memory is volatile and cannot be captured from disk or API logs.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs record API activity, not the contents of instance memory, and cannot reconstruct process memory or encryption keys. Option B is wrong because an EBS snapshot captures disk state, not volatile memory, and would miss in-memory malware, credentials, and network connections. Option C is wrong because VPC Flow Logs capture metadata about network flows (IPs, ports, bytes), not memory contents or process-level artifacts.

27
MCQeasy

Which of the following is a primary purpose of a SOAR (Security Orchestration, Automation and Response) platform in cloud security operations?

A.To automate response to security incidents by executing predefined playbooks.
B.To provide a centralized dashboard for cloud cost management.
C.To scan container images for vulnerabilities.
D.To enforce identity and access management policies.
AnswerA

SOAR platforms integrate security tools and execute predefined playbooks automatically, triggering containment, enrichment and notification actions when alerts fire. This orchestration and automation directly satisfies the stem's requirement to accelerate incident response beyond manual analyst triage.

Why this answer

SOAR platforms are designed to orchestrate security tools, automate repetitive response tasks, and execute predefined playbooks that coordinate actions across multiple systems during an incident. This reduces mean time to respond (MTTR) and enables consistent, repeatable incident handling. The primary purpose is automation of incident response workflows, not cost management, vulnerability scanning, or IAM enforcement.

Exam trap

CCSP often tests whether candidates confuse SOAR with other security tools — the trap is picking a tool that performs a specific function (scanning, IAM) rather than the orchestration and automation of response workflows.

How to eliminate wrong answers

Option B is wrong because cloud cost management is handled by FinOps tools or cloud provider cost explorers, not SOAR platforms — SOAR focuses on security operations, not financial operations. Option C is wrong because scanning container images for vulnerabilities is a function of vulnerability scanners (e.g., Trivy, Clair, Anchore) or CSPM tools, not SOAR — SOAR may consume scanner findings but does not perform the scanning itself. Option D is wrong because enforcing IAM policies is the role of identity providers and IAM systems (e.g., Okta, Azure AD, AWS IAM), not SOAR — SOAR may integrate with IAM for response actions like disabling a user, but it does not enforce policies.

28
MCQhard

A security team is investigating a potential data exfiltration incident where a large volume of data was downloaded from a cloud storage bucket. Which log source would provide the most granular details about the GET requests, including the requester identity and source IP?

A.VPC flow logs
B.Cloud storage access logs
C.Cloud management events (e.g., CloudTrail equivalent)
D.Log aggregation service for storage (e.g., CloudWatch equivalent)
AnswerB

Cloud storage access logs capture per-request records for object operations, including the GET method, requester identity, source IP address and timestamp. This granular detail satisfies the requirement to identify who downloaded the data and from where during the exfiltration investigation.

Why this answer

Cloud storage access logs provide detailed records of requests made to a bucket, including requester, source IP, and objects accessed. Cloud audit logs (data events) can also log storage operations, but storage access logs are more granular for this purpose.

29
MCQmedium

An organization is implementing a cloud SIEM solution to centralize security monitoring across multiple AWS accounts. Which service should be used to aggregate security findings and send them to a third-party SIEM like Splunk?

A.AWS CloudTrail
B.AWS Security Hub
C.AWS GuardDuty
D.AWS Config
AnswerB

AWS Security Hub aggregates findings across accounts and Regions via a single pane, then forwards them to third-party SIEMs such as Splunk through native integrations or EventBridge. This satisfies the requirement to centralise findings from multiple AWS accounts before onward delivery.

Why this answer

AWS Security Hub is the correct service because it is designed to aggregate security findings from multiple AWS services (e.g., GuardDuty, Inspector, Macie) and AWS accounts, and then forward them to third-party SIEM solutions like Splunk via AWS EventBridge or direct integration. This centralizes security alerts into a single dashboard and stream, enabling efficient monitoring across a multi-account environment.

Exam trap

CCSP often tests the distinction between services that generate findings (like GuardDuty) versus services that aggregate and normalize findings (like Security Hub), leading candidates to pick GuardDuty because they confuse detection with centralization.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity logs, not security findings, and it does not aggregate findings across accounts or natively forward to a SIEM. Option C is wrong because AWS GuardDuty is a threat detection service that generates findings, but it cannot aggregate findings from multiple accounts or services; it relies on Security Hub for centralization. Option D is wrong because AWS Config tracks resource configuration changes and compliance, not security findings, and it lacks the aggregation and SIEM forwarding capabilities of Security Hub.

30
MCQmedium

A cloud operations team runs a Kubernetes cluster on Google Kubernetes Engine (GKE). A recent audit found that several pods were scheduled onto nodes that do not meet the organization's hardened baseline, and the team wants to enforce that only nodes with specific labels are eligible for certain workloads. Which Kubernetes mechanism should the team implement?

A.PodDisruptionBudget
B.Horizontal Pod Autoscaler
C.Node affinity combined with node labels
D.NetworkPolicy
AnswerC

Node affinity rules in the pod spec use node labels as match expressions, so only nodes carrying the required hardened baseline label will be eligible. This directly enforces the placement requirement on GKE without needing a custom scheduler, and it can be made mandatory with requiredDuringSchedulingIgnoredDuringExecution.

Why this answer

Node affinity uses node labels as hard or soft match rules in the pod specification, so requiring a specific label ensures the scheduler only places the workload on nodes that carry the hardened baseline. This is the native Kubernetes control for constraining placement without replacing the default scheduler or altering cluster autoscaling behavior.

Exam trap

The trap here is confusing scheduling controls with runtime controls, assuming that a policy or disruption budget can dictate which node a pod lands on.

31
MCQeasy

What is the primary purpose of cloud security posture management (CSPM) tools?

A.To provide a centralized log storage solution.
B.To detect real-time threats like malware and intrusions.
C.To manage user identities and access permissions.
D.To assess and improve the security configuration of cloud resources against benchmarks.
AnswerD

CSPM continuously assesses cloud resource configurations against benchmarks such as CIS and identifies misconfigurations, drift and compliance gaps. This directly satisfies the stem's focus on the primary purpose: evaluating and hardening the security posture of provisioned cloud resources, rather than runtime workload protection or identity governance.

Why this answer

CSPM tools are designed to continuously monitor cloud environments, assess configurations against industry benchmarks (e.g., CIS, NIST, PCI DSS), and provide remediation guidance. Their primary purpose is to identify misconfigurations and compliance gaps, not to perform real-time threat detection or centralized logging.

Exam trap

ISC2 CCSP often tests the distinction between CSPM (configuration assessment) and other security tools (e.g., SIEM, IDS/IPS, IAM), so the trap here is confusing CSPM's proactive compliance monitoring with reactive threat detection or log management.

How to eliminate wrong answers

Option A is wrong because centralized log storage is the function of services like AWS CloudTrail, Azure Monitor, or GCP Cloud Logging, not CSPM tools which focus on configuration assessment. Option B is wrong because real-time threat detection for malware and intrusions is handled by dedicated security tools like AWS GuardDuty, Azure Defender, or GCP Threat Detection, whereas CSPM tools are configuration-focused and not designed for active threat hunting. Option C is wrong because managing user identities and access permissions is the role of IAM services (e.g., AWS IAM, Azure AD, GCP IAM), not CSPM tools which evaluate the security posture of resources but do not directly manage identities or permissions.

32
MCQmedium

A cloud security team is implementing a centralized logging solution for AWS. They need to ensure that all API activity in their production account is logged and that the logs are stored immutably for 7 years to meet compliance requirements. Which service should they use to capture the API activity?

A.Amazon CloudWatch Logs
B.AWS Config
C.Amazon VPC Flow Logs
D.AWS CloudTrail
AnswerD

AWS CloudTrail records API activity in an AWS account, including actions taken by users, roles, and AWS services. It provides event history and can deliver logs to an S3 bucket, which can be configured with Object Lock for immutability. This meets the requirement to capture all API activity and retain logs immutably for 7 years.

Why this answer

AWS CloudTrail is the service that records API activity in an AWS account, making it the correct choice for capturing all API calls. It integrates with Amazon S3, where logs can be stored with Object Lock to enforce immutability for compliance. The other services either focus on resource configuration, network traffic, or application logs, and cannot provide the comprehensive API auditing required.

Exam trap

The trap here is confusing AWS Config with CloudTrail, as both are auditing services, but only CloudTrail records API activity.

33
MCQeasy

An organization is using GCP and wants to collect audit logs for all API calls made within the project. Which GCP service should be enabled to capture these logs?

A.VPC Flow Logs
B.Cloud Audit Logs
C.Cloud Monitoring
D.Cloud Security Command Center
AnswerB

Cloud Audit Logs captures Admin Activity and Data Access entries for every API call in the project, satisfying the requirement to record all API activity. Enabling it at project level provides the audit trail directly, unlike Cloud Logging, which aggregates logs but does not itself generate API audit records.

Why this answer

Cloud Audit Logs is the correct GCP service because it automatically records API calls and administrative activities within a GCP project. It captures Admin Activity, Data Access, System Event, and Policy Denied logs, providing a comprehensive audit trail of who did what, where, and when. This is essential for security, compliance, and forensic investigations.

Exam trap

CCSP often tests the confusion between network-level logging (VPC Flow Logs) and API-level auditing (Cloud Audit Logs), so candidates must remember that audit logs capture control plane and data plane API calls, not packet flows.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) for VPC subnets, not API calls or audit events. Option C is wrong because Cloud Monitoring is for collecting metrics, traces, and dashboards to observe system performance, not for auditing API activity. Option D is wrong because Cloud Security Command Center aggregates security findings and asset inventory, but it does not itself capture API audit logs; it may consume them, but the primary service for audit logs is Cloud Audit Logs.

34
MCQmedium

An organization wants to ensure that all resources are compliant with CIS benchmarks. Which cloud service provides a unified view of compliance posture and recommendations?

A.Security Information and Event Management (SIEM) tool
B.Cloud Security Posture Management (CSPM) tool
C.Cloud monitoring and logging service
D.Policy-as-code enforcement service
AnswerB

A CSPM tool continuously assesses cloud resources against benchmarks such as CIS, aggregating findings into a unified compliance dashboard with prioritised remediation recommendations. This directly satisfies the stem's requirement for a single view of compliance posture, unlike native logging or inventory services that report raw configuration data without benchmark mapping.

Why this answer

A cloud security posture management (CSPM) tool provides a unified, centralized view of an organization's security and compliance posture, including specific recommendations aligned with CIS benchmarks. It aggregates findings from various security controls into a single score and actionable guidance, making it the correct service for monitoring compliance against CIS standards.

Exam trap

The trap here is that candidates confuse a policy enforcement service (which enforces rules) with a cloud security posture management (CSPM) tool (which provides the unified compliance posture and scoring), or they mistakenly think cloud monitoring and logging or SIEM services can serve as a compliance dashboard when they are designed for other purposes.

How to eliminate wrong answers

Option A is wrong because Azure Sentinel is a cloud-native SIEM/SOAR solution focused on threat detection, investigation, and response, not on providing a unified compliance posture view or CIS benchmark recommendations. Option C is wrong because Azure Monitor collects and analyzes telemetry data (metrics, logs) for performance and health monitoring, but it does not natively aggregate compliance posture or provide CIS benchmark-specific recommendations. Option D is wrong because Azure Policy enforces and audits compliance rules (e.g., tagging, allowed locations) but does not present a unified, scored compliance posture view; it is a building block that feeds into Secure Score, not the unified dashboard itself.

35
Multi-Selecteasy

A security engineer is implementing automated incident response for common cloud threats. Which TWO cloud services can be used together to create a serverless orchestration workflow for incident response? (Choose two.)

Select 2 answers
A.Orchestration service for serverless workflows
B.Serverless compute service
C.Infrastructure as code service
D.Virtual machine service
E.Vulnerability management service
AnswersA, B

A serverless orchestration service, such as AWS Step Functions, sequences incident response steps, branching and retrying between Lambda invocations. It satisfies the serverless orchestration workflow requirement by coordinating state across tasks without provisioning servers, complementing the serverless compute service chosen alongside it.

Why this answer

Option A, an orchestration service for serverless workflows (such as AWS Step Functions), is correct because it provides the state-machine logic that coordinates, sequences, and branches incident-response steps without managing servers. Option B, a serverless compute service (such as AWS Lambda), is correct because it executes the actual response actions—enriching findings, isolating resources, or notifying teams—as event-driven functions invoked by the orchestration workflow. Together, A and B form a fully serverless orchestration pipeline: the workflow service defines the incident-response state machine while the compute service runs the per-step code.

Option C, infrastructure as code, is for declaratively provisioning resources, not for orchestrating runtime incident-response logic. Option D, a virtual machine service, requires managing persistent instances and is not serverless. Option E, vulnerability management, identifies weaknesses but does not orchestrate or execute response workflows.

Exam trap

The trap is confusing orchestration with infrastructure as code or monitoring services; candidates might pick CloudFormation or Inspector, but the key is serverless workflow orchestration and compute.

36
MCQhard

An organization uses GCP and wants to detect container threats such as privilege escalation attempts within Kubernetes Engine. Which GCP service is designed specifically for this purpose?

A.Container Threat Detection
B.Cloud Security Scanner
C.Event Threat Detection
D.Cloud Audit Logs
AnswerA

Container Threat Detection continuously monitors Kubernetes Engine runtime activity, flagging privilege escalation, suspicious binaries and reverse shells inside containers. It operates at the workload level rather than scanning images or network flows, directly matching the requirement to detect in-cluster container threats.

Why this answer

Container Threat Detection (CTD) is a GCP service purpose-built to identify threats within Google Kubernetes Engine (GKE) containers, including privilege escalation attempts, by analyzing runtime behavior and Kubernetes audit logs. It uses machine learning and rule-based detection to spot anomalies like container breakout, unauthorized system calls, and attempts to escalate privileges via capabilities or security contexts. This makes it the correct choice for detecting container-specific threats in GKE.

Exam trap

ISC2 often tests the distinction between general threat detection services (like Event Threat Detection) and container-specific services (like Container Threat Detection), so candidates may confuse Event Threat Detection as covering all cloud threats, missing that it does not analyze container runtime behavior.

How to eliminate wrong answers

Option B (Cloud Security Scanner) is wrong because it is designed to scan web applications for vulnerabilities like XSS and SQL injection, not to detect runtime container threats or privilege escalation in Kubernetes. Option C (Event Threat Detection) is wrong because it focuses on identifying threats from cloud events such as suspicious IAM activity or compromised service accounts, not container-level runtime threats within GKE. Option D (Cloud Audit Logs) is wrong because it is a logging service that records API calls and administrative actions, not a detection service; it provides raw data but does not analyze or alert on container threats like privilege escalation.

37
MCQmedium

A security analyst is investigating a potential compromise of an AWS EC2 instance. Which step should be taken FIRST to contain the incident and prevent further damage?

A.Terminate the EC2 instance immediately.
B.Take a snapshot of the instance for forensic analysis.
C.Isolate the EC2 instance by updating the security group to deny all traffic.
D.Disable the IAM role attached to the instance.
AnswerC

Replacing the instance's security group with one denying all inbound and outbound traffic cuts attacker access instantly while leaving the instance running. Memory, processes and disk state remain intact for forensic capture, unlike termination or reboot, which would destroy volatile evidence.

Why this answer

The first priority in incident response is containment. Updating the security group to deny all traffic immediately isolates the EC2 instance from network communication, preventing lateral movement or data exfiltration while preserving the instance for further investigation. This aligns with the NIST SP 800-61 incident response framework, which emphasizes containment before eradication or recovery.

Exam trap

A common misconception is that immediate termination (Option A) is the fastest containment method, but this violates the principle of preserving evidence and may hinder forensic investigation.

How to eliminate wrong answers

Option A is wrong because terminating the instance destroys volatile data (e.g., memory, running processes, network connections) and prevents forensic analysis, which may be critical for understanding the attack vector. Option B is wrong because taking a snapshot is a forensic step that should occur after containment, not before; performing it first could allow the attacker to continue exfiltrating data or spreading to other resources. Option D is wrong because disabling the IAM role does not stop network-level attacks or data exfiltration; the instance could still communicate with external hosts, and the attacker might already have established persistence or backdoor access.

38
MCQeasy

An organization wants to implement a cloud security automation solution that can automatically remediate non-compliant resources in Azure. Which Azure service should be used to create remediation tasks?

A.Azure Policy
B.Azure Security Center
C.Azure Automation
D.Azure Logic Apps
AnswerA

Azure Policy evaluates resources against built-in or custom definitions and, through remediation tasks, automatically corrects non-compliant resources using managed identities. This directly satisfies the requirement for automated remediation in Azure, unlike monitoring or advisory services that only detect and report drift without enforcing configuration changes.

Why this answer

Azure Policy includes 'remediation tasks' that can automatically fix non-compliant resources, often using managed identities.

39
MCQmedium

An organization ingests AWS CloudTrail logs into a centralized SIEM for correlation. They want to detect an attacker who exfiltrates data by downloading large volumes from an S3 bucket. Which SIEM correlation rule would best detect this?

A.Alert on multiple failed login attempts
B.Alert on high volume of GetObject requests from a single IP
C.Alert on root account usage
D.Alert when a new IAM user is created
AnswerB

GetObject requests represent actual object downloads, so alerting when a single IP generates an abnormally high volume of them detects bulk data retrieval. Aggregating by source IP over a time window satisfies the exfiltration scenario, distinguishing sustained mass downloading from routine sporadic access.

Why this answer

Exfiltration of data from S3 typically involves a high volume of GetObject API calls from a single source IP. A SIEM correlation rule that triggers on a threshold of GetObject requests from the same IP address directly detects this anomalous download behavior, which is a key indicator of data exfiltration.

Exam trap

This exam often tests the distinction between detection of the exfiltration action itself (high volume of GetObject requests) versus precursor or unrelated events (failed logins, root usage, IAM creation), leading candidates to choose a rule that detects a different phase of the attack chain.

How to eliminate wrong answers

Option A is wrong because multiple failed login attempts indicate a brute-force attack on authentication, not data exfiltration from S3. Option C is wrong because root account usage is a security concern for privilege escalation or configuration changes, but it does not specifically detect bulk data downloads from S3. Option D is wrong because creating a new IAM user is an administrative action that could be part of an attack chain, but it does not directly detect the exfiltration event itself.

40
MCQmedium

A company uses Azure Policy with remediation tasks to automatically fix non-compliant resources. Which scenario can be automatically remediated using a built-in policy?

A.A virtual machine missing the Log Analytics agent
B.A user creating a new Azure subscription
C.A SQL database with advanced data security disabled
D.A storage account with public network access enabled
AnswerA

The built-in Deploy Log Analytics agent policy uses the deployIfNotExists effect, so a remediation task installs the missing extension on virtual machines flagged as non-compliant. This directly satisfies the automatic remediation scenario for VMs lacking the Log Analytics agent.

Why this answer

The built-in Azure Policy 'Deploy Log Analytics agent to Windows VMs' includes a remediation task that automatically installs the Log Analytics agent on existing VMs that are missing it. This is a DeployIfNotExists policy effect, which triggers a remediation task to correct non-compliance without manual intervention.

Exam trap

The CCSP exam often tests the distinction between policy effects (Audit, Deny, DeployIfNotExists) and which ones support automatic remediation, leading candidates to assume any non-compliance can be auto-fixed if a policy exists, but only DeployIfNotExists and Modify effects enable remediation tasks.

How to eliminate wrong answers

Option B is wrong because Azure Policy cannot automatically remediate the creation of a new Azure subscription; subscription creation is a tenant-level action that requires Azure RBAC or Azure Blueprints, not a policy with remediation. Option C is wrong because disabling advanced data security on a SQL database is a configuration that can be audited by Azure Policy, but the built-in policies for SQL advanced data security typically use AuditIfNotExists or Deny effects, not DeployIfNotExists with remediation tasks, so automatic remediation is not available out-of-the-box. Option D is wrong because while Azure Policy can audit or deny storage accounts with public network access enabled, the built-in policies for this setting use Deny or Audit effects, not DeployIfNotExists, meaning they block or report non-compliance but do not automatically remediate existing non-compliant resources.

41
MCQmedium

A security engineer is investigating a potential data exfiltration incident involving an Amazon S3 bucket. Which set of logs would provide the most relevant information to identify the source IP and API calls made to the bucket?

A.VPC Flow Logs for the subnet where the bucket resides
B.AWS Config configuration history for the S3 bucket
C.AWS CloudTrail data events for the S3 bucket
D.Amazon CloudWatch Logs for the EC2 instance accessing the bucket
AnswerC

CloudTrail data events record object-level S3 API activity, capturing the caller's source IP and the specific operations performed on the bucket. Management events alone omit object-level calls, so data events are required to trace the exfiltration's origin and API sequence.

Why this answer

AWS CloudTrail data events capture object-level S3 API activity such as GetObject, PutObject, and DeleteObject, including the identity and source IP of the caller. This is exactly the evidence needed to trace who accessed or exfiltrated objects from a specific bucket. Management events alone would not show object reads, so data events must be explicitly enabled for the bucket.

Exam trap

The trap is assuming that network-level logs (VPC Flow Logs) or configuration logs (AWS Config) can reveal API-level activity; candidates must remember that only CloudTrail data events capture S3 object-level operations and caller identity.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs only record IP-level metadata (source/dest IP, port, bytes, accept/reject) for traffic traversing ENIs; S3 is a regional service accessed via public endpoints, and flow logs cannot show S3 API calls or object names. Option B is wrong because AWS Config records configuration state changes (e.g., bucket policy, ACL, encryption settings), not data-plane access activity. Option D is wrong because CloudWatch Logs on an EC2 instance only capture what the instance's OS or application writes locally; they do not record S3 API calls made by other principals or by the instance unless the app explicitly logs them.

42
MCQhard

A cloud security engineer is responsible for securing a Kubernetes cluster running on Google Kubernetes Engine (GKE). They need to detect and respond to runtime threats such as cryptomining and reverse shell attempts. They want a solution that integrates natively with GKE and provides detailed container-level visibility. Which GCP service should they use?

A.Google Cloud's Cloud IDS
B.Google Cloud's Container Threat Detection
C.Google Cloud's Anthos Service Mesh
D.Google Cloud Security Command Center (SCC)
AnswerB

Container Threat Detection is a built-in service in GKE that monitors container runtime activity. It detects threats like cryptomining, reverse shells, and malware execution by analyzing system calls and process behavior. It provides detailed container-level visibility and integrates natively with GKE, sending findings to Security Command Center. This meets the requirement for runtime threat detection.

Why this answer

Container Threat Detection is a GKE-native service that monitors runtime activity within containers. It detects threats such as cryptomining and reverse shells by analyzing system calls and process behavior. It provides container-level visibility and integrates with Security Command Center for centralized findings.

This makes it the correct choice for runtime threat detection in GKE.

Exam trap

The trap here is confusing network-level intrusion detection (Cloud IDS) or posture management (SCC) with container runtime security, which requires deep introspection of container processes.

43
MCQeasy

A healthcare company stores regulated data in Amazon S3. An auditor requires proof that objects are protected against accidental deletion or overwrite for a fixed period, and that the protection cannot be removed even by the root account. Which S3 feature should the security team implement?

A.S3 Object Lock in compliance mode with a retention period matching the required fixed duration.
B.S3 Object Lock in governance mode with a retention period matching the required fixed duration.
C.A bucket policy that denies s3:DeleteObject and s3:PutObject to all principals except a dedicated backup role.
D.S3 Versioning with a lifecycle rule that transitions noncurrent versions to S3 Glacier Deep Archive.
AnswerA

S3 Object Lock in compliance mode prevents object versions from being overwritten or deleted for the specified retention period. Critically, compliance mode cannot be bypassed or shortened by any user, including the AWS account root user, satisfying the auditor's immutability requirement. Governance mode, by contrast, allows privileged users to alter retention.

Why this answer

S3 Object Lock in compliance mode creates a write-once-read-many (WORM) protection that no principal, including the root account, can bypass or shorten during the retention period. Governance mode and bucket policies are administratively changeable, and versioning alone does not prevent deletion. Compliance mode directly satisfies the immutability and fixed-duration requirements.

Exam trap

The trap here is treating versioning or a restrictive bucket policy as equivalent to WORM protection, when both can be reversed by privileged accounts.

44
MCQmedium

A company uses Microsoft Azure and wants to implement just-in-time (JIT) virtual machine access to reduce the attack surface. They need to ensure that only authorized users can access VMs on specific management ports, and that access is granted for a limited time. Which Azure service should they use?

A.Azure Bastion
B.Network security groups (NSGs) with service tags
C.Azure Firewall
D.Azure Security Center (now Microsoft Defender for Cloud) just-in-time VM access
AnswerD

Microsoft Defender for Cloud's just-in-time VM access allows you to lock down inbound traffic to VMs, permitting access only when needed and for a specified duration. It integrates with Azure RBAC and network security groups to grant temporary access on management ports, reducing exposure to attacks.

Why this answer

Microsoft Defender for Cloud's just-in-time VM access is designed to reduce the attack surface by allowing access to VMs only when needed, for a limited time, and on specific ports. It uses Azure RBAC to control who can request access and NSGs to enforce the temporary rules. This meets the requirement for time-limited, authorized access.

Exam trap

The trap here is assuming that Azure Bastion or NSGs provide just-in-time access, but they do not have the time-bound, request-based access control that JIT VM access offers.

45
MCQmedium

A security team needs to implement automated remediation for non-compliant resources in a cloud environment. They want to automatically fix public object storage bucket policies. Which combination of services should be used?

A.Audit logging service and serverless compute function
B.Threat detection service and workflow orchestration service
C.Security hub and vulnerability management service
D.Configuration management service and serverless compute function
AnswerD

A configuration management service continuously evaluates resource configuration against policy and detects non-compliant public bucket policies, then invokes a serverless function to remediate them automatically. This pairing satisfies the requirement for automated, event-driven correction without manual intervention.

Why this answer

Automated remediation of non-compliant resources requires a configuration management service to detect and evaluate compliance (e.g., AWS Config rules) and a serverless compute function (e.g., AWS Lambda) to execute the remediation action, such as modifying a public S3 bucket policy. This combination enables event-driven, automatic correction without manual intervention.

Exam trap

The trap here is confusing detection services (GuardDuty, Security Hub) with remediation services; CCSP candidates must recognize that automated remediation requires both a compliance evaluation engine and an execution mechanism, not just monitoring or alerting.

How to eliminate wrong answers

Option A is wrong because audit logging (e.g., CloudTrail) records API activity but does not evaluate resource compliance or trigger remediation logic. Option B is wrong because threat detection (e.g., GuardDuty) identifies malicious activity, not configuration drift, and workflow orchestration alone lacks the compliance evaluation engine. Option C is wrong because a security hub aggregates findings and vulnerability management scans for weaknesses, but neither automatically remediates bucket policies.

46
Multi-Selectmedium

A security team is enhancing logging in AWS to capture detailed data events for S3 buckets. Which TWO of the following should be enabled to achieve comprehensive monitoring of S3 data access? (Choose two.)

Select 2 answers
A.S3 server access logs
B.AWS CloudTrail data events for S3
C.AWS Config
D.VPC Flow Logs
E.Amazon GuardDuty
AnswersA, B

S3 server access logs record every request made to a bucket, including the requester, action, timestamp and response code, giving object-level audit detail. They capture data-plane access that bucket-level logging misses, satisfying the requirement for comprehensive S3 data access monitoring.

Why this answer

S3 server access logs (option A) are correct because they record detailed, bucket-level access requests to S3, including the requester, bucket name, request time, request action, response status, and error code, providing granular visibility into object-level data access. AWS CloudTrail data events for S3 (option B) are also correct because they capture object-level API activity such as GetObject, PutObject, and DeleteObject, which are not recorded by CloudTrail management events, thereby delivering comprehensive monitoring of S3 data access. AWS Config (option C) is not correct because it evaluates and records resource configuration changes and compliance, not individual S3 data access requests.

VPC Flow Logs (option D) is not correct because it captures IP traffic metadata for network interfaces in a VPC, not S3 object-level API operations. Amazon GuardDuty (option E) is not correct because it is a threat detection service that analyzes logs and findings, but it does not itself enable the detailed S3 data event logging required here.

Exam trap

A common pitfall is confusing AWS Config (which monitors configuration changes) with data access logging capabilities. Candidates often incorrectly select AWS Config for monitoring S3 data access because it records resource configurations, but it does not capture individual data access events. The correct choices for comprehensive data access monitoring are S3 server access logs and CloudTrail data events for S3.

47
MCQmedium

A security team is using AWS and wants to monitor for changes to security groups that could expose resources to the internet. They need to receive an alert when a security group rule is modified to allow inbound traffic from 0.0.0.0/0 on port 22. Which AWS service should they use to detect this change?

A.Amazon GuardDuty
B.AWS Trusted Advisor
C.AWS Config
D.AWS CloudTrail
AnswerC

AWS Config records changes to resource configurations, including security groups. You can create a custom rule or use a managed rule to evaluate security group configurations and trigger an alert when a rule allows inbound SSH from 0.0.0.0/0. AWS Config can also send notifications via Amazon SNS, enabling the security team to respond promptly.

Why this answer

AWS Config is designed to monitor resource configurations and evaluate them against desired settings. It can detect when a security group rule is changed to allow inbound SSH from 0.0.0.0/0 and trigger an alert. The other services either log API calls without evaluation, focus on threat detection, or provide periodic checks, making them less suitable for this specific requirement.

Exam trap

The trap here is assuming CloudTrail alone can detect insecure configurations, but it only records API activity without evaluating the resulting state.

48
MCQmedium

A cloud operations team runs a mission-critical application on Amazon EC2 instances behind an Application Load Balancer. The security policy requires that the instances be patched monthly, but the team wants to minimize downtime and avoid manual patching. They decide to use AWS Systems Manager Patch Manager. Which configuration should they implement to meet the patching requirement while maintaining availability?

A.Use AWS Config rules to automatically apply patches when a new CVE is published, and configure an SNS topic to notify the team.
B.Enable automatic OS updates on the EC2 instances by configuring the operating system's update service to run daily.
C.Create a patch baseline, a maintenance window that targets the instances, and a patch group that associates the instances with the baseline.
D.Create an Amazon EventBridge rule that triggers an AWS Lambda function to run yum update on each instance via AWS Systems Manager Run Command on a schedule.
AnswerC

This approach uses Patch Manager's core components: a patch baseline defines approved patches, a patch group links instances to the baseline, and a maintenance window schedules the patching during a defined period. It automates patching, reduces manual effort, and can be configured to patch one instance at a time or in batches, preserving availability.

Why this answer

Patch Manager simplifies patching by using patch baselines, patch groups, and maintenance windows. The baseline defines which patches are approved, the patch group associates instances with the baseline, and the maintenance window schedules the patching. This integrated approach automates patching, provides compliance visibility, and allows controlled rollout to maintain availability.

Exam trap

The trap here is assuming that AWS Config or EventBridge can directly apply patches, when they are monitoring and orchestration services, not patch deployment tools.

49
MCQmedium

A security operations team is using AWS Security Hub to aggregate findings from multiple AWS accounts. They want to automatically create a ticket in their IT service management (ITSM) system for any new critical finding. The ITSM system exposes a REST API. Which AWS service should they use to invoke the ITSM API when a critical finding is generated?

A.AWS CloudTrail
B.Amazon EventBridge
C.AWS Config
D.Amazon Simple Notification Service (SNS)
AnswerB

Security Hub publishes findings to EventBridge as events. You can create an EventBridge rule that matches critical findings and targets an AWS Lambda function or directly an API destination. EventBridge supports API destinations, allowing you to invoke external REST APIs. This enables automatic ticket creation in the ITSM system when a critical finding occurs.

Why this answer

Security Hub integrates with EventBridge by sending findings as events. EventBridge rules can filter for critical findings and route them to targets like Lambda or API destinations. API destinations allow EventBridge to invoke external REST APIs directly, enabling automatic ticket creation in the ITSM system without custom code.

Exam trap

The trap here is assuming that SNS or CloudTrail can directly invoke an external REST API based on Security Hub findings, when EventBridge is the native integration point.

50
MCQhard

A security operations center (SOC) uses AWS GuardDuty and wants to automatically isolate an Amazon EC2 instance that generates a high-severity finding. The isolation must block all network traffic except for forensic analysis traffic from a specific security subnet. Which combination of actions should be taken?

A.Modify the instance's security group to allow only traffic from the forensic subnet and remove all other rules.
B.Detach the instance's Elastic Network Interface (ENI) and attach a new ENI with a restrictive security group.
C.Move the instance to a new subnet with a network ACL that denies all traffic except from the forensic subnet.
D.Apply a new IAM role to the instance that denies all network access.
AnswerA

Modifying the security group to allow only forensic subnet traffic effectively isolates the instance while permitting necessary forensic access. This is a common isolation technique that blocks all other inbound and outbound traffic, aligning with the requirement to block all network traffic except forensic analysis traffic.

Why this answer

The most effective and least disruptive method to isolate an EC2 instance is to modify its security group to allow only traffic from a specific forensic subnet and remove all other rules. This blocks all other network traffic while enabling forensic analysis, and it can be automated via Lambda triggered by GuardDuty findings.

Exam trap

The trap here is confusing IAM roles with network security controls; IAM roles manage API permissions, not network traffic, so they cannot isolate an instance at the network level.

51
MCQmedium

A cloud operations team runs a fleet of Amazon EC2 instances behind an Application Load Balancer. After a recent penetration test, the team must ensure that only HTTP and HTTPS traffic reaches the instances from the load balancer, and that no instance can accept SSH from the internet. The instances currently have a security group named 'web-sg' that allows all inbound traffic from 0.0.0.0/0. Which action should the team take to meet these requirements with the LEAST administrative effort while following AWS best practices?

A.Keep the existing 'web-sg' rules but configure the load balancer to use a target group that only forwards traffic on ports 80 and 443, and enable connection draining.
B.Replace the 'web-sg' security group with a new security group that allows inbound HTTP and HTTPS from 0.0.0.0/0, and add a rule to deny SSH from 0.0.0.0/0.
C.Modify the 'web-sg' security group to allow inbound HTTP and HTTPS from the load balancer's security group, and remove all other inbound rules.
D.Create a new network ACL that allows inbound HTTP and HTTPS from the load balancer subnet and denies all other traffic, then associate it with the instance subnets.
AnswerC

This is correct because referencing the load balancer's security group as the source in the instance security group ensures only traffic from the load balancer is allowed, and removing other rules eliminates internet SSH. It uses security group referencing, which is the AWS-recommended least-privilege approach and requires no changes to the load balancer or instances.

Why this answer

Referencing the load balancer's security group in the instance security group is the most precise and least-effort method to restrict inbound traffic to only the load balancer. It leverages AWS security group referencing, which is stateful and supports least privilege without needing CIDR calculations. Removing all other inbound rules ensures no direct internet SSH access, satisfying both requirements.

Exam trap

The trap here is assuming that security groups can contain explicit deny rules or that network ACLs can reference security groups, when in fact security groups are allow-only and network ACLs are stateless and cannot reference security groups.

52
MCQmedium

A cloud security team wants to automatically remediate misconfigured S3 buckets that are publicly accessible. Which combination of AWS services can be used to detect and automatically fix this issue?

A.AWS GuardDuty and AWS Lambda
B.AWS CloudTrail and AWS Lambda
C.AWS Config and AWS Lambda
D.AWS Security Hub and AWS CloudTrail
AnswerC

AWS Config rules continuously evaluate bucket policies and ACLs, flagging public access as non-compliant. The configuration change then triggers a Lambda function that programmatically removes the public permissions, delivering automated detection and remediation without manual intervention.

Why this answer

AWS Config continuously monitors and records resource configurations, including S3 bucket policies and ACLs, and can evaluate them against desired rules. When a bucket is found to be publicly accessible, AWS Config can trigger an AWS Lambda function to automatically remediate the misconfiguration, such as by applying a restrictive bucket policy or blocking public access. This combination provides detection and automated remediation.

Exam trap

CCSP often tests the difference between threat detection (GuardDuty), auditing (CloudTrail), and configuration compliance (Config), so candidates must match the service to the requirement of detecting and remediating misconfigurations.

How to eliminate wrong answers

Option A is wrong because AWS GuardDuty is a threat detection service that identifies malicious activity and unauthorized behavior, but it does not evaluate resource configuration compliance or trigger remediation for misconfigured S3 buckets. Option B is wrong because AWS CloudTrail records API activity for auditing, but it does not assess resource configuration state or provide compliance evaluation; it cannot detect a publicly accessible bucket by itself. Option D is wrong because AWS Security Hub aggregates findings but does not directly detect misconfigured S3 buckets (it relies on Config or other services) and CloudTrail is for logging, not remediation.

53
MCQmedium

A cloud operations team is deploying a containerized workload on a managed Kubernetes service. They need to ensure that if a container image is discovered to contain a critical vulnerability, the running pods using that image are automatically replaced with a non-vulnerable version. Which mechanism BEST achieves this?

A.Use a network policy that isolates pods running the vulnerable image until the image is patched.
B.Configure a pod disruption budget that prevents pods with vulnerabilities from being evicted during maintenance windows.
C.Configure an admission controller that rejects the vulnerable image tag and use a deployment strategy that replaces pods when the image tag is updated to a patched version.
D.Enable a runtime security agent that detects the vulnerability at runtime and sends an alert to the security team for manual remediation.
AnswerC

Admission controllers can block new pods that reference a denied image, while a rolling update triggered by changing the image tag replaces existing pods with the patched version. This combination prevents vulnerable images from being scheduled and ensures running workloads converge on the safe image without manual pod deletion, directly satisfying the automatic replacement requirement.

Why this answer

Blocking the vulnerable image through an admission controller stops new pods from using it, and updating the deployment to a patched image tag triggers a rolling update that replaces existing pods. Together these enforce image policy and automatically converge the workload on the safe version, meeting the automatic replacement requirement without relying on manual intervention.

Exam trap

The trap here is assuming that runtime detection or network isolation automatically remediates a vulnerable container image, when only an admission control policy combined with a deployment update actually replaces running pods with a patched image.

54
MCQeasy

A security engineer needs to ensure that all API calls made to cloud resources are logged for auditing. Which cloud auditing feature should be enabled to capture management and data events?

A.Cloud monitoring and logging service
B.Configuration management service
C.Threat detection service
D.Cloud audit logging service
AnswerD

A cloud audit logging service records API activity, capturing both management events (control-plane operations) and data events (object-level reads and writes) with caller identity, timestamp and source IP. Enabling it satisfies the requirement to log all API calls for auditing.

Why this answer

Cloud audit logging service (e.g., AWS CloudTrail, Azure Activity Log, GCP Cloud Audit Logs) is the correct feature because it captures API calls made to cloud resources, including management and data events, for auditing purposes. It records who made the call, when, from where, and what was done, providing the necessary audit trail. This is the standard service for logging API activity across cloud providers.

Exam trap

CCSP often tests the confusion between monitoring/logging services (operational) and audit logging services (compliance/auditing), so candidates who pick monitoring or threat detection fall into the trap.

How to eliminate wrong answers

Option A is wrong because cloud monitoring and logging services (e.g., CloudWatch, Azure Monitor) focus on metrics, logs, and alarms for operational monitoring, not specifically on capturing API calls for auditing — though they may integrate with audit logs, they are not the primary audit logging feature. Option B is wrong because configuration management services (e.g., AWS Config, Azure Policy) track resource configurations and compliance, not API call logging. Option C is wrong because threat detection services (e.g., GuardDuty, Security Center) analyze for malicious activity but do not provide the raw audit log of all API calls.

55
MCQmedium

A company uses Azure Defender for Cloud to protect its hybrid environment. Which of the following is a feature of Azure Defender that provides vulnerability assessment for virtual machines?

A.Azure Secure Score
B.Azure Policy
C.Defender for Servers
D.Azure Sentinel
AnswerC

Defender for Servers includes Microsoft Defender for Endpoint integration, delivering agent-based vulnerability assessment for Azure, AWS, GCP and on-premises VMs. This satisfies the stem's hybrid-environment constraint, since the same scanning capability extends beyond Azure to non-Azure machines, unlike agentless scanning limited to Azure and AWS resource types.

Why this answer

Azure Defender includes integrated vulnerability assessment via Qualys or Microsoft built-in scanner, available for Defender for Servers.

56
MCQmedium

An organization is using Azure and wants to centrally collect activity logs from multiple subscriptions into a single Log Analytics workspace for cross-account analysis and retention management. What is the best approach?

A.Use Azure Monitor Agent on all VMs to collect logs.
B.Enable Azure Sentinel on each subscription and aggregate using cross-workspace queries.
C.Use Azure Policy to deploy Diagnostic Settings on each subscription to stream Activity Logs to a central Log Analytics workspace.
D.Use Azure Storage account with event grid to forward logs to a central location.
AnswerC

Azure Policy's deployIfNotExists effect assigns Diagnostic Settings at scale, streaming each subscription's Activity Log to one central Log Analytics workspace. This satisfies the cross-subscription collection and retention requirement without per-subscription manual configuration, since policy remediation enrols new subscriptions automatically.

Why this answer

Azure Policy can enforce the deployment of Diagnostic Settings across all subscriptions, automatically streaming Activity Logs to a central Log Analytics workspace. This ensures centralized collection, cross-account analysis, and retention management without manual configuration per subscription.

Exam trap

A common mistake is confusing Azure Monitor Agent (for VM guest OS logs) with Diagnostic Settings (for Azure platform logs), leading candidates to mistakenly choose agent-based collection for subscription-level Activity Logs.

How to eliminate wrong answers

Option A is wrong because Azure Monitor Agent collects OS-level performance and event logs from VMs, not Azure Activity Logs (which are subscription-level control plane logs). Option B is wrong because Azure Sentinel is a SIEM that can use cross-workspace queries, but it does not natively aggregate Activity Logs from multiple subscriptions into a single workspace; it requires Diagnostic Settings to forward logs first, making it an unnecessary extra layer. Option D is wrong because Azure Storage with Event Grid can forward logs, but it introduces latency, complexity, and lacks the native querying and retention management capabilities of Log Analytics workspaces.

57
MCQmedium

A cloud security architect is evaluating vulnerability management solutions for a hybrid cloud environment. The team needs to scan both on-premises servers and cloud workloads without installing agents on every system. Which approach is most suitable for cloud workloads?

A.Agent-based scanning using a cloud-native service
B.Network vulnerability scanning from a remote scanner
C.Container image scanning only
D.Agentless scanning via cloud APIs (CSPM)
AnswerD

Agentless scanning via cloud APIs queries the provider's control plane, so no software runs on each workload. This satisfies the stem's constraint of scanning cloud workloads without installing agents, unlike host-based tools that require per-system deployment.

Why this answer

Agentless scanning uses cloud APIs to assess vulnerabilities without requiring an agent on each instance. This is ideal for cloud workloads where agents may not be desired.

58
MCQeasy

An organization wants to detect potential crypto mining activity on their AWS EC2 instances. Which AWS service uses machine learning to identify such threats?

A.AWS WAF
B.Amazon GuardDuty
C.Amazon Inspector
D.AWS Shield
AnswerB

Amazon GuardDuty applies machine learning models to analyse VPC Flow Logs, DNS query logs, and CloudTrail management events for behavioural anomalies indicative of crypto mining, such as sustained outbound connections to known mining pools or unusual CPU utilisation patterns. This satisfies the constraint of detecting crypto mining on EC2 instances without requiring agent installation, as it relies on passive network and account-level telemetry.

Why this answer

Amazon GuardDuty is a threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to continuously monitor for malicious activity, including cryptocurrency mining (e.g., connections to known mining pools or unusual compute resource spikes). It analyzes AWS CloudTrail logs, VPC Flow Logs, and DNS logs to identify behavioral patterns indicative of crypto mining, such as sustained outbound traffic to mining pool IPs or unusual EC2 instance launches.

Exam trap

The trap here is that candidates often confuse Amazon Inspector (a vulnerability scanner) with GuardDuty (a threat detection service), mistakenly thinking Inspector's agent-based monitoring can detect runtime threats like crypto mining, when in fact Inspector only assesses configuration and software vulnerabilities.

How to eliminate wrong answers

Option A is wrong because AWS WAF is a web application firewall that protects against common web exploits like SQL injection and cross-site scripting, not a service that uses machine learning to detect crypto mining activity on EC2 instances. Option C is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and unintended network exposure, not a machine learning-based threat detection service for behavioral anomalies like crypto mining. Option D is wrong because AWS Shield is a managed DDoS protection service that safeguards against distributed denial-of-service attacks, not a service that identifies crypto mining threats via machine learning.

59
MCQeasy

A security analyst reviews GCP Security Command Center findings and sees a high-severity alert for Event Threat Detection indicating that a service account key was used from an unexpected location. What is the best immediate action to contain the threat?

A.Disable the service account key
B.Create a new service account
C.Delete the service account
D.Rotate the key and monitor
AnswerA

Disabling the compromised service account key immediately invalidates the credential, halting any further authenticated API calls from the unexpected location. This directly satisfies the containment requirement, since the key itself is the abused authentication artefact and revocation stops the threat without deleting the account's audit history.

Why this answer

The correct immediate action is to disable the compromised service account key because Event Threat Detection has identified that the key is being used from an unexpected location, indicating potential unauthorized access. Disabling the key stops all further usage without deleting the service account or its other keys, preserving legitimate operations. This aligns with the principle of least privilege and incident response containment, as the key can later be rotated or deleted after investigation.

Exam trap

ISC2 CCSP exams often test the distinction between 'disable' and 'rotate' in key compromise scenarios, where candidates mistakenly choose rotation thinking it invalidates the old key, but rotation only creates a new key without disabling the old one unless explicitly done.

How to eliminate wrong answers

Option B is wrong because creating a new service account does not address the compromised key; the old key remains active and can still be used by the attacker. Option C is wrong because deleting the entire service account would disrupt all applications and resources relying on that account, which is an overly destructive action for a single compromised key. Option D is wrong because rotating the key (generating a new key) does not immediately disable the old compromised key; the old key remains valid until it is explicitly disabled or deleted, allowing continued unauthorized access during the rotation process.

60
Multi-Selectmedium

A cloud security team is building an incident response runbook for workloads on AWS. They need to ensure that when a compromised EC2 instance is detected, responders can preserve volatile evidence and prevent further malicious activity without destroying forensic artifacts. (Choose two.)

Select 2 answers
A.Reboot the instance to clear any malicious processes from memory.
B.Capture an EBS snapshot of the instance's volumes before making changes.
C.Isolate the instance using a security group that allows no inbound or outbound traffic.
D.Terminate the instance immediately to stop the attacker.
E.Detach the root volume and attach it to an analysis instance without snapshotting first.
AnswersB, C

An EBS snapshot captures the block-level state of the attached volumes, preserving disk-based artifacts such as logs, binaries, and configuration. Taking it before remediation ensures the evidence remains intact even if the instance is later terminated or modified, which is essential for forensic analysis and legal defensibility.

Why this answer

Effective cloud incident response follows the order of containment and preservation before remediation. Isolating the instance with a restrictive security group stops command-and-control and lateral movement while keeping the system alive, and capturing EBS snapshots first preserves disk artifacts. Together these steps contain the threat without destroying the evidence responders need.

Exam trap

The trap here is prioritizing immediate eradication, terminating or rebooting the instance, over containment and evidence preservation, which destroys volatile artifacts.

61
MCQeasy

A company uses Azure Sentinel as its SIEM. To ingest Azure Activity Logs and correlate with other data sources, which connector should be configured?

A.Office 365 connector
B.Azure Defender connector
C.Azure Activity connector
D.Windows Security Events connector
AnswerC

The Azure Activity connector streams subscription-level control-plane events, such as resource creation and role assignments, into the Microsoft Sentinel workspace. It satisfies the stem's requirement to ingest Azure Activity Logs and correlate them with other sources through analytics rules and workbooks.

Why this answer

The Azure Activity connector is specifically designed to ingest Azure Activity Logs, which contain subscription-level events such as resource creation, modification, and deletion. This connector enables Sentinel to correlate these operational logs with other data sources for comprehensive threat detection and incident response.

Exam trap

The trap is that candidates may confuse Azure Activity Logs (subscription-level operations) with Azure Defender alerts (security findings) or Office 365 logs (SaaS application logs). However, only the Azure Activity connector ingests subscription-level events needed for correlation with other data sources in Sentinel.

How to eliminate wrong answers

Option A is wrong because the Office 365 connector ingests logs from Microsoft 365 services (e.g., Exchange, SharePoint, Teams), not Azure subscription-level activity logs. Option B is wrong because the Azure Defender connector ingests security alerts from Azure Defender (formerly Azure Security Center), not raw Azure Activity Logs. Option D is wrong because the Windows Security Events connector ingests security event logs from Windows machines (e.g., Event ID 4625 for failed logons), not Azure platform logs.

62
MCQhard

A security analyst is investigating a potential security incident in a Microsoft Azure environment. The analyst needs to review the history of role assignments and changes to Azure resources over the past 90 days. Which Azure service should the analyst use?

A.Azure Monitor Logs
B.Azure Security Center
C.Azure Activity Log
D.Azure AD Audit Logs
AnswerC

The Azure Activity Log provides a history of subscription-level events, including role assignments and resource changes. It retains data for 90 days by default, which aligns with the analyst's requirement. By reviewing the Activity Log, the analyst can see who made changes, what resources were affected, and when the changes occurred, which is essential for incident investigation.

Why this answer

The Azure Activity Log is the correct service because it records subscription-level events, including role assignments and resource modifications, and retains them for 90 days. This directly matches the analyst's need to review the history of changes over that period. Other services either focus on different scopes (like Azure AD) or require additional configuration for log retention.

Exam trap

The trap here is confusing Azure AD Audit Logs with Azure Activity Log, as both are audit logs but cover different scopes.

63
MCQmedium

An organization uses GCP and wants to monitor for threats in real-time, including detecting malicious activity from compromised service accounts. Which GCP service should be used?

A.Cloud Audit Logs
B.Cloud Security Scanner
C.Container Threat Detection
D.Event Threat Detection
AnswerD

Event Threat Detection continuously analyses Cloud Audit Logs and VPC flow logs using threat intelligence to surface compromised service accounts, cryptomining and data exfiltration in near real-time. Security Command Center Premium surfaces these findings, satisfying the real-time monitoring requirement that Cloud Logging alone cannot provide.

Why this answer

Event Threat Detection is part of GCP Security Command Center and provides real-time threat detection for IAM anomalies, including compromised service accounts.

64
MCQmedium

An organization is using GCP Security Command Center with Event Threat Detection. Which type of event is most likely to generate a finding for 'exfiltration'?

A.A service account creating a new VM
B.A user logging in from a new IP address
C.A firewall rule change allowing all inbound traffic
D.A large number of objects being downloaded from a Cloud Storage bucket
AnswerD

Event Threat Detection flags exfiltration when an unusually large volume of objects is downloaded from a Cloud Storage bucket, indicating bulk data theft. This behaviour matches the exfiltration detector's data-egress heuristics rather than IAM or network findings.

Why this answer

Event Threat Detection (ETD) in GCP Security Command Center monitors Cloud Storage access logs for anomalous data access patterns. A large number of object downloads from a single bucket within a short time window is a strong indicator of data exfiltration, as it matches the behavioral signature of bulk data extraction. ETD uses machine learning models trained on normal access baselines to flag such volume-based anomalies as 'exfiltration' findings.

Exam trap

A common trap in the ISC2 CCSP exam is confusing an anomalous sign-in event (Option B) with data exfiltration. Exfiltration requires a data transfer action, such as downloading many objects from a storage bucket, not just authentication from a new location.

How to eliminate wrong answers

Option A is wrong because creating a new VM is an infrastructure provisioning action, not a data movement event; ETD focuses on data access and network anomalies, not resource creation. Option B is wrong because a login from a new IP address typically triggers an 'anomalous login' or 'brute force' finding, not an exfiltration event; exfiltration requires data leaving the environment. Option C is wrong because a firewall rule change allowing all inbound traffic is a misconfiguration finding related to network security, not data exfiltration; ETD would flag this under 'open firewall' or 'ingress' rules, not data theft.

65
MCQmedium

A SOC analyst notices an alert for 'impossible travel' where a user logged in from New York and then from London within 15 minutes. The SIEM correlation rule likely compares which log fields?

A.User agent and browser type
B.Source IP address and timestamp
C.Destination IP and port
D.Volume of data transferred and timestamp
AnswerB

Impossible travel detection calculates the geographic distance between successive authentications and divides it by elapsed time. The SIEM rule therefore correlates source IP address, which resolves to location, against the timestamp of each login event to derive an impossible velocity.

Why this answer

Impossible travel detection correlates the geographic location derived from the source IP address with the login timestamp to compute whether the physical distance between two logins could be traveled in the elapsed time. If the implied speed exceeds a threshold (e.g., faster than commercial air travel), the SIEM flags the event as impossible travel.

Exam trap

CCSP often tests whether candidates understand that impossible travel is fundamentally a geolocation-plus-time correlation — distractors mention client attributes (user agent) or destination attributes (port) that don't establish physical location.

How to eliminate wrong answers

Option A is wrong because user agent and browser type describe the client software, not the user's physical location, so they cannot establish geographic impossibility. Option C is wrong because destination IP and port describe the target server being accessed, not the origin of the user's connection, so they don't reveal travel. Option D is wrong because data volume and timestamp measure exfiltration or usage patterns, not the geographic origin of logins, so they cannot detect impossible travel.

66
MCQeasy

Which of the following is a benefit of enabling log file validation for cloud audit logs?

A.It ensures the integrity of log files by allowing you to confirm that they have not been modified.
B.It automatically deletes old log files based on a retention policy.
C.It encrypts log files at rest.
D.It compresses log files to save storage space.
AnswerA

Log file validation uses cryptographic hashing to produce a digest for each audit log file, letting you verify that entries have not been altered or deleted after capture. This directly satisfies the stem's integrity requirement, supporting tamper-evident audit trails for compliance and forensic investigations.

Why this answer

Log file validation uses a hash-based digital signature (such as SHA-256) to create a digest file for each log file. This allows you to verify that the log files have not been tampered with, deleted, or modified after they were delivered, ensuring their integrity for forensic analysis and compliance.

Exam trap

The CCSP exam often tests the distinction between integrity (log file validation) and other security controls like encryption, compression, or lifecycle management, leading candidates to confuse validation with unrelated features.

How to eliminate wrong answers

Option B is wrong because CloudTrail log file validation does not manage retention or deletion; lifecycle policies are configured separately via S3 lifecycle rules or CloudTrail console settings. Option C is wrong because encryption at rest is provided by S3 server-side encryption (SSE-S3, SSE-KMS, or SSE-C), not by log file validation. Option D is wrong because compression is not a feature of log file validation; CloudTrail logs can be delivered in gzip format if configured, but validation does not compress them.

67
MCQmedium

A company is implementing a SIEM solution and needs to ingest security logs from multiple AWS accounts into a centralized security account. Which AWS service can best aggregate findings from all accounts?

A.Amazon GuardDuty
B.Amazon CloudWatch Logs
C.AWS Security Hub
D.AWS Config
AnswerC

AWS Security Hub aggregates findings across accounts through its multi-account administration, letting a delegated security account receive and consolidate findings from every member account. This directly satisfies the requirement to centralise findings from multiple AWS accounts into one security account, unlike services scoped to a single account.

Why this answer

AWS Security Hub is purpose-built to aggregate and normalize findings from multiple AWS accounts and services (GuardDuty, Inspector, Macie, Config, Firewall Manager, and third-party tools) into a single pane of glass. Using AWS Organizations integration, a delegated administrator account can centrally view and manage findings across all member accounts, which is exactly the SIEM-ingestion pattern described.

Exam trap

CCSP often tests the confusion between detection services (GuardDuty) and aggregation services (Security Hub) — candidates pick GuardDuty because it 'finds threats' but miss that the question asks about aggregating findings from many accounts.

How to eliminate wrong answers

Option A is wrong because GuardDuty is a threat-detection service that generates its own findings — it does not aggregate findings from other accounts or services into a central view. Option B is wrong because CloudWatch Logs stores and queries log data but does not normalize or aggregate security findings across accounts; it is a logging substrate, not a findings aggregator. Option D is wrong because AWS Config tracks resource configuration changes and compliance, producing configuration items and conformance packs, not a unified cross-account security findings dashboard.

68
Multi-Selecthard

A cloud security team is designing a detective control strategy for a multi-account AWS organization. The team wants to continuously evaluate resource configurations against CIS AWS Foundations Benchmark controls across all accounts and receive alerts when a resource drifts from the desired state. The team also wants to automatically remediate noncompliant resources where possible. Which TWO AWS services should be combined to meet these requirements? (Choose two.)

Select 2 answers
A.AWS Trusted Advisor
B.AWS Config with conformance packs
C.AWS Systems Manager Automation runbooks
D.AWS Security Hub with CIS AWS Foundations Benchmark standard
E.Amazon GuardDuty
AnswersB, C

AWS Config continuously records resource configurations and evaluates them against rules. Conformance packs bundle AWS Config rules mapped to standards such as the CIS AWS Foundations Benchmark and can be deployed across an organization using a delegated administrator account. This provides the continuous compliance evaluation and drift detection the team requires across all accounts.

Why this answer

Continuous configuration evaluation against CIS controls across an organization is delivered by AWS Config conformance packs, which package standards-mapped rules and support multi-account deployment through a delegated administrator. Automatic remediation of noncompliant resources is delivered by AWS Config remediation actions that invoke AWS Systems Manager Automation runbooks. Security Hub and Trusted Advisor provide visibility or advice but do not perform the configuration recording and automated remediation this design requires.

Exam trap

The trap here is assuming AWS Security Hub alone enforces CIS compliance and remediates drift, when it aggregates findings and depends on AWS Config for evaluation and on Systems Manager Automation for remediation.

69
MCQeasy

A cloud security engineer is tasked with ensuring that all API calls made to AWS resources are logged for audit purposes. Which AWS service should be enabled to capture management events such as creating or deleting EC2 instances?

A.AWS Config
B.AWS CloudTrail
C.Amazon GuardDuty
D.AWS Security Hub
AnswerB

CloudTrail records API activity across AWS services, capturing management events such as RunInstances or TerminateInstances with caller identity, source IP and timestamp. Enabling it in each region and account provides the audit trail the stem requires, which service-level logs alone cannot deliver.

Why this answer

AWS CloudTrail is the correct service because it is specifically designed to record API activity in an AWS account, including management events such as creating or deleting EC2 instances. It captures the who, what, when, and source IP for every API call, which is essential for audit logging and compliance. AWS Config, by contrast, records resource configuration changes and compliance history, not API call logs.

Exam trap

The trap here is that candidates confuse AWS Config (which tracks configuration history) with CloudTrail (which tracks API calls), leading them to select AWS Config for audit logging of management events.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration changes and evaluates compliance rules, but it does not capture API call logs or management events like creating or deleting EC2 instances. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, but it does not itself generate or store API audit logs. Option D is wrong because AWS Security Hub aggregates security findings from multiple services (including CloudTrail) and provides a compliance dashboard, but it is not a logging service and does not capture raw API events.

70
MCQmedium

A security analyst notices that an IAM user from a cloud account has logged in from two different countries within a span of 10 minutes. Which type of detection mechanism is most likely to flag this activity as suspicious?

A.A cloud configuration management database (CMDB)
B.A vulnerability scanner
C.An agent-based intrusion detection system (IDS)
D.A correlation rule in a SIEM
AnswerD

A SIEM correlation rule joins disparate events across a time window, so it can compare two authentication logs from different countries ten minutes apart and raise an alert. Single-event detections, such as signature or anomaly checks, evaluate each login in isolation and miss the geographic impossibility.

Why this answer

A correlation rule in a SIEM is designed to aggregate and analyze log data from multiple sources, such as cloud IAM logs, to detect anomalous patterns. The specific scenario of a user logging in from two geographically distant countries within 10 minutes is a classic example of an impossible travel time anomaly, which SIEM correlation rules are built to flag by comparing login timestamps and IP geolocation data.

Exam trap

The CCSP exam often tests the distinction between detection mechanisms that analyze static configurations (CMDB, vulnerability scanners) versus those that analyze dynamic behavioral patterns (SIEM correlation rules), leading candidates to confuse a CMDB's asset inventory function with real-time anomaly detection.

How to eliminate wrong answers

Option A is wrong because a cloud configuration management database (CMDB) is a repository for storing metadata about IT assets and their relationships, not a real-time detection mechanism for user login anomalies. Option B is wrong because a vulnerability scanner is designed to identify security weaknesses in systems (e.g., missing patches, misconfigurations), not to analyze user behavior or login patterns. Option C is wrong because an agent-based intrusion detection system (IDS) monitors network traffic or host-level events for known attack signatures, but it does not typically correlate geolocation data from cloud IAM logs to detect impossible travel scenarios.

71
MCQhard

A financial services company stores regulated data in Amazon S3 and must prove to auditors that objects cannot be deleted or overwritten for seven years, even by a compromised root account. The security team needs the strongest native control that preserves the data for the retention period. Which S3 feature should they enable?

A.S3 Cross-Region Replication to a second bucket
B.S3 Object Lock in compliance mode
C.Bucket policies that deny s3:DeleteObject to all principals
D.S3 Versioning with a lifecycle rule to transition objects to S3 Glacier Deep Archive
AnswerB

S3 Object Lock in compliance mode prevents any user, including the root account, from overwriting or deleting a protected object version until the retention date passes. This is the strongest native immutability control in S3 and directly satisfies the seven-year retention requirement for regulated data.

Why this answer

S3 Object Lock in compliance mode enforces a write-once-read-many retention that no principal, including the account root, can shorten or remove before the retention date. Versioning and replication improve durability and recoverability but remain mutable by privileged users, so only compliance-mode Object Lock satisfies the immutability proof the auditors demand.

Exam trap

The trap here is treating replication or versioning as equivalent to immutability, when only Object Lock in compliance mode resists even root-level deletion.

72
Multi-Selectmedium

A security architect is designing a logging strategy for a multi-cloud environment using AWS and Azure. Which TWO practices should be implemented to ensure log integrity and prevent tampering? (Choose two.)

Select 2 answers
A.Store logs in a publicly readable S3 bucket for transparency
B.Encrypt logs using server-side encryption with AWS KMS
C.Enable CloudTrail log file validation
D.Use S3 Object Lock or Azure Immutable Blob Storage
E.Enable cross-region replication for logs
AnswersC, D

CloudTrail log file validation generates digest files containing hashes of each delivered log, enabling detection of any post-delivery alteration or deletion. This satisfies the log-integrity requirement by cryptographically proving AWS API activity records were not tampered with before forensic review.

Why this answer

Option C is correct because CloudTrail log file validation generates a digitally signed digest file for each log file, allowing you to verify that logs have not been altered or deleted after delivery. Option D is correct because S3 Object Lock (in compliance or governance mode) and Azure Immutable Blob Storage enforce WORM (write once, read many) policies, preventing logs from being modified or deleted during a retention period. Option A is wrong because a publicly readable S3 bucket exposes logs to unauthorized access and tampering, undermining integrity.

Option B is wrong because KMS server-side encryption protects confidentiality at rest but does not prevent an authorized user or attacker with write permissions from altering or deleting log objects. Option E is wrong because cross-region replication improves durability and availability but does not prevent tampering with the source or replicated logs.

Exam trap

The trap is confusing encryption or replication with integrity — candidates must recognize that only cryptographic validation (detection) plus immutability (prevention) actually stop tampering.

73
MCQhard

After a security incident involving a compromised access key, a security engineer needs to collect forensic evidence from the cloud environment. Which of the following actions would be most useful for determining the timeline of the compromise?

A.Taking a memory dump of the compute instance
B.Reviewing cloud audit logs for the compromised key
C.Analyzing network flow logs for data exfiltration
D.Checking configuration management logs for resource changes
AnswerB

Cloud audit logs record every API call made with the compromised access key, including timestamps, source IPs and requested actions. This chronological record directly establishes when the key was first misused and the sequence of attacker activity, satisfying the need to determine the compromise timeline.

Why this answer

Cloud audit logs contain detailed records of all API calls, including the identity, timestamp, and source IP. Analyzing these logs helps establish the timeline of when the key was used.

74
MCQmedium

A cloud security team needs to ensure that all AWS API activity across a multi-account organization is captured in a tamper-evident, immutable log that can be queried later for forensic analysis. The organization uses AWS Organizations with a dedicated security account. Which approach BEST meets these requirements?

A.Configure each member account to send AWS CloudTrail events to a local CloudWatch Logs group and rely on the default 90-day retention.
B.Use AWS Config to record configuration changes across accounts and store the configuration history in the security account for later retrieval.
C.Enable AWS CloudTrail as an organization trail that delivers logs to a centralized S3 bucket with S3 Object Lock in compliance mode and validate log file integrity.
D.Enable Amazon GuardDuty in the security account and export its findings to an S3 bucket with versioning enabled for long-term storage.
AnswerC

An organization trail automatically applies to all accounts in AWS Organizations, delivering a single consolidated record of API activity. Delivering to a centralized S3 bucket protected by S3 Object Lock in compliance mode prevents deletion or alteration, and CloudTrail log file integrity validation provides cryptographic proof that logs were not tampered with, satisfying forensic-grade requirements.

Why this answer

Centralized, tamper-evident API logging in AWS Organizations is achieved with an organization trail that aggregates events into a single S3 bucket. S3 Object Lock in compliance mode prevents anyone, including the root user, from deleting or overwriting objects for the retention period, while CloudTrail log file integrity validation uses digest files to prove logs were not altered, which is essential for forensic admissibility.

Exam trap

The trap here is assuming that enabling CloudTrail in each account or exporting GuardDuty findings provides a centralized, immutable audit trail, when only an organization trail with S3 Object Lock and integrity validation meets tamper-evident, organization-wide forensic requirements.

75
MCQeasy

A security engineer needs to ensure that all API calls made to AWS resources are logged for auditing purposes. Which AWS service should be enabled to capture management events, data events, and provide log file validation?

A.Amazon CloudWatch Logs
B.AWS CloudTrail
C.AWS Config
D.AWS GuardDuty
AnswerB

AWS CloudTrail captures API activity across AWS resources, covering both management events and, when configured, data events such as S3 object operations. Its log file validation feature produces digest files proving logs were not altered after delivery, satisfying the auditing and tamper-evidence requirements stated in the stem.

Why this answer

AWS CloudTrail is the correct service because it is specifically designed to log API calls and actions taken within an AWS account, capturing management events (e.g., creating or deleting resources) and data events (e.g., S3 object-level operations). It also provides log file validation through digital signatures using SHA-256 hashing and RSA, ensuring the integrity and authenticity of the log files after they have been delivered.

Exam trap

A common mistake is to confuse the service that generates logs (CloudTrail) with services that store or analyze logs (CloudWatch Logs, GuardDuty), leading candidates to select CloudWatch Logs as the primary logging service for API calls.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs is a service for monitoring, storing, and accessing log files from various AWS resources (e.g., EC2, Lambda), but it does not natively capture AWS API calls or provide log file validation; it can only ingest CloudTrail logs if configured as a destination. Option C is wrong because AWS Config is a service for evaluating resource configurations against desired policies and tracking configuration changes, not for logging API calls or providing log file validation. Option D is wrong because AWS GuardDuty is a threat detection service that analyzes CloudTrail logs, VPC Flow Logs, and DNS logs for malicious activity, but it does not itself capture or log API calls nor provide log file validation.

Page 1 of 2 · 77 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Ccsp Security Ops questions.