easyMultiple SelectObjective-mapped
CCSP Practice Question: Which TWO cloud monitoring tools are used…
Which TWO cloud monitoring tools are used primarily for detecting anomalous behavior that may indicate a security incident? (Choose two.)
⚠ Common exam trap
ISC2 often tests the distinction between monitoring for performance (infrastructure/APM tools) versus monitoring for security (IDS/SIEM), and candidates mistakenly choose infrastructure monitoring or APM because they think 'monitoring' broadly covers security, but these tools lack the specific anomaly detection and correlation capabilities required for incident detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Intrusion detection system (IDS).
An Intrusion Detection System (IDS) is specifically designed to monitor network traffic and system activities for signs of malicious activity or policy violations, making it a primary tool for detecting anomalous behavior indicative of a security incident. A Security Information and Event Management (SIEM) system aggregates and correlates logs from multiple sources, using rules and analytics to identify patterns of suspicious activity that may signal a security breach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Infrastructure monitoring tool.
Why it's wrong here
Infrastructure monitoring focuses on resource health, not security.
- ✓
Intrusion detection system (IDS).
Why this is correct
IDS monitors network traffic for malicious activity.
- ✗
Cloud cost management tool.
Why it's wrong here
Cost management tools do not detect security incidents.
- ✗
Application performance monitoring (APM).
Why it's wrong here
APM monitors performance, not security.
- ✓
Security information and event management (SIEM) system.
Why this is correct
SIEM aggregates logs and correlates events to detect anomalies.
Go deeper
Related to this question
About these practice questions
One of 964 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.