easyMultiple Select
CCSP Practice Question: Which TWO cloud monitoring tools are used…
Which TWO cloud monitoring tools are used primarily for detecting anomalous behavior that may indicate a security incident? (Choose two.)
⚠ Common exam trap
ISC2 often tests the distinction between monitoring for performance (infrastructure/APM tools) versus monitoring for security (IDS/SIEM), and candidates mistakenly choose infrastructure monitoring or APM because they think 'monitoring' broadly covers security, but these tools lack the specific anomaly detection and correlation capabilities required for incident detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Intrusion detection system (IDS).
An Intrusion Detection System (IDS) is specifically designed to monitor network traffic and system activities for signs of malicious activity or policy violations, making it a primary tool for detecting anomalous behavior indicative of a security incident. A Security Information and Event Management (SIEM) system aggregates and correlates logs from multiple sources, using rules and analytics to identify patterns of suspicious activity that may signal a security breach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Infrastructure monitoring tool.
Why it's wrong here
Infrastructure monitoring tracks CPU, memory and disk metrics to report availability and capacity, not behavioural anomalies. It is tempting because it does surface threshold breaches, but it lacks the baselining and correlation of user, network and data activity that UEBA or SIEM tooling performs to flag incidents.
- ✓
Intrusion detection system (IDS).
Why this is correct
An IDS monitors network or host traffic against signatures and behavioural baselines, generating alerts when activity deviates from normal patterns. That anomaly detection directly supports identifying potential security incidents, which is the monitoring purpose the question specifies.
- ✗
Cloud cost management tool.
Why it's wrong here
Cost management tools track spend against budgets and forecasts, offering no telemetry on user, network or workload behaviour. It tempts because cloud monitoring is a broad category, but anomaly detection requires behavioural baselines from SIEM or user entity behaviour analytics platforms instead.
- ✗
Application performance monitoring (APM).
Why it's wrong here
APM measures latency, throughput and error rates to diagnose application health, not adversarial activity. It tempts because APM dashboards surface sudden performance deviations that can accompany attacks, yet distinguishing malicious behaviour requires correlation in a SIEM or UEBA tool.
- ✓
Security information and event management (SIEM) system.
Why this is correct
A SIEM aggregates and correlates logs from many sources, applying analytics and rules to surface anomalous behaviour across the estate. This satisfies the stem's requirement for detecting potential security incidents, complementing traffic-level inspection with centralised, cross-source event correlation and alerting.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.