ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A payment-processing workload is being migrated to AWS. PCI DSS requires the organization to be able to reconstruct full network sessions and to retain all related audit evidence for at least 12 months in a tamper-evident repository. The security team also wants to avoid introducing additional CPU or disk overhead on production EC2 instances. Which design change best satisfies these requirements?

  • Forward all syslog messages to a bastion host and store them on a local file system with permissions set to read-only for administrators.

  • Mirror all VPC traffic to a dedicated capture appliance in a separate security VPC and store the resulting pcap files in an Amazon S3 bucket with Object Lock enabled.

  • Install tcpdump agents on every EC2 instance and schedule uploads of rotated capture files to an S3 bucket that has versioning disabled.

  • Enable CloudTrail data events for VPC and export the logs to CloudWatch Logs, then archive them in an encrypted DynamoDB table.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot