ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A SaaS provider centralizes its IaaS flow logs and host telemetry in a cloud-native SIEM that offers machine-learning-driven user and entity behavior analytics (UEBA). Late one night, the SOC receives an alert that a development virtual machine, normally inactive after business hours, has begun sending large amounts of data to an unknown external IP range at 03:00. Which specific monitoring capability within the SIEM most likely triggered this alert?

  • Role-based access control policy evaluation on the management plane

  • Scheduled log rotation and archival policy enforcement

  • Signature matching against a list of known command-and-control domains

  • Behavior-based anomaly detection that builds baselines for normal host activity

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot