ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A SaaS provider centralizes its IaaS flow logs and host telemetry in a cloud-native SIEM that offers machine-learning-driven user and entity behavior analytics (UEBA). Late one night, the SOC receives an alert that a development virtual machine, normally inactive after business hours, has begun sending large amounts of data to an unknown external IP range at 03:00. Which specific monitoring capability within the SIEM most likely triggered this alert?
Role-based access control policy evaluation on the management plane
Scheduled log rotation and archival policy enforcement
Signature matching against a list of known command-and-control domains
Behavior-based anomaly detection that builds baselines for normal host activity
UEBA components in modern SIEM or XDR platforms apply machine-learning algorithms to establish normal behavioral baselines for each user, host, and application. When future activity significantly deviates from these learned patterns-such as a normally idle development VM suddenly launching large outbound transfers in the middle of the night-the anomaly-based engine flags the event for investigation. Signature matching relies on known indicators and would only trigger if the destination matched an existing rule. Log rotation or RBAC evaluation do not assess traffic patterns or behavioral context, so they would not identify this type of unusual but previously unseen activity. Therefore, behavior-based anomaly detection (baseline deviation) is the function that generated the alert.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is UEBA in a SIEM and how does it work?
Open an interactive chat with Bash
How does anomaly detection differ from signature-based threat detection?
Open an interactive chat with Bash
Why wouldn't traditional log rotation or RBAC evaluations detect this incident?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .