ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A Tier-1 analyst in your organization's cloud-focused security operations center (SOC) is monitoring the SIEM dashboard. Within five minutes the analyst observes a steady stream of outbound connections from a normally dormant Platform-as-a-Service (PaaS) workload to an unfamiliar external IP address. Initial triage confirms that the traffic is unauthorized and may indicate data exfiltration. According to standard SOC role segregation and escalation procedures, which action should the Tier-1 analyst take next?

  • Create an incident ticket and escalate the event to the Tier-2 response team for deeper investigation and containment.

  • Immediately shut down the affected PaaS instance to stop the traffic.

  • Notify law enforcement to initiate legal proceedings against the suspected attacker.

  • Close the alert as a false positive because the traffic did not trigger a critical alarm.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot