ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During a post-incident review, a cloud SOC discovers that attackers moved between Linux virtual machines weeks before detection. Analysts receive only syslog from each instance, so early network-level indicators were missing. To close the gap, the security engineer plans to collect a provider-native log that records accepted and rejected traffic for every virtual NIC in each subnet and forward it to the SIEM. Which log source fulfills this requirement?
Hypervisor management console logs from the host servers
Virtual network flow logs generated by the cloud provider
Control-plane API audit trail (e.g., cloud activity logs)
Object storage access logs for buckets or containers
Provider flow-log services (such as AWS VPC Flow Logs or Azure Network Watcher flow logs) capture metadata about every network connection to and from a virtual network interface, including whether traffic was accepted or rejected. Streaming these records to a SIEM lets analysts correlate east-west movement that guest OS syslog alone cannot reveal. Control-plane audit trails record management API calls, not packet flows. Object-storage access logs show only bucket or blob operations and give no insight into instance-to-instance traffic. Hypervisor console logs capture management events on the host but likewise omit detailed network session information.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are virtual network flow logs and how do they work?
Open an interactive chat with Bash
Why are control-plane API audit trails insufficient for detecting network-level indicators?
Open an interactive chat with Bash
How can SIEM integration enhance the value of network flow logs?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .