ISC2 Certified Cloud Security Professional (CCSP) Practice Question

During a post-incident review, a security operations team found that VPC Flow Logs from AWS, Azure Activity Logs, and on-premises firewall events were difficult to correlate in their new cloud-hosted SIEM because the recorded times did not line up. To improve the accuracy of future investigations across all environments, which action should be taken first?

  • Increase the SIEM's log retention period from 30 to 90 days to keep a longer history for correlation.

  • Enable log compression and convert all records to the RFC 5424 syslog format before forwarding to the SIEM.

  • Deploy agent-based collectors in each environment to minimize log transport latency to the SIEM.

  • Configure every cloud service, host, and the SIEM to synchronize with the same authoritative NTP or PTP time source.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot