ISC2 Certified Cloud Security Professional (CCSP) Practice Question
You are the cloud security architect for a multinational enterprise that runs its workloads in several regions of the same public IaaS provider. Compliance mandates state that all audit logs (management API calls, hypervisor events, and guest-OS logs) must be retained for seven years, protected against alteration or deletion, and remain accessible even if an entire region suffers an outage. Which design choice best satisfies all of these requirements?
Store logs locally on each tenant virtual machine and encrypt them with application-managed keys.
Forward all logs to a centralized logging service in each region and replicate them later using periodic block-storage snapshots.
Enable the provider's flow-log feature and rely on its default log retention settings.
Stream all logs in near real-time to a dedicated security account in a different region, store them in object storage with WORM retention locks, and restrict access through role-based policies.
Streaming every category of audit data to a dedicated security account in a different region and writing it to object storage configured for write-once-read-many (WORM) retention provides three critical safeguards: centralization in an independent account limits the blast radius of a compromise, cross-region storage ensures availability during a regional failure, and WORM enforcement makes the logs tamper-evident for the full seven-year period. Merely keeping logs in regional services or on the originating virtual machines does not guarantee immutability or cross-region durability, and relying on default retention periods rarely meets stringent regulatory timelines.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is WORM retention and why is it important for log storage?
Open an interactive chat with Bash
What is a dedicated security account in the context of cloud environments?
Open an interactive chat with Bash
How does cross-region storage ensure availability during outages?
Open an interactive chat with Bash
What is WORM (Write-Once-Read-Many) storage?
Open an interactive chat with Bash
Why is cross-region storage important for audit logs?
Open an interactive chat with Bash
What is the role of a dedicated security account in this design?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .