ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your organization runs its production microservices on a managed Kubernetes cluster in a public cloud. The SOC's SIEM triggers an alert showing hundreds of failed SSH attempts in the last five minutes against the bastion host that administrators use to reach worker nodes. According to standard incident-response workflow, which immediate action best represents the containment phase while still preserving evidence for possible forensics?

  • Create a temporary deny rule for the offending IP address in the bastion host's cloud network security group and begin a forensic disk and memory snapshot of the host.

  • Immediately file a breach notification with the relevant data-protection regulator and await further instructions.

  • Shut down and delete the entire virtual network that contains the Kubernetes cluster to guarantee the attacker is removed.

  • Increase SIEM log retention from 30 to 90 days to gather more historical context before acting.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot