ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your security team feeds a cloud-hosted SIEM with machine-learning analytics using three sources today: cloud provider API audit logs, operating-system event logs from all virtual machines, and alerts from the web application firewall placed at the Internet edge. Despite this, recent red-team testing showed that malware running in a compromised container was able to communicate with a second subnet and establish command-and-control (C2) traffic without triggering any alert. To close this visibility gap while re-using the SIEM's analytics, which additional data source should you integrate first?
East-west flow logs from the cloud virtual network (such as VPC Flow Logs or VNet Flow Logs) that record traffic between internal subnets.
Access logs from the object storage service that record read and write operations.
Weekly status exports from the enterprise patch-management platform.
Invocation metrics from all serverless functions handling background jobs.
The SIEM already ingests control-plane activity (API audit logs) and host-level events, and it monitors north-south traffic through the web application firewall. What is missing is visibility into east-west network activity inside the virtual network, where lateral movement and C2 were observed. Enabling and forwarding virtual network (e.g., VPC or VNet) flow logs that capture traffic between elastic network interfaces allows the SIEM's machine-learning models to analyze connection metadata, build baselines, and flag anomalous internal communications. Patch management reports, object-storage access logs, and serverless invocation metrics add operational insight but do not contain the network-level information required to identify intra-subnet C2 channels, so they would not directly remediate the demonstrated blind spot.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are VPC Flow Logs and VNet Flow Logs?
Open an interactive chat with Bash
What is east-west traffic in cloud networks?
Open an interactive chat with Bash
How does machine learning in a SIEM analyze flow logs?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .