Cloud Security Operations Flashcards
6 cards from real CCSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Cloud Security Operations flashcards as text
What is the primary goal of a Security Information and Event Management (SIEM) system in cloud operations?
Answer: To aggregate, correlate, and analyze security events from multiple sources for threat detection and incident response
A SIEM centralizes log collection and applies correlation rules to detect suspicious patterns across an organization's entire cloud and on-premises environment.
In cloud incident response, what does the containment phase primarily involve?
Answer: Limiting the spread and impact of the incident to prevent further damage
Containment stops the attack from spreading by isolating affected systems, revoking compromised credentials, and blocking malicious traffic.
What does cloud log management best practice require regarding log integrity?
Answer: Logs should be written to a separate, immutable, write-once storage location to prevent tampering
Logs must be stored in a separate, write-once (immutable) location outside the monitored environment to prevent attackers from covering their tracks by modifying or deleting logs.
What is the purpose of a runbook in cloud security operations?
Answer: A documented, step-by-step procedure for responding to specific security incidents or operational tasks
Runbooks provide standardized, repeatable procedures that operations teams follow during incidents, reducing response time and human error.
Which metric measures the average time from when an attack occurs to when it is detected?
Answer: Mean Time to Detect (MTTD)
Mean Time to Detect (MTTD) measures the average elapsed time between the start of an attack and its detection by the security team.
What is the key difference between vulnerability scanning and penetration testing?
Answer: Vulnerability scanning identifies potential weaknesses automatically; penetration testing actively exploits vulnerabilities to determine real impact
Vulnerability scanners produce lists of potential issues without confirming exploitability, while penetration testers actively attempt to exploit vulnerabilities to assess real-world risk.