Cloud Security Operations Flashcards
6 cards from real CCSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Cloud Security Operations flashcards as text
What is a key indicator of compromise (IoC) in cloud security monitoring?
Answer: An artifact or observation (e.g., unusual API calls, impossible travel logins) that suggests a system may have been breached
IoCs are forensic artifacts such as unusual traffic patterns, unexpected geographic logins, or anomalous API calls that suggest malicious activity may have occurred.
In cloud security, what does UEBA (User and Entity Behavior Analytics) do?
Answer: Establishes behavioral baselines and alerts on anomalous deviations that may indicate insider threats or compromised accounts
UEBA uses machine learning to model normal behavior for users and entities, then flags deviations (e.g., data exfiltration patterns, unusual login times) as potential threats.
What is the primary security benefit of using immutable logging in cloud environments?
Answer: Logs cannot be altered or deleted by attackers, preserving forensic integrity
Immutable logs use write-once storage or append-only mechanisms so that even a fully compromised account cannot alter historical log records, preserving evidence integrity.
Which phase of the incident response lifecycle focuses on restoring systems to normal operations after a security incident?
Answer: Recovery
The Recovery phase involves restoring and validating systems to return to normal business operations after containment and eradication of the threat.
What is the purpose of threat intelligence sharing in cloud security operations?
Answer: To allow organizations to collectively improve defenses by sharing indicators of compromise and attacker tactics across the community
Threat intelligence sharing (via ISACs, STIX/TAXII, or commercial feeds) allows organizations to benefit from others' detection and response experiences to defend against known threats faster.
In a cloud environment, what does automated remediation (auto-remediation) typically do when a misconfiguration is detected?
Answer: Automatically applies corrective actions (e.g., closing an open port, enabling encryption) without human intervention
Auto-remediation uses infrastructure automation to instantly correct detected misconfigurations, reducing the window of exposure without waiting for manual intervention.