Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityMedium

A company is implementing a new cloud-based data analytics platform that processes sensitive customer information. The platform utilizes multiple cloud services, including compute instances, managed databases, and object storage. To maintain regulatory compliance, the company needs to ensure that all administrative actions performed on these cloud resources are recorded, immutable, and easily auditable. Which cloud management plane security feature BEST addresses this requirement?

  1. AData Loss Prevention (DLP) policies across services.
  2. BCloud audit logging and monitoring services.
  3. CCentralized Identity and Access Management (IAM).
  4. DCloud Access Security Broker (CASB) integration.
Show answer & explanation

Correct answer: B. Cloud audit logging and monitoring services.

Cloud audit logging and monitoring services (e.g., AWS CloudTrail, Azure Monitor Activity Logs, GCP Cloud Audit Logs) are specifically designed to record all API calls and administrative actions taken on cloud resources. These logs are typically immutable, time-stamped, and can be integrated with analytical tools for auditing and compliance purposes, directly addressing the requirement.

Why the other options are wrong

  • A. DLP policies prevent sensitive data exfiltration but do not track or record administrative actions taken on cloud resources.
  • C. Centralized IAM manages user identities and permissions, which is crucial for controlling who *can* perform actions, but it does not inherently record *what* actions were performed in an immutable, auditable log.
  • D. CASBs provide visibility, compliance, and threat protection, but their primary role is not to be the definitive source of immutable administrative action logs for the CSP's services.

Cloud Audit Logging

A cloud service feature that records API calls and administrative actions for all resources, providing an immutable audit trail for security and compliance.

  • Records all management plane activities.
  • Logs are typically immutable and time-stamped.
  • Essential for compliance, forensics, and security monitoring.

Memory trick: Audit logs record every cloud command, for compliance always at hand.

More Cloud Platform and Infrastructure Security questions