Certified Cloud Security Professional (CCSP)Cloud Security OperationsEasy
A cloud security analyst is investigating a potential insider threat where a privileged user is suspected of unauthorized data access. Which of the following cloud security monitoring tools would provide the most relevant information for detecting and analyzing this specific type of activity?
- ACloud firewall logs
- BUser and Entity Behavior Analytics (UEBA)
- CNetwork flow logs
- DVulnerability scanner reports
Show answer & explanationAnswer & explanation
Correct answer: B. User and Entity Behavior Analytics (UEBA)
UEBA tools specialize in detecting anomalous user behavior, which is crucial for identifying insider threats that might involve legitimate credentials used for unauthorized actions.
Why the other options are wrong
- A. Cloud firewall logs primarily focus on network perimeter traffic and access rules, not internal user behavior anomalies.
- C. Network flow logs show traffic patterns but might not reveal the intent or specific user actions behind authorized network connections.
- D. Vulnerability scanner reports identify system weaknesses, not ongoing user activity or insider threats.
User and Entity Behavior Analytics (UEBA)
A security solution that uses machine learning and analytics to detect anomalous behavior by users and entities (e.g., applications, hosts) within an organization's cloud environment.
- Focuses on identifying insider threats and targeted attacks.
- Establishes a baseline of normal behavior.
- Alerts on deviations from baselines.
Memory trick: UEBA watches users like a hawk watches its prey.