CCSP - Cloud Data Security - Section 2.8

Design and implement auditability, traceability, and accountability of data events.

Definition of event sources and identity attribution, logging and storage of event data, chain of custody and non-repudiation, and continuous optimisation of log collection.

event sources and attributionchain of custodynon-repudiationlog managementSIEM

Practice question for this objective

Free sampleCloud Data Securitymedium

A team collects logs from many cloud services into a central platform and wants a capability that not only stores the events but also correlates them in near real time to raise alerts on suspicious patterns. Which statement most accurately distinguishes a SIEM from a basic log management system?

  • AA SIEM adds correlation, alerting, and analysis across aggregated events, whereas log management chiefly collects, stores, and retains them Correct
  • BA SIEM only archives raw events for compliance retention, whereas log management performs the real-time correlation and alerting
  • CA SIEM replaces the need to generate logs at each source because it produces its own event records independently
  • DA SIEM and log management are interchangeable terms, differing only in the vendor branding applied to the same tool
Distinguish a SIEM's correlation and alerting layer from a log management system's collection and retention role. Log management focuses on aggregating, storing, and retaining event data, while a SIEM builds on that foundation by correlating events across sources and generating near real-time alerts, which is the analytical capability the team is seeking.

Why A is correct: This captures the real distinction: log management centralises collection, storage, and retention, while a SIEM layers cross-source correlation, analytics, and near real-time alerting on top of that aggregated data.

Why B is wrong: This reverses the two roles; archiving for retention is the log management function, and correlation with alerting is what the SIEM adds, so the mapping is backwards.

Why C is wrong: A SIEM depends on events forwarded from sources; it does not manufacture authoritative records on their behalf, so treating it as a substitute for source logging is incorrect.

Why D is wrong: The terms are not synonyms; conflating them ignores the analytical correlation and alerting layer that defines a SIEM beyond simple collection and storage.

See more CCSP practice questions, answers explained.

More in this domain

Back to all Cloud Data Security objectives, or the CCSP cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.