exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 161 discussion

Actual exam question from CompTIA's CS0-002
Question #: 161
Topic #: 1
[All CS0-002 Questions]

Which of the following BEST describes how logging and monitoring work when entering into a public cloud relationship with a service provider?

  • A. Logging and monitoring are not needed in a public cloud environment.
  • B. Logging and monitoring are done by the data owners.
  • C. Logging and monitoring duties are specified in the SLA and contract.
  • D. Logging and monitoring are done by the service provider.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
wico1337
Highly Voted 2 years, 6 months ago
Selected Answer: C
Honestly, seeing so many people say D, that I trusted, make me regret trusting their decisions for earlier answers. This is so blatantly C that I am shocked someone made it to this test without knowing it. D is stating "as a matter of fact". When in reality, you can easily have cloud platforms in which you are in charge of logging/monitoring. Paas for example. Everything in the end will be defined in the contract or SLA.
upvoted 7 times
wico1337
2 years, 6 months ago
Or even think about Iaas lol
upvoted 2 times
...
2Fish
2 years, 1 month ago
Agree.. the verbiage can throw us off sometimes. In AWS, you subscribe to CloudTrail, CloudWatch, and GuardDuty. Now, while AWS actually logs the data, the company will monitor the alerts.
upvoted 1 times
...
...
chaddman
Most Recent 1 year, 6 months ago
Selected Answer: C
When entering into a public cloud relationship with a service provider, the responsibilities surrounding logging and monitoring are typically specified in the Service Level Agreement (SLA) and contract. These documents delineate the roles and responsibilities of both the cloud service provider and the customer regarding various aspects of the service, including security monitoring and logging. It's crucial to have these duties clearly outlined to ensure proper security measures are followed, and both parties are aware of their respective responsibilities. Therefore, the answer is: C. Logging and monitoring duties are specified in the SLA and contract.
upvoted 1 times
...
grelaman
1 year, 7 months ago
Selected Answer: D
While customers may have the option to configure and customize logging and monitoring settings to meet their specific needs, the service provider is responsible for the underlying infrastructure and the default monitoring and logging mechanisms.
upvoted 1 times
grelaman
1 year, 7 months ago
The SLA and contract will typically define the specific metrics that will be logged and monitored, as well as the frequency and method with which the data will be collected and reported. The SLA may also specify the service provider's response time to any logging or monitoring alerts. In my opinon, SLA is not the best way to describe how logging and monitoring work in a cloud environment or when we are subscribing services to a Cloud provider.
upvoted 1 times
...
...
POWNED
1 year, 9 months ago
Selected Answer: C
Its scary to see people voting on here that have no idea what they are talking about. When it comes to the cloud there is no 1 right answer here. What if the customer has a IaaS, PaaS, SaaS? The only and obvious answer here is C.
upvoted 1 times
...
kyky
1 year, 10 months ago
Selected Answer: D
D. Logging and monitoring are done by the service provider. When using a public cloud service, the responsibility for logging and monitoring typically lies with the service provider. Public cloud service providers have robust logging and monitoring systems in place to ensure the security, performance, and availability of their services.
upvoted 1 times
...
ksr933
2 years ago
Comptia material says SLA Logging and Monitoring Again, as part of standard secure software development practices, the API should provide sufficient logging and monitoring. Monitoring should provide alerts when an API is being bombarded with requests in a potential DoS attack, or being subject to multiple authentication or other errors, indicating a potential brute force or fuzzing attack. Another potential issue is if the cloud provider does not supply access to log files or monitoring tools. This is most likely to be the case with a software as a service model. Requirements for logging and monitoring should be identified at the start of a contract and set out in an SLA with the provider.
upvoted 1 times
...
Dany_Suarez
2 years, 2 months ago
Selected Answer: C
Comptia guide says: Logging and Monitoring Another potential issue is if the cloud provider does not supply access to log files or monitoring tools. This is most likely to be the case with a software as a service model. Requirements for logging and monitoring should be identified at the start of a contract and set out in an SLA with the provider.
upvoted 2 times
...
gwanedm
2 years, 4 months ago
Selected Answer: C
I will go with C
upvoted 2 times
...
Abyad
2 years, 5 months ago
Selected Answer: C
6 Cloud Monitoring Best Practices 1. Use the Built-in Activity Monitoring All leading cloud providers can be set to monitor every cloud activity — human, script or API-based — basically at no cost other than the storage used. These cloud activity logs can be sizable and verbose, so most enterprises keep them in the cloud to reduce bandwidth costs, allowing for larger datasets and longer retention. 2. Activate Logging on Everything You can and Retain it For at Least a Year In addition to activity logs, the leading cloud providers offer detailed logging for every IaaS/PaaS capability offered — networking, containers, serverless and other services. The best practice is to log everything possible, including network flow logs. This pervasive visibility can be baselined and analyzed for patterns, providing the foundation for behavioral analytics-based threat detection
upvoted 2 times
...
SolventCourseisSCAM
2 years, 5 months ago
Selected Answer: C
when entering public cloud relationship, before beginning to use public cloud service, there is a SLA/contract which mentions how the logging and monitoring service works while using the service. You can choose D, but it depends what kinds of cloud service you are getting from public cloud. If you are getting IaaS or PaaS, maybe you are responsible for logging and monitoring, so it mentions on the SLA/contract. On SaaS service provide provides logging and monitoring, but "AGAIN" it mentions on the SLA/contract. So the answer is not D, but C
upvoted 1 times
SolventCourseisSCAM
2 years, 5 months ago
I am changing my answer to D
upvoted 1 times
...
...
forklord72
2 years, 6 months ago
I couldn't find any information in my research to support this but I thought it was odd how in the question the word public was specified for the type of cloud provider. Makes me wonder if companies are allowed to have monitoring privileges in a public environment
upvoted 1 times
forklord72
2 years, 6 months ago
Going with C if I get this question, I never learned anywhere about there being a definitive answer on who is responsible in any cloud environment.
upvoted 1 times
...
...
R00ted
2 years, 6 months ago
Selected Answer: D
I agree with D
upvoted 1 times
...
SAAVYTECH
2 years, 7 months ago
Selected Answer: D
When transitioning over to a cloud solution, an organization may lose visibility of certain points on the technology stack, particularly if it’s subscribing to PaaS or SaaS solutions. Because the responsibility of protecting portions of the stack falls to the service provider, it does sometimes mean the organization loses monitoring capabilities, for better or worse. Chapman, Brent; Maymi, Fernando. CompTIA CySA+ Cybersecurity Analyst Certification All-in-One Exam Guide, Second Edition (Exam CS0-002) (p. 158). McGraw Hill LLC. Kindle Edition.
upvoted 3 times
...
amateurguy
2 years, 7 months ago
Selected Answer: C
I actually don't have a 100% sure answer for this, I would think that the SLA would decide who does the logging and monitoring, could it be that sometimes the organization itself does the logging and monitoring and it doesn't always have to be done by the service provider? The other thing is they are saying that they are about to "go into a relationship", i think that doesn't necessarily mean that the cloud service provider is a cloud SECURITY service provider, they could be providing another cloud service. If I had to go with an answer it would be C, Im going with SLA and contract.
upvoted 2 times
...
Cizzla7049
2 years, 7 months ago
Selected Answer: D
D is the answer
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago