A county cloud operations desk wants early warning when audit API calls and VPC flow patterns look abnormal across multi-cloud accounts. Which approach best supports detecting suspicious activity?
Select an answer to reveal the explanation.
Short Explanation
Waiting for someone to file a ticket is like waiting for the fire alarm after the building is already smoky. SIEM-style dashboards that watch audit trails and network events catch weird spikes before the help desk lights up. County clouds generate tons of breadcrumbs—use them.
Full Explanation
Suspicious activity monitoring in cloud environments depends on continuous collection of control-plane audit events and data-plane network telemetry. Security information and event management or equivalent analytics surfaces correlate those streams and flag deviations that human ticket queues would miss. Annual static reviews and silent logging gaps leave municipal operators without timely attack visibility.