
EC-CouncilCertified Cloud Security Engineer
Domain 5Objective 1
Forensic Investigation in Cloud CCSE Practice Questions (Page 2)
Part of the Cloud Forensics and Resilience domain, which makes up ~17% of our current practice bank.
43questions here
9free pages
7concepts
Questions 6–10
- 6
What is the primary purpose of maintaining a chain of custody for cloud-based evidence?
Select an answer first - 7
A security team detects suspicious activity on an Azure VM. The incident response plan requires preserving evidence for potential legal action. Which sequence of actions aligns with proper incident response and forensic preservation?
Select an answer first - 8
A forensic investigation involves data that is subject to a legal hold order. The data resides in a cloud storage service. What must the investigator do to comply with the legal hold?
Select an answer first - 9
A forensic investigator is examining a serverless application on AWS Lambda. The function's code has been updated multiple times since the incident. Which data source provides the most reliable evidence of what code was executed during the incident?
Select an answer first - 10
A forensic investigator is acquiring evidence from a cloud environment and needs to maintain a clear chain of custody. Which practice is essential?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.