
EC-CouncilCertified Cloud Security Engineer
Domain 5Objective 1
Forensic Investigation in Cloud CCSE Practice Questions (Page 4)
Part of the Cloud Forensics and Resilience domain, which makes up ~17% of our current practice bank.
43questions here
9free pages
7concepts
Questions 16–20
- 16
What is the most accurate definition of cloud forensics?
Select an answer first - 17
During an incident in a Kubernetes cluster running on Google Kubernetes Engine (GKE), a forensic analyst needs to capture the state of a compromised pod before it is deleted. Which approach best preserves the pod's forensic data?
Select an answer first - 18
What is the first step in the incident response process as applied to a cloud-based incident?
Select an answer first - 19
An incident responder needs to collect volatile data from a Windows VM in Azure. The VM is running and the responder has administrative access. Which method is most appropriate for collecting memory evidence?
Select an answer first - 20
A company's cloud environment has experienced a suspected data breach. The incident response team needs to preserve evidence while minimizing business disruption. Which action should be taken first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.