
EC-CouncilCertified Cloud Security Engineer
Domain 5Objective 1
Forensic Investigation in Cloud CCSE Practice Questions (Page 6)
Part of the Cloud Forensics and Resilience domain, which makes up ~17% of our current practice bank.
43questions here
9free pages
7concepts
Questions 26–30
- 26
A forensic investigator is handling a case where a cloud VM is suspected of containing evidence of fraud. The VM is in a region that is subject to data sovereignty laws. The investigator needs to acquire the VM's disk and memory while preserving the chain of custody. The cloud provider offers a snapshot API and a memory dump feature. The legal team requires that the evidence be stored in a specific country. What is the best approach?
Select an answer first - 27
A forensic analyst is investigating a breach in a multi-tenant cloud environment. The analyst needs to collect evidence from a shared physical host. Which challenge is unique to cloud forensics in this scenario?
Select an answer first - 28
During an incident response in a hybrid cloud environment, the team discovers that an on-premises server and an AWS EC2 instance are both compromised. The team needs to preserve evidence from both environments. Which approach is most appropriate?
Select an answer first - 29
In a cloud-based incident, what is the primary goal of the containment phase?
Select an answer first - 30
What is the primary purpose of a forensic report in a cloud investigation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.