
EC-CouncilCertified Cloud Security Engineer
Domain 5Objective 1
Forensic Investigation in Cloud CCSE Practice Questions (Page 8)
Part of the Cloud Forensics and Resilience domain, which makes up ~17% of our current practice bank.
43questions here
9free pages
7concepts
Questions 36–40
- 36
A forensic team is collecting evidence from a cloud environment that is subject to a legal hold. Which action is most important to ensure the evidence remains intact?
Select an answer first - 37
A security analyst is responding to a suspected compromise of a Linux VM in AWS. The instance is still running, and the analyst needs to preserve volatile data before shutting it down. Which action should the analyst take first?
Select an answer first - 38
A forensic investigation involves data stored in a cloud provider located in a different country than the company's headquarters. The legal team is concerned about cross-border data transfer regulations. Which factor is most critical in determining whether the data can be legally transferred?
Select an answer first - 39
A security team is responding to a ransomware attack that encrypted files in an Azure Storage account. The team needs to recover the data and preserve evidence. Which action should be taken first?
Select an answer first - 40
A company has detected a ransomware attack on a cloud workload. The incident response team is following the NIST incident response lifecycle. Which phase involves identifying the attack vector and the affected resources?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCSE” is a trademark of its owner, used for identification only.