
EC-CouncilComputer Hacking Forensic Investigator
Domain 6Objective 1
Cloud Forensics CHFI Practice Questions (Page 2)
Part of the Cloud and Communication Forensics domain, which makes up ~14% of our current practice bank.
53questions here
11free pages
9concepts
Questions 6–10
- 6
An investigator is handling a cloud incident where the compromised VM is in a different region than the investigator's location. The VM is running and contains volatile evidence. The investigator has API access but no direct console access. What is the best sequence of actions?
Select an answer first - 7
A company uses a hybrid cloud where sensitive data is stored in an on-premises private cloud and processed in a public cloud. An incident occurs, and evidence is needed from both environments. The legal team is concerned about cross-border data transfer because the public cloud is in another country. What is the most important factor in planning the evidence collection?
Select an answer first - 8
What is a key capability of cloud-native forensic tools provided by cloud service providers?
Select an answer first - 9
An investigator needs to collect volatile evidence from a running cloud VM in an IaaS environment. The VM is critical to the business and cannot be stopped. Which method is most appropriate?
Select an answer first - 10
An investigator needs to collect user activity logs from a cloud storage service. The service provides an API for accessing logs. What is the most appropriate method to ensure the logs are preserved as evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.