
EC-CouncilComputer Hacking Forensic Investigator
Domain 6Objective 1
Cloud Forensics CHFI Practice Questions (Page 8)
Part of the Cloud and Communication Forensics domain, which makes up ~14% of our current practice bank.
53questions here
11free pages
9concepts
Questions 36–40
- 36
A forensic investigator is starting an investigation of a security incident in a public cloud environment. The incident involves a compromised VM. What is the first step in the cloud forensic process?
Select an answer first - 37
An investigator is analyzing a compromised cloud environment and needs to correlate user activity across multiple services (e.g., storage, compute, and identity). Which tool is most appropriate for this task?
Select an answer first - 38
An investigator needs to acquire evidence from a cloud VM that is part of a clustered application. The VM is running and holds critical volatile data. The investigator has access to the cloud provider's API. The VM is encrypted with a customer-managed key. What is the best approach to preserve volatile evidence while maintaining the VM's availability?
Select an answer first - 39
A forensic investigator is examining a cloud environment and needs to analyze virtual machine disk images. Which tool is most appropriate for this task?
Select an answer first - 40
A forensic investigator is examining a breach in a hybrid cloud deployment where sensitive customer data is stored in a private cloud on-premises and processing workloads run in a public cloud. The investigator needs to collect evidence from both environments. What is the primary challenge that must be addressed first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.