
EC-CouncilComputer Hacking Forensic Investigator
Domain 6Objective 1
Cloud Forensics CHFI Practice Questions (Page 9)
Part of the Cloud and Communication Forensics domain, which makes up ~14% of our current practice bank.
53questions here
11free pages
9concepts
Questions 41–45
- 41
An investigator needs to collect virtual machine (VM) disk images from an IaaS environment for analysis. The VMs are running in a public cloud. Which method is most appropriate for acquiring non-volatile evidence?
Select an answer first - 42
A government agency uses a community cloud shared with other agencies. An incident occurs, and the agency needs to collect evidence. What is a unique forensic consideration for this deployment model?
Select an answer first - 43
What is a common method for acquiring non-volatile evidence from an IaaS virtual machine?
Select an answer first - 44
A multinational corporation operates a hybrid cloud where customer data is processed in a public cloud region in Singapore and archived in a private cloud hosted in Frankfurt. A data breach occurs, and the legal team requires forensic acquisition of the archived data. The private cloud's storage is encrypted at rest with keys held by the corporation. The public cloud provider refuses to release logs without a court order from Singapore. Which forensic approach best addresses the jurisdictional and access constraints?
Select an answer first - 45
A company uses an IaaS platform and suspects a compromised VM. The investigator needs to acquire volatile memory evidence. What is the most appropriate method?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CHFI” is a trademark of its owner, used for identification only.