ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During a cloud-hosted breach investigation, a security analyst must export hypervisor log files from the provider's management plane to the corporate forensic repository. Which action best maintains the evidentiary value of the logs so they remain admissible in court?
Generate a cryptographic hash of the original logs, copy them to read-only media, recalculate the hash on the copies, and record each hand-off in a chain-of-custody log.
Export the logs via secure FTP, then encrypt the archive with the organization's public PGP key before distribution to the investigation team.
Compress the log directory on the hypervisor to reduce size, delete the uncompressed originals, and transfer the archive over an encrypted tunnel.
Take timestamped screenshots of the log entries, email them to yourself, and request the cloud provider keep the raw files for 90 days.
For digital evidence to be admissible, the analyst must be able to prove the data has not been altered and to document everyone who handled it. Creating a cryptographic hash (for example, SHA-256) of the original log files before acquisition, then validating that the copied files produce an identical hash, demonstrates integrity. Recording these steps in a chain-of-custody form links each person, date, time, and action taken with the evidence. Simply relying on provider timestamps, screenshots, or compressed copies without originals does not provide strong assurance against tampering, and encrypting after transfer without prior hashing cannot prove the files were unaltered during transit.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a cryptographic hash and why is it used in forensic investigations?
Open an interactive chat with Bash
What is a chain-of-custody log, and why is it important in evidence handling?
Open an interactive chat with Bash
What is SHA-256 and how is it different from other hashing algorithms?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .