ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During an incident response, you must collect evidence from a running Linux workload hosted on a public IaaS platform after IDS alarms indicated possible credential theft. You believe critical artifacts reside both in RAM and on the attached virtual disk. Following commonly accepted forensic data collection methodology that respects the order of volatility and minimizes evidence contamination, which action should you perform first?
Copy /var/log via SSH to secure storage, and afterwards trigger a hypervisor-level snapshot of memory and disk
Immediately stop the instance to freeze its state and create a block-level snapshot of the attached volume
Use the provider's live-memory capture feature to obtain a full RAM dump, then create a snapshot of the virtual disk
Gracefully shut down the VM, export the virtual disk, then request the provider to supply a memory dump
In digital forensics, the order-of-volatility principle states that the most volatile data (which disappears first) must be captured before less volatile data. RAM contents change constantly and are lost as soon as a virtual machine is powered off or modified, so a live memory acquisition is the highest priority. After the memory image is secured, a consistent block-level snapshot of the virtual disk can be taken for later analysis. Shutting down or stopping the instance before capturing memory would destroy volatile evidence, and copying log files from within the OS would alter timestamps and file metadata, compromising integrity.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the 'order-of-volatility' in digital forensics?
Open an interactive chat with Bash
Why is capturing RAM data before other artifacts important in forensic investigations?
Open an interactive chat with Bash
What tools or features can be used to capture RAM data in public IaaS platforms?
Open an interactive chat with Bash
What is the order-of-volatility in digital forensics?
Open an interactive chat with Bash
Why is live-memory acquisition critical in forensic investigations?
Open an interactive chat with Bash
What is a snapshot in the context of virtual disk forensics?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .