ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During an investigation in an IaaS environment, a security engineer discovers that an active Windows Server virtual machine may be exfiltrating sensitive data. The engineer can immediately perform any of the following actions: request a hypervisor memory dump of the running VM, trigger a crash-consistent snapshot of its virtual disks, download the cloud provider's API access logs, or retrieve the last 24 hours of firewall logs. To best preserve digital evidence in line with the accepted order of volatility, which action should the engineer perform first?
Trigger an immediate crash-consistent snapshot of the VM's virtual disks.
Collect the past 24 hours of firewall logs from the provider's archive.
Download the cloud provider's API access logs before they are overwritten.
Request a hypervisor-level memory snapshot of the live virtual machine.
Forensic collection generally follows the order of volatility principle: data most likely to change or disappear is captured before less-volatile information. In a live virtual machine, RAM contains running processes, encryption keys, network connections, and other transient artifacts that can be lost as soon as the system is shut down or altered. A hypervisor-level memory snapshot captures this volatile data with minimal impact on the guest. Virtual disk snapshots, API logs, and archived firewall logs are all less volatile because they are written to persistent storage and can be retrieved later without significant risk of loss or alteration. Therefore, acquiring the memory dump first best preserves critical evidence while maintaining its integrity.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the order of volatility?
Open an interactive chat with Bash
Why is a hypervisor memory snapshot important during forensic investigations?
Open an interactive chat with Bash
How does a crash-consistent snapshot differ from a hypervisor memory snapshot?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .