ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During an investigation of suspected insider data theft, an organization's incident response team learns that the virtual machines involved run in a public IaaS environment that automatically terminates unused instances after four hours. Before any evidence is lost, which contractual requirement with the cloud service provider is MOST critical to preserve legally admissible forensic artifacts when such incidents occur?
An SLA guaranteeing 99.99 percent availability for the compute service hosting the workload
Quarterly delivery of the provider's SOC 2 Type II attestation report to the customer
Contractual escrow of customer encryption keys so the provider can decrypt data on demand
A right-to-snapshot clause that obligates the provider to create and preserve full VM images and related logs immediately after an incident is reported
Forensic soundness depends on quickly capturing and preserving volatile evidence before automated cloud processes delete or overwrite it. A contract clause that guarantees immediate creation and secure retention of full VM snapshots and associated logs upon incident notification enables investigators to maintain chain of custody and perform offline analysis. Key-escrow, SOC reports, and high-availability SLAs may be useful for other purposes but do not ensure that the specific data a court may require is captured and preserved in time.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is forensic soundness?
Open an interactive chat with Bash
What is a right-to-snapshot clause?
Open an interactive chat with Bash
Why are SOC 2 Type II reports not sufficient for forensic investigations?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .