ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
A security incident has exposed an Amazon EC2 instance that hosts sensitive customer data. The organization's digital-forensics policy states: 1) create a snapshot of the affected Amazon EBS volume using approved AWS tools, 2) immediately calculate and record an SHA-256 hash of the snapshot, and 3) upload both the hash value and the acquisition log to the secured evidence vault before any examination occurs. A junior cloud security engineer performs the following steps:
Creates the snapshot with the AWS CLI.
Attaches the snapshot to an isolated forensics account in read-only mode and inspects the file system for indicators of compromise.
Calculates the SHA-256 hash of the snapshot and stores the hash and acquisition log in the evidence vault.
Which step violated the organization's policy?
Uploading the acquisition log and hash file to the secured evidence vault via SFTP
Creating the snapshot of the EBS volume with the AWS CLI
Calculating a SHA-256 hash of the snapshot
Attaching the snapshot to an isolated account and inspecting the file system before hashing it
The organization mandates that the cryptographic hash of the evidence be generated and recorded immediately after the snapshot is taken, before any examination. Mounting and inspecting the snapshot before computing the hash risks altering the evidence (for example, by triggering file-system updates) and breaks the prescribed chain-of-custody sequence. Simply using the AWS CLI to create the snapshot, uploading logs to the evidence vault, or keeping the attachment read-only all comply with the stated procedures.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an SHA-256 hash?
Open an interactive chat with Bash
Why is calculating the hash before examination important in digital forensics?
Open an interactive chat with Bash
What does the chain of custody mean in digital forensics?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Incident Response and Recovery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .