Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityHard
A cloud security team is investigating a potential compromise involving a virtual machine (VM) in their IaaS environment. They suspect unauthorized access to the VM's operating system. To perform a forensic analysis without altering the running system, they need to acquire a complete, forensically sound copy of the VM's memory. Which cloud capability would best facilitate this process?
- AAttaching a new data disk
- BMemory acquisition tool via the hypervisor API
- CCreating a custom VM image
- DSnapshotting the VM's disk
Show answer & explanationAnswer & explanation
Correct answer: B. Memory acquisition tool via the hypervisor API
Memory acquisition via the hypervisor API allows for extracting a forensically sound image of the running VM's memory without installing agents or altering the guest OS, which is crucial for incident response.
Why the other options are wrong
- A. Attaching a new data disk is for storage, not for volatile memory acquisition.
- C. Creating a custom VM image is for deploying new VMs, not for live memory forensics.
- D. Snapshotting the disk captures the disk state, but not the volatile memory (RAM).
Cloud VM Memory Forensics
The process of acquiring and analyzing the volatile memory (RAM) of a virtual machine in a cloud environment for security incident response and forensic investigations.
- Crucial for detecting malware, rootkits, and unauthorized processes.
- Often requires specific cloud provider tools or hypervisor API access.
- Must be done carefully to maintain forensic integrity.
Memory trick: When investigating a VM, catching its 'thoughts' (memory) is key. You need to go straight to the HYPERVISOR's brain to get a clean copy, not just look at its 'notes' (disk).