Certified Cloud Security Professional (CCSP)Cloud Security OperationsMedium

A security operations team is implementing a cloud forensics process for an IaaS environment. After identifying a compromised virtual machine, the next critical step is to preserve the integrity of the evidence. Which of the following actions is most crucial for achieving this goal?

  1. ACreating a snapshot or image of the compromised VM's disk.
  2. BIsolating the compromised VM from the network.
  3. CCollecting volatile memory data from the VM.
  4. DShutting down the compromised VM to prevent further damage.
Show answer & explanation

Correct answer: A. Creating a snapshot or image of the compromised VM's disk.

Creating a snapshot or image of the disk ensures a forensically sound copy of the persistent data, preserving its state at the time of compromise without altering the original evidence.

Why the other options are wrong

  • B. Isolating the VM is important for containment but doesn't directly preserve the evidence itself.
  • C. Collecting volatile data is important, but disk imaging preserves the persistent state, which is often more crucial for initial evidence preservation.
  • D. Shutting down the VM can alter volatile memory, modify system logs, and change timestamps, thus corrupting evidence.

Cloud Forensics - Evidence Preservation

The process of securing and maintaining the integrity of digital evidence from cloud environments to ensure its admissibility in legal or disciplinary proceedings.

  • Crucial for maintaining chain of custody.
  • Often involves creating immutable copies (snapshots/images) of disks.
  • Avoids altering the original compromised system.

Memory trick: Evidence is like a delicate flower; preserve it carefully.

More Cloud Security Operations questions