Certified Cloud Security Professional (CCSP)Cloud Security OperationsMedium
A security operations team is implementing a cloud forensics process for an IaaS environment. After identifying a compromised virtual machine, the next critical step is to preserve the integrity of the evidence. Which of the following actions is most crucial for achieving this goal?
- ACreating a snapshot or image of the compromised VM's disk.
- BIsolating the compromised VM from the network.
- CCollecting volatile memory data from the VM.
- DShutting down the compromised VM to prevent further damage.
Show answer & explanationAnswer & explanation
Correct answer: A. Creating a snapshot or image of the compromised VM's disk.
Creating a snapshot or image of the disk ensures a forensically sound copy of the persistent data, preserving its state at the time of compromise without altering the original evidence.
Why the other options are wrong
- B. Isolating the VM is important for containment but doesn't directly preserve the evidence itself.
- C. Collecting volatile data is important, but disk imaging preserves the persistent state, which is often more crucial for initial evidence preservation.
- D. Shutting down the VM can alter volatile memory, modify system logs, and change timestamps, thus corrupting evidence.
Cloud Forensics - Evidence Preservation
The process of securing and maintaining the integrity of digital evidence from cloud environments to ensure its admissibility in legal or disciplinary proceedings.
- Crucial for maintaining chain of custody.
- Often involves creating immutable copies (snapshots/images) of disks.
- Avoids altering the original compromised system.
Memory trick: Evidence is like a delicate flower; preserve it carefully.