Certified Cloud Security Professional (CCSP)Cloud Security OperationsMedium
During a cloud security incident involving a suspected data exfiltration from a storage bucket, a forensic investigator needs to collect immutable logs that record all access attempts, modifications, and deletions to the bucket, including the identity of the actor and the timestamp. Which cloud service or feature would be most critical for the investigator to analyze to establish a chain of custody and reconstruct the event timeline?
- ACloud resource tags.
- BCloud activity logging (e.g., AWS CloudTrail, Azure Monitor Activity Log, GCP Cloud Audit Logs).
- CNetwork traffic flow logs (e.g., VPC Flow Logs, NSG Flow Logs).
- DVirtual Machine (VM) console output.
Show answer & explanationAnswer & explanation
Correct answer: B. Cloud activity logging (e.g., AWS CloudTrail, Azure Monitor Activity Log, GCP Cloud Audit Logs).
Cloud activity logging services (like CloudTrail, Azure Monitor Activity Log, Cloud Audit Logs) specifically record API calls and management events for cloud resources, including who performed an action, what action was performed, and when. These logs are immutable and crucial for forensic investigations to reconstruct event timelines and establish chain of custody.
Why the other options are wrong
- A. Resource tags are labels for organizing resources and do not provide activity logs or forensic evidence.
- C. Network flow logs show network traffic metadata (source/destination IP, port, protocol) but do not typically contain details about who accessed a storage bucket or what specific actions were performed on it.
- D. VM console output primarily shows boot messages and OS-level interactions, not specific cloud service API calls or storage bucket access.
Cloud Activity Logging
Cloud services that record API calls and management events for cloud resources, providing an audit trail of actions taken within the cloud environment.
- Captures 'who, what, when, where' for cloud resource operations.
- Logs are typically immutable to ensure integrity for forensic purposes.
- Essential for security auditing, compliance, and incident response.
Memory trick: Cloud 'Trail' leaves breadcrumbs for the forensic 'Detective'.