Certified Cloud Security Professional (CCSP)Cloud Security OperationsHard

During a cloud incident response, the security team determines that a critical database containing sensitive customer information may have been compromised. To preserve the integrity of potential evidence and ensure proper chain of custody, which of the following is the MOST critical initial step for cloud forensics within an IaaS environment?

  1. ARestoring the database from the last known good backup
  2. BCreating a forensic image of the affected database's underlying storage volume
  3. CCollecting network flow logs from the virtual private cloud (VPC)
  4. DIsolating the affected database instance from the network
Show answer & explanation

Correct answer: B. Creating a forensic image of the affected database's underlying storage volume

Creating a forensic image (or snapshot) of the underlying storage volume is critical for preserving the state of the compromised database at the time of compromise. This ensures that the original evidence is untouched and can be analyzed offline without altering it, which is fundamental for maintaining the integrity and chain of custody required for forensics.

Why the other options are wrong

  • A. Restoring from backup changes the state of the system and potentially overwrites or destroys the evidence of the compromise, making it unsuitable as an initial forensic step.
  • C. Collecting network flow logs is important for understanding network activity, but it's secondary to preserving the compromised system's state itself when the database is the primary target.
  • D. Isolating the instance is a containment step, important for preventing further damage, but not the primary step for *preserving evidence* for forensics.

Cloud Forensics - Evidence Preservation

The process of collecting and preserving digital evidence in a cloud environment in a forensically sound manner.

  • Prioritizes non-alteration of evidence.
  • Requires specialized tools and techniques for cloud resources.
  • Often involves creating snapshots or images of affected assets.

Memory trick: Snap the state first, then secure and search for clues.

More Cloud Security Operations questions