Bird
0
0

A forensic team needs to preserve evidence from a cloud service. Which approach best preserves evidence integrity?

hard🧠 Conceptual Q8 of 15
Cybersecurity - Digital Forensics
A forensic team needs to preserve evidence from a cloud service. Which approach best preserves evidence integrity?
ADownload files manually without logging actions
BCapture logs and metadata directly from the cloud provider with timestamps
CAsk the suspect to provide data copies
DTake screenshots of the cloud interface
Step-by-Step Solution
Solution:
  1. Step 1: Understand cloud evidence challenges

    Cloud data is dynamic; capturing logs and metadata preserves context and timing.
  2. Step 2: Evaluate methods for integrity

    Direct capture with timestamps ensures authenticity; manual downloads or screenshots lack full context.
  3. Final Answer:

    Capture logs and metadata directly from the cloud provider with timestamps -> Option B
  4. Quick Check:

    Cloud evidence = Logs + metadata capture [OK]
Quick Trick: Use provider logs to preserve cloud evidence integrity [OK]
Common Mistakes:
MISTAKES
  • Relying on suspect-provided data
  • Using screenshots instead of logs
  • Downloading without logging

Want More Practice?

15+ quiz questions · All difficulty levels · Free

Free Signup - Practice All Questions
More Cybersecurity Quizzes