CHFI Application, Email and Cloud Forensics Practice Question
A security analyst is investigating a potential data breach in a GCP environment. The analyst reviews the GCP audit logs and finds the following events: (1) A service account was granted the 'roles/storage.objectAdmin' role on a storage bucket containing sensitive data, (2) The service account then listed objects in the bucket, (3) The service account downloaded several objects. Which THREE actions should the analyst take immediately?
⚠ Common exam trap
EC-CHFI emphasizes the importance of preserving evidence and following forensic procedures; candidates might mistakenly choose to delete the bucket thinking it stops the breach, but that destroys evidence and violates forensic chain of custody.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analyze the IAM policy change that granted the role to identify the source
Option A is correct because the first event is an IAM policy change (granting roles/storage.objectAdmin), and the analyst must trace the Admin Activity audit log entry for SetIamPolicy to identify the principal, source IP, user agent, and timestamp that made the grant. Option B is correct because roles/storage.objectAdmin grants full control over objects (create, read, update, delete), which is excessive for a service account that only needs to read sensitive data; revoking or downgrading the binding (e.g., to roles/storage.objectViewer) immediately limits further exfiltration. Option D is correct because audit logs are the primary forensic evidence and can be altered or aged out under the default 30-day Data Access log retention, so exporting them to a secure, immutable location (e.g., a locked Cloud Storage bucket or BigQuery dataset) preserves the chain of custody. Option C is not appropriate as an immediate technical step since law enforcement should be engaged only after internal incident response confirms a breach and per organizational/legal guidance. Option E is wrong because deleting the bucket destroys evidence and does not stop the already-granted service account from acting elsewhere; containment should be done via IAM revocation and key disabling instead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Analyze the IAM policy change that granted the role to identify the source
Why this is correct
Analyzing the IAM policy change that granted the role is the definitive step for identifying the source because it reveals the exact principal, timestamp, and method used to elevate privileges. Check Cloud Admin Activity audit logs for 'google.iam.admin.v1.SetIAMPolicy' events, noting whether the grant came from a compromised user, an OAuth token, or an external session. This forensic root-cause analysis establishes the attack vector and scope, guiding appropriate containment and recovery efforts.
- ✓
Revoke the service account's excessive permissions
Why this is correct
Revoking the service account's excessive permissions is an effective containment measure that stops the attacker from continuing to use the compromised identity to access or exfiltrate data. However, simply deleting the role may break legitimate operations, so first document the original policy bindings and, if possible, implement a temporary deny policy or conditional access that blocks the suspicious source while preserving evidence. The goal is to terminate ongoing access without erasing the evidence trail.
- ✗
Contact law enforcement immediately
Why it's wrong here
Contacting law enforcement immediately is inappropriate at this stage because the highest priority is to contain the breach and preserve volatile cloud logs and memory before they are lost. Premature external notification can trigger legal holds or chain-of-custody issues, and may not align with organizational incident-response procedures that require initial internal investigation and triage. Law enforcement involvement is a later consideration after evidence is secured and the scope of the breach is understood.
- ✓
Preserve the audit logs by exporting them to a secure location
Why this is correct
Preserving audit logs by exporting them to a secure, separate storage bucket with object versioning, retention locks, and restricted access prevents an attacker with high-level permissions from overwriting or deleting forensic evidence. Because Admin Activity and Data Access logs are stored for limited retention windows, immediate export to an immutable medium ensures that the IAM grant event and all subsequent actions are available for deep analysis. This is a critical first step in maintaining the chain of custody.
- ✗
Delete the storage bucket to prevent further access
Why it's wrong here
Deleting the storage bucket to prevent further access is a destructive error because the bucket contains the only evidence of the exfiltration—object metadata, access logs, and possibly the exact data copy. The attacker may have already transferred the data to another location, so deletion neither stops exfiltration nor secures the environment; instead, it destroys the artifacts needed to determine the breach scope and origin. Proper incident response would be to disable access, remove compromised credentials, and leave the bucket intact for forensic capture.
Go deeper
Related to this question
Learn chapter
Evidence Handling and Chain of Custody
Key term
Chain of custody
Chain of custody is a documented process that tracks the handling, transfer, and possession of evidence or digital assets from the moment they are collected until they are presented in court or used in an investigation.
Key term
Process Memory Dump
A process memory dump is a snapshot of all the data a specific running program has stored in RAM at a single moment, used for analyzing its behavior and contents.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.