Courseiva
Network and Cloud Forensics →mediumMultiple Choice

CHFI Network and Cloud Forensics Practice Question

An investigator is analyzing cloud storage logs and finds an entry showing that a file was accessed using the root credentials from an IP address in a different geographic region. The organization has strict policies against root usage. What should the investigator do FIRST?

⚠ Common exam trap

The trap here is that candidates panic and choose a reactive security action (like revoking keys or changing passwords) instead of following forensic best practice: preserve and validate before acting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check if the activity correlates with a known vulnerability or authorized task

The first step in any forensic investigation is to correlate the suspicious activity with known events, such as authorized tasks or vulnerabilities, to avoid false positives. Root access from an unfamiliar IP could be legitimate if tied to a scheduled maintenance window or a known vulnerability exploitation attempt that requires verification. Prematurely changing credentials or contacting law enforcement could destroy evidence or alert an attacker before the scope is understood.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Check if the activity correlates with a known vulnerability or authorized task

    Why this is correct

    Correlating the observed access against logged change tickets, vulnerability scanners (e.g., CVE data), and scheduled maintenance windows is the correct initial triage step. It lets you determine whether the activity is a false positive or expected administrative behavior before taking any action that would be disruptive or destructive. Cross-referencing source IP, user agent, and API call pattern against known vulnerability signatures or authorized task records preserves evidential integrity while filtering out benign anomalies.

  • ✗

    Contact law enforcement for cybercrime investigation

    Why it's wrong here

    Contacting law enforcement at this stage is premature and can jeopardize the investigation. Legal referral is appropriate only after internal technical verification confirms that the activity is malicious, the scope is understood, and digital evidence has been legally preserved. Premature reporting risks violating jurisdictional thresholds or tipping off the adversary, and it bypasses the internal incident response workflow where attribution and impact are still unconfirmed.

  • ✗

    Change the password of the root account

    Why it's wrong here

    Changing the root account password is an invasive containment measure that can alert the adversary and destroy volatile forensic evidence such as active session tokens, kernel memory artifacts, or attacker-modified configuration files. In cloud environments, credential rotation may also break dependent services or logging pipelines, causing the loss of critical audit trail data. The password should be rotated only after evidence has been captured and a documented incident response plan authorizes credential remediation.

  • ✗

    Immediately revoke the root access keys

    Why it's wrong here

    Immediately revoking root access keys is a reactive action based on unconfirmed suspicion; it may lock out legitimate users, break automation, and cause an availability incident if the access was actually authorized. Revoking keys also destroys the ability to continue passive monitoring of the attacker's behavior, which is often necessary to determine entry point and dwell time. The proper sequence is to first validate the activity through log correlation, preserve forensic artifacts, and only then apply least-privilege containment measures under a formal IR decision.

About these practice questions

One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.