CHFI Network and Cloud Forensics Practice Question
During a cloud forensics investigation, the investigator discovers that the cloud provider uses shared storage for multiple tenants. Which challenge is MOST likely to arise when acquiring a forensic image?
⚠ Common exam trap
EC-Council often tests the misconception that physical access or encryption are the main hurdles, but the real challenge in cloud forensics is data commingling due to shared tenancy, which complicates legal and technical acquisition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data commingling with other tenants
In cloud environments with shared storage, data from multiple tenants resides on the same physical or logical volume. When acquiring a forensic image, the investigator cannot isolate a single tenant's data without also capturing other tenants' data, leading to data commingling. This violates chain-of-custody and privacy principles, making it the primary challenge.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Physical acquisition of the storage device is required
Why it's wrong here
In cloud environments, physical acquisition is not a forensic requirement because the underlying storage is abstracted by virtualization and multi-tenancy. Investigators can acquire evidence through logical means, such as snapshotting a virtual disk, exporting a cloud image, or using the provider's storage APIs. The fact that storage is shared does not force physical access; the hypervisor or storage backend presents a consistent logical view. Thus, this option is incorrect.
- ✗
No API access to the storage system
Why it's wrong here
The availability of API access to a cloud storage system is a function of the provider's service model, access controls, and contractual cooperation, not a consequence of shared storage. Most major providers offer forensic-friendly APIs or SDKs for enumerating and retrieving objects, and investigators often use these for logical acquisition. Shared physical media does not eliminate or obstruct these API endpoints, so this is not a challenge specific to multi-tenant storage. Therefore, this option is not correct.
- ✗
Inability to decrypt data at rest
Why it's wrong here
Decrypting data at rest is a general forensic obstacle that applies whether storage is dedicated or shared, because it depends on the encryption strategy (e.g., server-side vs. client-side) and the availability of keys. Cloud yields key-management services that can be leveraged, and investigators may obtain keys from the tenant. Shared storage does not inherently alter the decryption process, as encryption operates on logical volumes or objects regardless of physical media sharing. Hence, it is not a challenge unique to shared storage.
- ✓
Data commingling with other tenants
Why this is correct
Data commingling with other tenants is the core challenge, as shared storage causes multiple organizations' data to occupy the same physical media, including potentially unallocated or leftover blocks. A forensic acquisition from such media may inadvertently capture another tenant's data, creating privacy, legal, and chain-of-custody complications. Investigators must employ careful isolation techniques, such as acquiring only the specific virtual disk or object while documenting that surrounding media contains unrelated data. This makes tenant-to-tenant isolation the primary difficulty in multi-tenant cloud forensics.
Go deeper
Related to this question
Learn chapter
Forensic Investigation Process and Methodology
Key term
EnCase Forensic
EnCase Forensic is a digital forensics software suite used by investigators to acquire, analyze, and report on data from computers and mobile devices in a legally admissible way.
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.