CHFI Application, Email and Cloud Forensics Practice Question
Which cloud forensic challenge refers to the inability to physically access the storage media where data resides?
⚠ Common exam trap
EC-Council CHFI exam often tests the distinction between 'lack of physical access' and 'multi-tenancy' by presenting multi-tenancy as a plausible answer, but the key is that multi-tenancy is about resource sharing, not the inability to physically touch the storage media.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Lack of physical access
Cloud forensics often involves data stored on remote servers managed by a cloud service provider (CSP). Forensic investigators cannot physically seize or access the hard drives or SSDs due to the CSP's infrastructure and security policies, making physical access impossible. This lack of physical access is a fundamental challenge that distinguishes cloud forensics from traditional digital forensics, where the media can be physically acquired and imaged.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data jurisdiction
Why it's wrong here
Data jurisdiction is a legal challenge that involves determining which country's laws govern access to data stored in other territories, potentially requiring mutual legal assistance treaties or cross-border warrants. It does not refer to the physical inability to seize or touch cloud servers, which is the specific challenge of lack of physical access. Jurisdiction obstacles are about legal authorization and data sovereignty, not about the investigator's hands-on capabilities.
- ✓
Lack of physical access
Why this is correct
Lack of physical access means investigators cannot directly seize or image the underlying magnetic media or solid-state drives that store cloud data, because those devices reside in provider-managed data centers. This forces reliance on logical acquisition through provider APIs or legal processes, making it difficult to verify the integrity and chain of custody of the evidence. It is the core forensic challenge that distinguishes cloud investigations from traditional on-premises computer forensics.
- ✗
Multi-tenancy
Why it's wrong here
Multi-tenancy is a cloud characteristic where multiple customers share the same physical infrastructure, such as processors, memory, and storage, which creates risks of cross-tenant data exposure and complicates isolation of evidence during forensic collection. However, this is a shared-resource challenge, not a physical access challenge: the investigator still cannot touch the hardware, but the added complication is separating one tenant's data from another on the same disk. Multi-tenancy also raises privacy and legal concerns because other tenants' data may be co-mingled, but the inability to physically seize servers is a distinct issue.
- ✗
Volatility of evidence
Why it's wrong here
Volatility of evidence refers to the temporary and transient nature of certain digital artifacts, such as RAM contents, open network connections, and process listings, which vanish when power is lost or the system is shut down. In the cloud, elasticity and auto-scaling can terminate instances and delete data over time, so evidence may be lost without prompt action. But volatility is about the lifespan of the data, not about the investigator's ability to physically access the hardware, which is the key challenge of lack of physical access.
Go deeper
Related to this question
Learn chapter
Data Acquisition and Duplication Techniques
Key term
Evidence Admissibility
Evidence admissibility is the legal and technical standard that determines whether digital evidence can be used in a court of law.
Key term
Forensic Evidence Collection
Forensic evidence collection is the process of identifying, preserving, and gathering digital data from computers and devices in a way that keeps it valid for use in legal investigations or internal incident response.
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.