Courseiva

CHFI Application, Email and Cloud Forensics Practice Question

Which of the following is a primary challenge in cloud forensics due to shared infrastructure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multi-tenancy and data comingling

Multi-tenancy means multiple customers share the same physical resources. This complicates evidence isolation and can lead to data comingling, making forensic acquisition difficult.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Slow internet speeds

    Why it's wrong here

    Slow internet speeds are a performance metric, not a forensic impediment. Cloud forensic acquisitions depend on API-based access and logical disk snapshots, where bandwidth affects the time to transfer evidence but does not compromise the integrity, admissibility, or legal validity of the data. Even with dial-up speeds, an investigator can still obtain a forensically sound copy, provided the provider's acquisition mechanism is reliable. Thus, this is a minor logistical annoyance, not a primary challenge of cloud forensics.

  • ✓

    Multi-tenancy and data comingling

    Why this is correct

    Multi-tenancy and data comingling are a primary challenge because cloud infrastructure pools resources across many customers on shared physical hardware. When an investigator acquires a forensic image from a virtual disk or memory, the underlying storage may contain remnants or interleaved blocks from other tenants, making it difficult to isolate the target's data without cross-contamination. This threatens chain of custody, requires careful logical isolation verification, and raises significant privacy and legal issues because collecting other tenants' data may violate statutes or service agreements. The shared responsibility model complicates attribution further, as the investigator must prove that the evidence belongs solely to the suspected tenant.

  • ✗

    Lack of logging capabilities

    Why it's wrong here

    The claim that cloud providers lack logging capabilities is false—providers offer comprehensive logging services such as AWS CloudTrail, Azure Activity Logs, and Google Cloud Audit Logs that record API calls, administrative actions, and security events. The actual forensic challenge is managing the enormous volume of logs, their retention periods, and verifying their integrity when the provider controls the logging infrastructure. Logs can be tampered with or disabled without proper access controls, but they absolutely exist and are a crucial evidence source. Therefore, lack is not the issue; trust and configurability are.

  • ✗

    Inability to perform network analysis

    Why it's wrong here

    Network analysis is indeed possible in cloud environments through tools like VPC Flow Logs (which capture IP traffic metadata), AWS Traffic Mirroring, vTap, and hypervisor-level monitoring. Investigators can install packet capture utilities inside virtual machines and inspect network traffic just as on on-premises systems, limited only by the visibility into the physical network fabric. The distinction is that logical network boundaries and virtual switches may obscure some traffic, but the ability to perform network forensics remains intact. Thus, 'inability' is an incorrect statement—the limitations are about scope and access, not feasibility.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.