CHFI Application, Email and Cloud Forensics Practice Question
Which of the following is a primary challenge in cloud forensics due to the shared responsibility model?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inability to perform live acquisition of volatile data without cooperation from the cloud provider
The shared responsibility model means the cloud provider controls the infrastructure, limiting the investigator's ability to acquire volatile data without provider support.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Inability to perform live acquisition of volatile data without cooperation from the cloud provider
Why this is correct
In IaaS and PaaS cloud models, forensic investigators lack direct physical or administrative access to the hypervisor, host OS, or physical memory. Capturing volatile data such as RAM, kernel structures, and active network connections must therefore occur through the cloud provider's APIs, which often require explicit cooperation, credential delegation, or legal process. When the VM is stopped or terminated, that volatile evidence is irrevocably lost, making the inability to perform live acquisition without provider assistance a primary challenge and a critical violation of the order of volatility.
- ✗
Data is always stored in a single jurisdiction
Why it's wrong here
Cloud providers routinely replicate customer data across multiple geographic regions and availability zones to ensure durability and low-latency access. As a result, a single logical data set may physically reside in several countries, each with its own data protection and location-specific legal requirements. Jurisdiction is certainly a forensic and legal challenge because of conflicting subpoena and privacy laws, but the claim that data is always in a single jurisdiction is factually incorrect and oversimplifies the complexity.
- ✗
Lack of encryption support
Why it's wrong here
Modern cloud platforms provide robust encryption capabilities, including AES-256 for data at rest and TLS 1.2+ for data in transit, as standard offerings. The actual forensic hurdle is not a lack of encryption support but rather the investigator's inability to obtain decryption keys, which may be held only by the customer or managed inside hardware security modules that the provider controls. Encryption often complicates imaging and analysis, but it does not represent a primary challenge of cloud forensics; it is a feature, not an absence.
- ✗
Cloud logs are immutable and cannot be altered
Why it's wrong here
Cloud provider logs such as AWS CloudTrail, Azure Activity Logs, and GCP Audit Logs are not inherently immutable; they are recorded as events and stored in object storage or log streams. An attacker with elevated IAM privileges or access to the underlying account can disable logging, modify log settings, delete archived log files, or inject false entries. While some solutions offer append-only or write-once-read-many (WORM) storage for logs, this is an optional configuration and not an automatic property, so the blanket statement that cloud logs cannot be altered is false.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.