hardMultiple Choice
CCSP Practice Question: A cloud security engineer is reviewing incident…
A cloud security engineer is reviewing incident response procedures for a hybrid cloud environment. During a security incident, the team needs to collect forensic evidence from a compromised virtual machine while preserving its state. Which of the following actions should be taken first?
⚠ Common exam trap
CCSP often tests the misconception that evidence collection (e.g., snapshot) should come before containment, but containment is always the first priority to stop the spread and preserve volatile data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disconnect the virtual machine from the network
Disconnecting the VM from the network is the first step to prevent further compromise, stop data exfiltration, and preserve the current state of the VM's memory and disk for forensic analysis. This isolates the VM without altering its running state, allowing later snapshot or memory capture. Notifying the provider or installing agents could tip off attackers or modify the system, and taking a snapshot first might capture a compromised state but doesn't stop ongoing malicious activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Take a snapshot of the virtual machine's disk
Why it's wrong here
A disk snapshot captures the VM's persistent storage but omits volatile memory, running processes and network state, so live artefacts are lost and the snapshot itself alters the running instance. It is tempting because snapshots are fast, non-destructive and preserve disk state, which suffices when only file-system evidence is required.
- ✗
Notify the cloud provider
Why it's wrong here
Notifying the provider does not preserve the VM's state; evidence continues changing or may be destroyed by automated remediation while awaiting a response. It is tempting because provider notification is mandatory under many incident response playbooks and shared responsibility models, but it is a parallel communication step, not the first evidence-preservation action.
- ✓
Disconnect the virtual machine from the network
Why this is correct
Disconnecting the VM from the network isolates it, preventing further attacker activity, data exfiltration or remote tampering while leaving memory and disk state intact for capture. This preserves volatile evidence before any snapshot or acquisition step alters the system.
- ✗
Install a forensic agent on the virtual machine
Why it's wrong here
Installing an agent writes to the compromised VM's disk and memory, overwriting volatile evidence and breaching forensic soundness before any capture occurs. It is tempting because agents enable live memory and process collection, which is valid only after volatile state has been preserved through an out-of-band snapshot or memory capture.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.