CCSP Cloud Security Operations Practice Question
A cloud security team is building an incident response runbook for compromised compute instances in a public cloud. They need to preserve volatile evidence and maintain chain of custody while minimizing service disruption. Which TWO actions should be included in the runbook? (Choose two.)
⚠ Common exam trap
The trap here is believing that terminating or rebooting a compromised instance is the safest first step, when doing so destroys volatile evidence and breaks chain of custody before memory and disk artifacts can be captured.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture a memory dump of the running instance before shutting it down, storing the dump in a write-once location with a documented hash.
Preserving volatile memory before any shutdown and snapshotting persistent volumes into an isolated forensic account together capture the full evidence set while maintaining integrity. Both actions record identifiers and hashes for chain of custody, and they allow the original instance to be contained or rebuilt without losing forensic artifacts, which is the core of a defensible cloud incident response runbook.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable all logging on the instance to prevent the attacker from tampering with logs, then re-enable after remediation.
Why it's wrong here
Disabling logging destroys the audit trail needed to understand the compromise and may violate regulatory retention requirements. Attackers could also have already altered logs, so stopping collection does not improve security. This action harms investigation and compliance rather than preserving evidence or maintaining chain of custody.
- ✓
Capture a memory dump of the running instance before shutting it down, storing the dump in a write-once location with a documented hash.
Why this is correct
Volatile evidence such as memory contents is lost on shutdown or reboot, so capturing a memory dump first preserves critical artifacts like running processes and network connections. Storing it in a write-once location and recording a cryptographic hash establishes integrity and chain of custody, which are essential for forensic validity and later legal or disciplinary use.
- ✗
Immediately terminate the instance to prevent further malicious activity and rely on the cloud provider's internal logs for evidence.
Why it's wrong here
Termination destroys volatile memory and local disk state, and provider logs do not capture in-instance artifacts such as process memory or uncommitted file writes. This approach may stop the attack but severely limits forensic reconstruction. It also undermines chain of custody because the primary evidence source is gone before it can be documented.
- ✓
Create a snapshot of the instance's volumes and copy it to a restricted forensic account, recording the snapshot ID and creation time.
Why this is correct
Snapshotting persistent volumes captures disk state for offline analysis without altering the original, and copying to a restricted forensic account isolates evidence from the compromised environment. Recording the snapshot ID and timestamp supports chain of custody. This preserves non-volatile evidence while allowing the original instance to be isolated or rebuilt.
- ✗
Reboot the instance into safe mode to clear malicious processes, then continue using it for production traffic.
Why it's wrong here
Rebooting destroys volatile memory and may trigger malware persistence mechanisms, while continuing to use the instance risks re-infection and further data loss. Safe mode is an operating system concept not guaranteed in cloud instances and does not preserve evidence. This action jeopardizes both containment and forensic integrity.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.