Courseiva

CCSP Cloud Security Operations Practice Question

A cloud security team is building an incident response runbook for compromised compute instances in a public cloud. They need to preserve volatile evidence and maintain chain of custody while minimizing service disruption. Which TWO actions should be included in the runbook? (Choose two.)

⚠ Common exam trap

The trap here is believing that terminating or rebooting a compromised instance is the safest first step, when doing so destroys volatile evidence and breaks chain of custody before memory and disk artifacts can be captured.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture a memory dump of the running instance before shutting it down, storing the dump in a write-once location with a documented hash.

Preserving volatile memory before any shutdown and snapshotting persistent volumes into an isolated forensic account together capture the full evidence set while maintaining integrity. Both actions record identifiers and hashes for chain of custody, and they allow the original instance to be contained or rebuilt without losing forensic artifacts, which is the core of a defensible cloud incident response runbook.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable all logging on the instance to prevent the attacker from tampering with logs, then re-enable after remediation.

    Why it's wrong here

    Disabling logging destroys the audit trail needed to understand the compromise and may violate regulatory retention requirements. Attackers could also have already altered logs, so stopping collection does not improve security. This action harms investigation and compliance rather than preserving evidence or maintaining chain of custody.

  • ✓

    Capture a memory dump of the running instance before shutting it down, storing the dump in a write-once location with a documented hash.

    Why this is correct

    Volatile evidence such as memory contents is lost on shutdown or reboot, so capturing a memory dump first preserves critical artifacts like running processes and network connections. Storing it in a write-once location and recording a cryptographic hash establishes integrity and chain of custody, which are essential for forensic validity and later legal or disciplinary use.

  • ✗

    Immediately terminate the instance to prevent further malicious activity and rely on the cloud provider's internal logs for evidence.

    Why it's wrong here

    Termination destroys volatile memory and local disk state, and provider logs do not capture in-instance artifacts such as process memory or uncommitted file writes. This approach may stop the attack but severely limits forensic reconstruction. It also undermines chain of custody because the primary evidence source is gone before it can be documented.

  • ✓

    Create a snapshot of the instance's volumes and copy it to a restricted forensic account, recording the snapshot ID and creation time.

    Why this is correct

    Snapshotting persistent volumes captures disk state for offline analysis without altering the original, and copying to a restricted forensic account isolates evidence from the compromised environment. Recording the snapshot ID and timestamp supports chain of custody. This preserves non-volatile evidence while allowing the original instance to be isolated or rebuilt.

  • ✗

    Reboot the instance into safe mode to clear malicious processes, then continue using it for production traffic.

    Why it's wrong here

    Rebooting destroys volatile memory and may trigger malware persistence mechanisms, while continuing to use the instance risks re-infection and further data loss. Safe mode is an operating system concept not guaranteed in cloud instances and does not preserve evidence. This action jeopardizes both containment and forensic integrity.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.