mediumMultiple ChoiceObjective-mapped
CCSP Practice Question: During a security incident involving a…
During a security incident involving a compromised virtual machine (VM) in a public cloud, the incident response team needs to preserve evidence for potential legal action. Which of the following actions should be taken FIRST?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a forensic image of the VM's volumes while it is still running
Creating a forensic image captures both volatile and persistent data while preserving the original state for evidence. Option A is incorrect because stopping the VM first may cause loss of volatile data (e.g., memory, running processes), and a snapshot after stop is less forensically sound than imaging before stop. Option B is incorrect because deleting the VM destroys all evidence immediately. Option C is incorrect because while network isolation is important for containment, it does not directly preserve the VM's state for forensic analysis; the first step should be to capture forensic evidence before any other action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stop the VM and take a snapshot of its disks
Why it's wrong here
Stopping the VM may cause loss of volatile data (e.g., memory, running processes), and a snapshot taken after stopping is less forensically sound than imaging before any changes.
- ✗
Delete the VM immediately to prevent further damage
Why it's wrong here
Deleting the VM destroys all evidence immediately.
- ✗
Isolate the VM by removing it from the network
Why it's wrong here
While network isolation is important for containment, it does not directly preserve the VM's state for forensic analysis; the first step should be to capture forensic evidence.
- ✓
Create a forensic image of the VM's volumes while it is still running
Why this is correct
Creating a forensic image while the VM is running captures both volatile and persistent data, preserving the original state for evidence.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 964-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.