โ† All CCSK Flashcard Decks

Incident Response and Business Continuity in Cloud Flashcards

6 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Incident Response and Business Continuity in Cloud flashcards as text
  1. What is the primary challenge of cloud incident response compared to on-premises incident response?

    Answer: Limited physical access and reliance on provider-supplied logs reduce investigative control

    In cloud environments, customers cannot access physical media and depend on provider-provided logs and APIs for forensic investigation, limiting their control.

  2. According to CCSK, what should be included in a cloud-specific incident response plan?

    Answer: Defined roles, escalation procedures, provider notification requirements, evidence preservation methods, and cloud-specific playbooks

    A cloud IR plan must address cloud-specific factors like evidence collection from provider APIs, provider notification protocols, and isolation procedures for cloud workloads.

  3. What is 'evidence preservation' in cloud incident response and why is it challenging?

    Answer: Capturing forensic artifacts (logs, snapshots, memory) before they are overwritten or auto-deleted in dynamic cloud environments

    Cloud environments auto-delete logs, terminate instances, and scale dynamically, requiring rapid evidence capture before artifacts disappear.

  4. What does CCSK recommend for 'containment' of a compromised cloud workload?

    Answer: Isolate the workload by modifying security groups and network ACLs while preserving forensic state

    Containment in cloud involves isolating the workload through network controls while preserving its state for forensic investigation before remediation.

  5. According to CCSK, what is the role of a 'runbook' in cloud incident response?

    Answer: A documented, step-by-step procedure for responding to specific types of security incidents in cloud environments

    Runbooks provide pre-defined, tested procedures for common incident types, enabling faster and more consistent response without ad hoc decision-making under pressure.

  6. What is 'cloud forensics' and what unique challenges does the cloud environment present?

    Answer: Digital forensic investigation in cloud environments, challenged by multi-tenancy, ephemeral resources, and limited physical access

    Cloud forensics faces unique challenges including inability to access physical media, evidence volatility in ephemeral environments, and jurisdictional issues with multi-tenant data.