Cloud Forensics Flashcards
7 cards from real CHFI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cloud Forensics flashcards as text
What are the following? cloud computing services that deliver hardware, operating systems, and virtual machines. Which a service API may be used to govern.
Answer: Infrastructure-as-a-Service (IaaS)
Infrastructure-as-a-Service (IaaS) provides virtualized computing resources over the internet, including virtual machines, storage, networks, and operating systems. Users have control over the operating systems, applications, and middleware, while the cloud provider manages the underlying infrastructure. This model allows for significant flexibility and scalability, often managed through APIs for programmatic control.
Which of the following best describes the cloud deployment paradigm used for shared infrastructure between multiple enterprises with common concerns (security, compliance, jurisdiction, etc.)?
Answer: Community Cloud
A community cloud deployment model is designed for a specific community of organizations that share common concerns, such as security requirements, compliance regulations, or jurisdiction. It can be managed internally or by a third party and hosted either internally or externally. This model allows for shared infrastructure and resources while addressing the unique needs of the participating entities, offering a balance between public and private cloud benefits.
Which of the following phases does the aforementioned duties take place in when performing the many phases of cloud forensics, one of which involves resolving functional, operational, and security issues in the cloud ecosystem?
Answer: Troubleshooting
The troubleshooting phase in cloud forensics involves identifying and resolving various issues that can arise within the complex cloud ecosystem. This includes addressing functional problems, operational inefficiencies, and security vulnerabilities that might impact the integrity of data or the forensic investigation itself. It's a proactive and reactive process to ensure the cloud environment is stable and secure for forensic activities and to overcome challenges in evidence collection.
If a crime is committed in a cloud environment, identify the specific offense that was committed there.
Answer: Cloud as a subject
When a crime is committed *in* a cloud environment, meaning the cloud itself is the target or location of the criminal activity (e.g., data theft from a cloud server, unauthorized access to cloud resources), it is categorized as 'Cloud as a Subject.' This distinguishes it from using the cloud as a tool to commit a crime elsewhere or the cloud being the object of a crime (e.g., the cloud provider itself being attacked).
When a cloud acts like an object, it is committing the crime of cloud as object.
Answer: False
This statement is false. When a cloud acts as an object, it means the cloud itself is the victim of the crime, such as a denial-of-service attack against a cloud provider's infrastructure or data being stolen from cloud storage. The cloud is not 'committing' the crime; rather, it is the entity being acted upon by the criminal, suffering the impact of the malicious activity.
When a hacker utilizes one compromised cloud to attack additional accounts, they are using the cloud as a tool.
Answer: True
This statement is true. When a hacker leverages a compromised cloud environment (e.g., using a compromised virtual machine or cloud account) to launch attacks against other targets, the cloud infrastructure is serving as an instrument or means to facilitate the crime. In this scenario, the cloud is not the victim or the location of the crime, but rather the 'tool' used by the perpetrator to achieve their malicious goals.
Cloud forensics are divided into nine main groups, according to NIST.
Answer: False
This statement is false. NIST (National Institute of Standards and Technology) has published extensive guidelines and frameworks for cloud computing and forensics, but they do not categorize cloud forensics into a specific number like 'nine main groups.' NIST documents typically define cloud deployment models, service models, and outline challenges and principles for cloud forensics, rather than a fixed number of groups.