ETExamTower
Q13Forensics Processes

DRAG DROP - Drag and drop the cloud characteristic from the left onto the challenges presented for gathering evidence on the right. Select and Place: <DragDrop items={["broad network access","rapid Elasticity","measured service","resource pooling"]} slots={[{"answer":"measured service","id":"slot1","label":"application details are unavailable to investigators since being deemed private and confidential"},{"answer":"broad network access","id":"slot2","label":"obtaining evidence from the cloud service provider"},{"answer":"resource pooling","id":"slot3","label":"circumvention of virtual machine isolation techniques via code or bad actor"},{"answer":"rapid Elasticity","id":"slot4","label":"evidence correlation across one or more cloud providers"}]} explanation={"Measured service can limit investigators’ access to private cloud application implementation details. Resource pooling creates multi-tenant virtualized environments, so a VM-isolation escape can affect the hypervisor or other guest VMs. Rapid elasticity and distributed provider use make cross-provider artifact correlation difficult. Broad network access makes evidence acquisition dependent on remotely accessible provider-controlled systems.\n\n**Learn more:** [NISTIR 8006: NIST Cloud Computing Forensic Science Challenges](https://doi.org/10.6028/NIST.IR.8006)"} reuse={false} />

Question exhibit
← → navigate · a answer
Discussion · 0
No comments yet. Be the first.