Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 312-49v10 All Questions

View all questions & answers for the 312-49v10 exam

Exam 312-49v10 topic 1 question 701 discussion

Actual exam question from ECCouncil's 312-49v10
Question #: 701
Topic #: 1
[All 312-49v10 Questions]

During an incident response to a data breach in a company's AWS environment, a forensic investigator is tasked to analyze and extract data from different storage types for further examination. What would be the most appropriate and effective course of action given that Amazon S3, EBS, and EFS were used?

  • A. Implement ACL permissions for S3 buckets, and attach the affected EFS to a Linux instance for data extraction
  • B. Create IAM policies to restrict access, and proceed with data extraction from EBS and EFS storage types
  • C. Extract all data directly from Amazon S3 and EBS, and attach the EFS to a Linux instance for data extraction
  • D. Snapshot the affected EBS volumes and S3 buckets, and mount EFS to a Linux instance for analysis
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
aqeel1506
4 months ago
D. Snapshot the affected EBS volumes and S3 buckets, and mount EFS to a Linux instance for analysis aligns with the practices recommended in the CHFI v10 textbook. The textbook emphasizes the importance of creating snapshots of EBS volumes for forensic analysis to preserve the state of the data. It also suggests that Amazon EFS can be mounted to a Linux instance for detailed examination. For S3 buckets, the textbook would support securing and extracting data appropriately, but the snapshotting and mounting approach ensures comprehensive coverage and maintains the integrity of the evidence.
upvoted 1 times
...
Elb
5 months, 2 weeks ago
Amazon EC2 instances use EBS volumes that act like virtual hard drives In the event of a security incident, investigators must take an offline snapshot of the EBS volume from the affected EC2 instance to acquire forensic evidence
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...