nerdexam
EC-Council

312-49V11 · Question #88

During a forensic investigation into suspicious activities within an organization's AWS environment, the investigator uses Amazon CloudWatch to adjust the storage duration of specific log data sets…

The correct answer is C. Modifies retention policies for individual log groups. Under the CHFI v11 objectives related to Cloud Forensics and AWS Forensics, log preservation is a critical requirement for effective investigation and legal admissibility. In Amazon Web Services, CloudWatch Logs retention policies allow investigators to control how long log…

Cloud Forensics

Question

During a forensic investigation into suspicious activities within an organization's AWS environment, the investigator uses Amazon CloudWatch to adjust the storage duration of specific log data sets. This action is crucial for managing the lifespan of logs and ensuring that critical logs are preserved for further analysis during the investigation. Which feature of Amazon CloudWatch is the investigator using in this scenario?

Options

  • AAnalyzes and monitors systems and applications through the log data.
  • BSearches and analyzes log data efficiently using CloudWatch Logs Insights.
  • CModifies retention policies for individual log groups.
  • DSets notification alerts for specific API activities for further investigation and troubleshooting.

How the community answered

(40 responses)
  • A
    5% (2)
  • B
    10% (4)
  • C
    83% (33)
  • D
    3% (1)

Explanation

Under the CHFI v11 objectives related to Cloud Forensics and AWS Forensics, log preservation is a critical requirement for effective investigation and legal admissibility. In Amazon Web Services, CloudWatch Logs retention policies allow investigators to control how long log data is stored before it is automatically deleted. Modifying retention policies for individual log groups ensures that relevant forensic artifacts--such as authentication logs, API activity records, and system events--remain available for analysis throughout the investigation lifecycle. In this scenario, the investigator's goal is not to analyze or query logs immediately, but to extend or manage the lifespan of log data so that it is not lost due to default retention limits. This aligns precisely with the feature that allows investigators to modify retention policies for individual log groups. CHFI v11 highlights the importance of preserving cloud-based evidence early, as cloud logs may be ephemeral and subject to automatic deletion if not properly configured.

Topics

#Amazon CloudWatch#log retention policy#cloud forensics#AWS log management

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice