CCSP - Cloud Security Operations - Section 5.4

Support digital forensics.

Forensic data collection methodologies, evidence management, and collection, acquisition and preservation of digital evidence in a multi-tenant environment where physical seizure is not possible.

forensic data collectionevidence managementchain of custodyISO/IEC 27037ISO/IEC 27050

Practice question for this objective

Free sampleCloud Security Operationshard

A healthcare SaaS provider hosts patient records classified as sensitive. A hospital customer's legal team issues a preservation request for one tenant's data ahead of litigation. The provider operates a shared multi-tenant database. Which action BEST satisfies the forensic preservation obligation without breaching other tenants' data?

  • AExport a full snapshot of the shared database and hand it to the requesting customer's legal team
  • BPlace a scoped legal hold that preserves only the requesting tenant's records and associated logs in an immutable store Correct
  • CSuspend routine data-retention purges across the entire platform until the litigation concludes
  • DEncrypt the requesting tenant's records with a customer-held key so they cannot be modified
Preservation in multi-tenant cloud forensics requires a tenant-scoped, immutable legal hold that isolates relevant data without exposing other tenants. A legal hold suspends normal deletion for the specific custodian data and, when combined with immutable storage, prevents spoliation while tenant scoping keeps the collection lawful and confidential in a shared environment.

Why A is wrong: A full snapshot would preserve the data, but it commingles every tenant's records, so disclosing it breaches confidentiality obligations to the other tenants and exceeds the scope of the request.

Why B is correct: Correct: a tenant-scoped legal hold isolates the relevant custodian data, preserves it against alteration or routine deletion, and avoids exposing or collecting other tenants' records in a shared platform.

Why C is wrong: Halting all purges does prevent spoliation, but applying it platform-wide is disproportionate, inflates storage and privacy risk for unrelated tenants, and is not the scoped response the situation requires.

Why D is wrong: Encryption protects confidentiality but does not prevent deletion or overwriting, so it fails the preservation goal, which requires immutability and a hold against routine purges rather than key control.

See more CCSP practice questions, answers explained.

More in this domain

Back to all Cloud Security Operations objectives, or the CCSP cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.