certslothcertsloth
CCSP/Topic 13

ISC2 / Professional

Cloud Operations, Forensics and Service Management

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Preserve evidence before an ephemeral system disappears.

Must remember

Cloud resources can be short-lived while their effects persist. Centralize appropriate control-plane, data-access, identity and workload logs before an incident. Record tenant/account, actor, action, resource, time and result. Protect logs from the identity being investigated and define retention/cost controls deliberately.

Forensics may depend on provider APIs, snapshots and contractual assistance rather than physical disk seizure. Establish collection rights, available timestamps, chain of custody and isolation procedures in advance. A snapshot can be crash-consistent rather than application-consistent; preserve enough context to interpret it. Do not assume a provider exposes hypervisor or another tenant's evidence.

Operational controls cover configuration baselines, patches, vulnerability assessment, administrative access, capacity, availability and backup/restoration. Monitor the host and guest responsibilities that actually belong to your service model. Quotas, regional capacity and identity dependencies can cause outages even when CPU metrics look healthy.

Distinguish service-management activities: incident management restores service, problem management seeks underlying causes, change management controls modifications, release management organizes deliverable versions and deployment installs them. Configuration management tracks relevant items and relationships; service-level management reviews commitments and evidence.

Use tested maintenance/rollback procedures and communicate with customers, providers, partners and regulators through assigned owners. A security operations center needs clear escalation, intelligence, response authority and continuous tuning. Outsourced monitoring does not remove the need for an internal decision maker.

Exercise a compromised cloud administrator, a deleted data store and an inaccessible region. Confirm that clean identities, keys, logs and recovery copies remain available outside the failed trust boundary.

Choose under exam pressure

Requirement Choice and reason
Short-lived compromised workload Preserve available logs, metadata and permitted snapshots promptly.
Recurring outage after repeated restores Problem/root-cause management, not only incident closure.
Provider-controlled evidence required Use pre-agreed assistance and legal/contractual channels.

Traps

  • A VM snapshot is not automatically a forensic image of every relevant system layer.
  • Availability monitoring alone will not detect excessive permissions.

Active recall

1. Incident versus problem management?

Incident management restores service; problem management addresses underlying causes.

2. Why prearrange provider forensic assistance?

Evidence access, timing and responsibilities differ from on-premises ownership.

3. What context makes a cloud log useful?

Reliable actor, action, resource, tenant, timestamp and outcome information.

4. Why isolate backup permissions from production administrators?

A compromised production identity should not be able to destroy all recovery paths.

5. Can you assume access to hypervisor evidence?

No. Provider responsibilities, multitenancy and contract terms constrain access.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.