Question 1 of 30
In a cloud forensics investigation, a security analyst is tasked with determining the timeline of events leading up to a data breach in a multi-tenant cloud environment. The analyst has access to various logs, including API access logs, virtual machine (VM) logs, and network traffic logs. Given that the breach occurred on March 15, 2023, and the analyst has identified suspicious API calls made on March 10, 2023, how should the analyst prioritize the investigation of the logs to establish a comprehensive timeline of the breach?
Start with the API access logs to identify the source of the suspicious calls and correlate them with VM logs for any unauthorized access.
Focus solely on the network traffic logs to determine if there were any unusual patterns leading up to the breach.
Analyze the VM logs first to check for any changes made to the virtual machines before examining the API access logs.
Review the cloud provider's security alerts to see if any were triggered around the time of the breach without further log analysis.

Preparing for CISCO 300-215 Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free