What it means
Evidence may be distributed across regions, accounts, managed services, and provider-controlled infrastructure. Acquisition methods depend on APIs, retention, permissions, and legal authority.
Why it matters
Elastic resources and short-lived credentials can disappear quickly, making prior logging and automated preservation essential.
Practical focus
- Define evidence sources and collection authority before an incident
- Preserve snapshots, logs, and configuration metadata promptly
- Record acquisition methods, time, identity, and integrity
Common mistakes
- Assuming a disk image contains the whole incident
- Collecting evidence with undocumented administrator actions
- Ignoring provider time, region, and retention differences
Certification relevance
This subject appears in or supports the following certification bodies of knowledge: