ExamGecko
Home / Isaca / CISM / Practice Test 3
Ask Question

Isaca CISM Practice Test 3

Add to Whishlist
00:00:00
Show Answer
Report Issue   Restart test

Question 1 / 40

Which of the following is MOST important when conducting a forensic investigation?

Analyzing system memory
Analyzing system memory
Documenting analysis steps
Documenting analysis steps
Capturing full system images
Capturing full system images
Maintaining a chain of custody
Maintaining a chain of custody
Comment (0)
Suggested answer: D
Explanation:

Maintaining a chain of custody is the most important step when conducting a forensic investigation, as this ensures that the evidence is preserved, protected, and documented from the time of collection to the time of presentation in court. A chain of custody provides a record of who handled the evidence, when, where, why, and how, and prevents any tampering, alteration, or loss of the evidence. A chain of custody also establishes the authenticity, reliability, and admissibility of the evidence in legal proceedings.Analyzing system memory, documenting analysis steps, and capturing full system images are also important, but not as important as maintaining a chain of custody, as they do not guarantee the integrity and validity of the evidence.Reference= CISM Review Manual 2023, page 1701; CISM Review Questions, Answers & Explanations Manual 2023, page 332; ISACA CISM - iSecPrep, page 183

asked 01/10/2024
Archana Pingily
46 questions