ExamGecko
Question list
Search
Search

Question 81 - CISM discussion

Report
Export

Which of the following is MOST important when conducting a forensic investigation?

A.
Analyzing system memory
Answers
A.
Analyzing system memory
B.
Documenting analysis steps
Answers
B.
Documenting analysis steps
C.
Capturing full system images
Answers
C.
Capturing full system images
D.
Maintaining a chain of custody
Answers
D.
Maintaining a chain of custody
Suggested answer: D

Explanation:

Maintaining a chain of custody is the most important step when conducting a forensic investigation, as this ensures that the evidence is preserved, protected, and documented from the time of collection to the time of presentation in court. A chain of custody provides a record of who handled the evidence, when, where, why, and how, and prevents any tampering, alteration, or loss of the evidence. A chain of custody also establishes the authenticity, reliability, and admissibility of the evidence in legal proceedings.Analyzing system memory, documenting analysis steps, and capturing full system images are also important, but not as important as maintaining a chain of custody, as they do not guarantee the integrity and validity of the evidence.Reference= CISM Review Manual 2023, page 1701; CISM Review Questions, Answers & Explanations Manual 2023, page 332; ISACA CISM - iSecPrep, page 183

asked 01/10/2024
Archana Pingily
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first