ExamGecko
Question list
Search
Search

Question 595 - CISM discussion

Report
Export

To prepare for a third-party forensics investigation following an incident involving malware, the incident response team should:

A.
isolate the infected systems.
Answers
A.
isolate the infected systems.
B.
preserve the evidence.
Answers
B.
preserve the evidence.
C.
image the infected systems.
Answers
C.
image the infected systems.
D.
clean the malware.
Answers
D.
clean the malware.
Suggested answer: B

Explanation:

According to the CISM Review Manual, the incident response team should preserve the evidence as the first step to prepare for a third-party forensics investigation, as it helps to maintain the integrity and admissibility of the evidence in a court of law. Preserving the evidence may include isolating and imaging the infected systems, but these are not the only actions required. Cleaning the malware may destroy or alter the evidence and should be avoided until the investigation is completed.

Reference= CISM Review Manual, 27th Edition, Chapter 3, Section 3.6.2, page 165

asked 01/10/2024
Elefánti Gábor
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first