ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 575 - 220-1102 discussion

Report
Export

A technician receives a high-priority ticket about sensitive information collected from an end user's workstation. Which of the following steps should a technician take to preserve the chain of custody for a forensic investigation?

A.
Reimage the workstation.
Answers
A.
Reimage the workstation.
B.
Inform the user of the investigation.
Answers
B.
Inform the user of the investigation.
C.
Recover and secure the workstation.
Answers
C.
Recover and secure the workstation.
D.
Back up the workstation
Answers
D.
Back up the workstation
Suggested answer: C

Explanation:

In the context of a forensic investigation, especially involving sensitive information, preserving the integrity and the chain of custody of the potential evidence is crucial. The step to 'Recover and secure the workstation' involves physically securing the workstation to prevent any unauthorized access and logically securing the data by ensuring that no changes are made to the system or files. This step helps maintain the original state of the workstation, which is essential for a legitimate forensic analysis and ensuring that the evidence is admissible in legal proceedings.

asked 02/10/2024
Kees den Dekker
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first