ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 35 - CS0-003 discussion

Report
Export

An incident response team found IoCs in a critical server. The team needs to isolate and collect technical evidence for further investigation. Which of the following pieces of data should be collected first in order to preserve sensitive information before isolating the server?

A.
Hard disk
Answers
A.
Hard disk
B.
Primary boot partition
Answers
B.
Primary boot partition
C.
Malicious tiles
Answers
C.
Malicious tiles
D.
Routing table
Answers
D.
Routing table
E.
Static IP address
Answers
E.
Static IP address
Suggested answer: A

Explanation:

The hard disk is the piece of data that should be collected first in order to preserve sensitive information before isolating the server. The hard disk contains all the files and data stored on the server, which may include evidence of malicious activity, such as malware installation, data exfiltration, or configuration changes. The hard disk should be collected using proper forensic techniques, such as creating an image or a copy of the disk and maintaining its integrity using hashing algorithms.

asked 02/10/2024
Melvin Bruijnaers
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first