ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 138 - CS0-003 discussion

Report
Export

Which of the following is a reason why proper handling and reporting of existing evidence are important for the investigation and reporting phases of an incident response?

A.
TO ensure the report is legally acceptable in case it needs to be presented in court
Answers
A.
TO ensure the report is legally acceptable in case it needs to be presented in court
B.
To present a lessons-learned analysis for the incident response team
Answers
B.
To present a lessons-learned analysis for the incident response team
C.
To ensure the evidence can be used in a postmortem analysis
Answers
C.
To ensure the evidence can be used in a postmortem analysis
D.
To prevent the possible loss of a data source for further root cause analysis
Answers
D.
To prevent the possible loss of a data source for further root cause analysis
Suggested answer: A

Explanation:

The correct answer is A. To ensure the report is legally acceptable in case it needs to be presented in court.

Proper handling and reporting of existing evidence are important for the investigation and reporting phases of an incident response because they ensure the integrity, authenticity, and admissibility of the evidence in case it needs to be presented in court. Evidence that is mishandled, tampered with, or poorly documented may not be accepted by the court or may be challenged by the opposing party. Therefore, incident responders should follow the best practices and standards for evidence collection, preservation, analysis, and reporting1.

The other options are not reasons why proper handling and reporting of existing evidence are important for the investigation and reporting phases of an incident response. They are rather outcomes or benefits of conducting a thorough and effective incident response process. A lessonslearned analysis (B) is a way to identify the strengths and weaknesses of the incident response team and improve their performance for future incidents. A postmortem analysis © is a way to determine the root cause, impact, and timeline of the incident and provide recommendations for remediation and prevention. A root cause analysis (D) is a way to identify the underlying factors that led to the

incident and address them accordingly.

asked 02/10/2024
MD NAZRI BEZAMAN
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first