ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 282 - SY0-601 discussion

Report
Export

Which of the following incident response phases should the proper collection of the detected 'ocs and establishment of a chain of custody be performed before?

A.
Containment
Answers
A.
Containment
B.
Identification
Answers
B.
Identification
C.
Preparation
Answers
C.
Preparation
D.
Recovery
Answers
D.
Recovery
Suggested answer: A

Explanation:

Containment is the phase where the incident response team tries to isolate and stop the spread of the incident12. Before containing the incident, the team should collect and preserve any evidence that may be useful for analysis and investigation12. This includes documenting the incident details, such as date, time, location, source, and impact12. It also includes establishing a chain of custody, which is a record of who handled the evidence, when, where, how, and why3. A chain of custody ensures the integrity and admissibility of the evidence in court or other legal proceedings3.

asked 02/10/2024
Andres Romo
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first