ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 583 - SY0-601 discussion

Report
Export

Which of the following is a reason why a forensic specialist would create a plan to preserve data after an incident and prioritize the sequence for performing forensic analysis?

A.
Order of volatility
Answers
A.
Order of volatility
B.
Preservation of event logs
Answers
B.
Preservation of event logs
C.
Chain of custody
Answers
C.
Chain of custody
D.
Compliance with legal hold
Answers
D.
Compliance with legal hold
Suggested answer: A

Explanation:

Order of volatility is the order in which a forensic specialist should collect evidence based on how quickly the data can be lost or altered. The most volatile data, such as CPU registers and cache, should be collected first, followed by less volatile data, such as disk drives and archival media. Order of volatility helps preserve the integrity and validity of the evidence and prevent data loss or corruption123 Reference: CompTIA Security+ SY0-601 Certification Study Guide, Chapter 11: Explaining Digital Forensics Concepts, page 494; Order of Volatility - Computer Forensics Recruiter; Order of Volatility – CompTIA Security+ SY0-401: 2.4; CFR and Order of Volatility - Get Certified Get Ahead

asked 02/10/2024
Camrin Schroyer
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first