ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 329 - SY0-701 discussion

Report
Export

Which of the following is a reason why a forensic specialist would create a plan to preserve data after an modem and prioritize the sequence for performing forensic analysis?

A.
Order of volatility
Answers
A.
Order of volatility
B.
Preservation of event logs
Answers
B.
Preservation of event logs
C.
Chain of custody
Answers
C.
Chain of custody
D.
Compliance with legal hold
Answers
D.
Compliance with legal hold
Suggested answer: A

Explanation:

When conducting a forensic analysis after an incident, it's essential to prioritize the data collection process based on the 'order of volatility.' This principle dictates that more volatile data (e.g., data in memory, network connections) should be captured before less volatile data (e.g., disk drives, logs). The idea is to preserve the most transient and potentially valuable evidence first, as it is more likely to be lost or altered quickly.

Reference =

CompTIA Security+ SY0-701 Course Content: Domain 04 Security Operations.

CompTIA Security+ SY0-601 Study Guide: Chapter on Digital Forensics.

asked 02/10/2024
Pawel Lenart
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first