EC-Council
212-89 · Question #148
212-89 Question #148: Real Exam Question with Answer & Explanation
The correct answer is B. Chain-of-Custody. See the full explanation below for the reasoning.
Question
Organizations or incident response teams need to protect the evidence for any future legal actions that may be taken against perpetrators that intentionally attacked the computer system. EVIDENCE PROTECTION is also required to meet legal compliance issues. Which of the following documents helps in protecting evidence from physical or logical damage?
Options
- AChain-of-Precedence
- BChain-of-Custody
- CNetwork and host log records
- DForensic analysis report
Community Discussion
No community discussion yet for this question.