nerdexam
EC-Council

212-89 · Question #148

Organizations or incident response teams need to protect the evidence for any future legal actions that may be taken against perpetrators that intentionally attacked the computer system. EVIDENCE PROT

Sign in or unlock 212-89 to reveal the answer and full explanation for question #148. The question stem and answer options stay visible for context.

Computer Forensics in Incident Handling

Question

Organizations or incident response teams need to protect the evidence for any future legal actions that may be taken against perpetrators that intentionally attacked the computer system. EVIDENCE PROTECTION is also required to meet legal compliance issues. Which of the following documents helps in protecting evidence from physical or logical damage?

Options

  • AChain-of-Precedence
  • BChain-of-Custody
  • CNetwork and host log records
  • DForensic analysis report

Unlock 212-89 to see the answer

You've previewed enough free 212-89 questions. Unlock 212-89 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Chain-of-Custody#Evidence Protection#Evidence Integrity#Legal Compliance
Full 212-89 Practice