220-1102 · Question #59
An incident handler needs to preserve evidence for possible litigation. Which of the following will the incident handler MOST likely do to preserve the evidence?
The correct answer is B. Clone any impacted hard drives. To preserve evidence for possible litigation, an incident handler will most likely clone any impacted hard drives to create an exact forensic image.
Question
An incident handler needs to preserve evidence for possible litigation. Which of the following will the incident handler MOST likely do to preserve the evidence?
Options
- AEncrypt the files
- BClone any impacted hard drives
- CContact the cyber insurance company
- DInform law enforcement
How the community answered
(37 responses)- A5% (2)
- B84% (31)
- C3% (1)
- D8% (3)
Why each option
To preserve evidence for possible litigation, an incident handler will most likely clone any impacted hard drives to create an exact forensic image.
Encrypting the files does not preserve the original state for forensic analysis and could alter timestamps or other metadata.
Cloning impacted hard drives creates a bit-for-bit copy of the original evidence, ensuring that the original state is preserved without alteration and can be analyzed forensically. This step is critical in maintaining the integrity and admissibility of digital evidence for potential litigation.
Contacting the cyber insurance company is an administrative step related to incident response but does not directly preserve digital evidence.
Informing law enforcement is part of the reporting aspect of an incident but does not directly preserve the technical evidence itself.
Concept tested: Digital forensics evidence preservation
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-86.pdf
Topics
Community Discussion
No community discussion yet for this question.