CAS-003 · Question #508
A laptop is recovered a few days after it was stolen. Which of the following should be verified during incident response activities to determine the possible impact of the incident?
The correct answer is A. Full disk encryption status. If the organization have their laptops fully encrypted (FDE), the only thing to be verified is wether the disk is still encrypted and his integrity is preserved (assuming the key used was not leaked). This would also guarantee that the OS is preserved, since an attacker could…
Question
A laptop is recovered a few days after it was stolen. Which of the following should be verified during incident response activities to determine the possible impact of the incident?
Options
- AFull disk encryption status
- BTPM PCR values
- CFile system integrity
- DPresence of UEFI vulnerabilities
How the community answered
(21 responses)- A90% (19)
- B5% (1)
- D5% (1)
Explanation
If the organization have their laptops fully encrypted (FDE), the only thing to be verified is wether the disk is still encrypted and his integrity is preserved (assuming the key used was not leaked). This would also guarantee that the OS is preserved, since an attacker could not access OS and The problem is that the question does not inform if the laptop was fully encrypted or not.
Topics
Community Discussion
No community discussion yet for this question.