nerdexam
CompTIA

CAS-003 · Question #508

A laptop is recovered a few days after it was stolen. Which of the following should be verified during incident response activities to determine the possible impact of the incident?

The correct answer is A. Full disk encryption status. If the organization have their laptops fully encrypted (FDE), the only thing to be verified is wether the disk is still encrypted and his integrity is preserved (assuming the key used was not leaked). This would also guarantee that the OS is preserved, since an attacker could…

Enterprise Security Operations

Question

A laptop is recovered a few days after it was stolen. Which of the following should be verified during incident response activities to determine the possible impact of the incident?

Options

  • AFull disk encryption status
  • BTPM PCR values
  • CFile system integrity
  • DPresence of UEFI vulnerabilities

How the community answered

(21 responses)
  • A
    90% (19)
  • B
    5% (1)
  • D
    5% (1)

Explanation

If the organization have their laptops fully encrypted (FDE), the only thing to be verified is wether the disk is still encrypted and his integrity is preserved (assuming the key used was not leaked). This would also guarantee that the OS is preserved, since an attacker could not access OS and The problem is that the question does not inform if the laptop was fully encrypted or not.

Topics

#FDE#incident response#data breach assessment#laptop theft

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice