nerdexam
Isaca

CISM · Question #476

An employee who denies accusations of downloading inappropriate material to an organizational device has been discharged. In support of the disciplinary action, the collection of legal evidence is…

The correct answer is D. Create a forensic image of the original file system. The best recommendation for collecting legal evidence is to create a forensic image of the original file system, as it preserves the integrity of the data and ensures that the evidence remains admissible in legal proceedings. A forensic image is an exact copy of the system…

Submitted by klara.se· Apr 18, 2026Information Security Incident Management

Question

An employee who denies accusations of downloading inappropriate material to an organizational device has been discharged. In support of the disciplinary action, the collection of legal evidence is required. Which of the following is the information security manager's BEST recommendation?

Options

  • ACollect evidence from the employee endpoint security logs.
  • BCollect evidence from firewall logs.
  • CLog in to the employee's device and create a forensic copy to a USB drive.
  • DCreate a forensic image of the original file system.

How the community answered

(41 responses)
  • A
    5% (2)
  • B
    10% (4)
  • C
    2% (1)
  • D
    83% (34)

Explanation

The best recommendation for collecting legal evidence is to create a forensic image of the original file system, as it preserves the integrity of the data and ensures that the evidence remains admissible in legal proceedings. A forensic image is an exact copy of the system, including metadata and deleted files, and allows for a detailed analysis without altering the original data. While logs provide useful information, they do not offer the same level of comprehensive, legally defensible evidence as a forensic image.

Topics

#Digital Forensics#Evidence Collection#Incident Response#Legal Compliance

Community Discussion

No community discussion yet for this question.

Full CISM Practice