CISM · Question #476
An employee who denies accusations of downloading inappropriate material to an organizational device has been discharged. In support of the disciplinary action, the collection of legal evidence is…
The correct answer is D. Create a forensic image of the original file system. The best recommendation for collecting legal evidence is to create a forensic image of the original file system, as it preserves the integrity of the data and ensures that the evidence remains admissible in legal proceedings. A forensic image is an exact copy of the system…
Question
An employee who denies accusations of downloading inappropriate material to an organizational device has been discharged. In support of the disciplinary action, the collection of legal evidence is required. Which of the following is the information security manager's BEST recommendation?
Options
- ACollect evidence from the employee endpoint security logs.
- BCollect evidence from firewall logs.
- CLog in to the employee's device and create a forensic copy to a USB drive.
- DCreate a forensic image of the original file system.
How the community answered
(41 responses)- A5% (2)
- B10% (4)
- C2% (1)
- D83% (34)
Explanation
The best recommendation for collecting legal evidence is to create a forensic image of the original file system, as it preserves the integrity of the data and ensures that the evidence remains admissible in legal proceedings. A forensic image is an exact copy of the system, including metadata and deleted files, and allows for a detailed analysis without altering the original data. While logs provide useful information, they do not offer the same level of comprehensive, legally defensible evidence as a forensic image.
Topics
Community Discussion
No community discussion yet for this question.