CISM · Question #727
Which of the following BEST enables an organization to determine what activities and changes have occurred on a system during a cybersecurity incident?
The correct answer is D. Computer forensics. Computer forensics is the discipline specifically designed to reconstruct what happened on a system - identifying which activities occurred, what was changed, and when. It involves collecting, preserving, and analyzing digital evidence in a legally sound manner. Continuous log…
Question
Which of the following BEST enables an organization to determine what activities and changes have occurred on a system during a cybersecurity incident?
Options
- AContinuous log monitoring
- BRoot cause analysis
- CPenetration testing
- DComputer forensics
How the community answered
(30 responses)- A3% (1)
- B3% (1)
- C10% (3)
- D83% (25)
Explanation
Computer forensics is the discipline specifically designed to reconstruct what happened on a system - identifying which activities occurred, what was changed, and when. It involves collecting, preserving, and analyzing digital evidence in a legally sound manner. Continuous log monitoring (A) is a real-time detective control, not an investigative one. Root cause analysis (B) is a process methodology, not a technical capability for evidence collection. Penetration testing (C) is proactive and occurs before incidents. Only forensics answers the question of what actually happened during an incident.
Topics
Community Discussion
No community discussion yet for this question.