nerdexam
Isaca

CISM · Question #727

Which of the following BEST enables an organization to determine what activities and changes have occurred on a system during a cybersecurity incident?

The correct answer is D. Computer forensics. Computer forensics is the discipline specifically designed to reconstruct what happened on a system - identifying which activities occurred, what was changed, and when. It involves collecting, preserving, and analyzing digital evidence in a legally sound manner. Continuous log…

Submitted by certguy· Apr 18, 2026Information Security Incident Management

Question

Which of the following BEST enables an organization to determine what activities and changes have occurred on a system during a cybersecurity incident?

Options

  • AContinuous log monitoring
  • BRoot cause analysis
  • CPenetration testing
  • DComputer forensics

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    10% (3)
  • D
    83% (25)

Explanation

Computer forensics is the discipline specifically designed to reconstruct what happened on a system - identifying which activities occurred, what was changed, and when. It involves collecting, preserving, and analyzing digital evidence in a legally sound manner. Continuous log monitoring (A) is a real-time detective control, not an investigative one. Root cause analysis (B) is a process methodology, not a technical capability for evidence collection. Penetration testing (C) is proactive and occurs before incidents. Only forensics answers the question of what actually happened during an incident.

Topics

#Digital Forensics#Incident Investigation#Incident Response#Cybersecurity Incident

Community Discussion

No community discussion yet for this question.

Full CISM Practice