CISM · Question #83
To prepare for a third-party forensics investigation following an incident involving malware, the incident response team should:
The correct answer is D. preserve the evidence.. To prepare for a third-party forensics investigation, the incident response team's most crucial step is to preserve all relevant evidence from the incident.
Question
To prepare for a third-party forensics investigation following an incident involving malware, the incident response team should:
Options
- Aclean the malware.
- Bisolate the infected systems.
- Cimage the infected systems.
- Dpreserve the evidence.
How the community answered
(56 responses)- A5% (3)
- B2% (1)
- C2% (1)
- D91% (51)
Why each option
To prepare for a third-party forensics investigation, the incident response team's most crucial step is to preserve all relevant evidence from the incident.
Cleaning the malware before a forensic investigation could destroy critical evidence needed to understand the attack's scope, method, and origin.
While isolating infected systems is a critical containment step in an incident response, the primary preparation for *forensics* is evidence preservation, which often includes imaging the isolated systems.
Imaging the infected systems is a *method* of preserving evidence, but 'preserve the evidence' is the overarching objective that encompasses imaging and other actions.
Forensic investigations critically rely on the integrity and completeness of evidence. Before any other actions that might alter the state of infected systems, it is paramount to preserve all potential evidence, such as logs, memory dumps, and disk images, to ensure the third-party investigators have an accurate and untainted record of the incident for analysis.
Concept tested: Incident response - evidence preservation
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-86.pdf
Topics
Community Discussion
No community discussion yet for this question.