nerdexam
GIAC

GSEC · Question #326

What security practice is described by NIST as the application of science to the identification, collection, examination, and analysis of data while maintaining data integrity and chain of custody?

The correct answer is A. Digital forensics. NIST defines digital forensics as the scientific process of identifying, collecting, examining, and analyzing data while preserving its integrity and maintaining a strict chain of custody.

Incident Handling, Risk, and Governance

Question

What security practice is described by NIST as the application of science to the identification, collection, examination, and analysis of data while maintaining data integrity and chain of custody?

Options

  • ADigital forensics
  • BVulnerability Assessments
  • CPenetration Tests
  • DIncident Response

How the community answered

(46 responses)
  • A
    72% (33)
  • B
    4% (2)
  • C
    15% (7)
  • D
    9% (4)

Why each option

NIST defines digital forensics as the scientific process of identifying, collecting, examining, and analyzing data while preserving its integrity and maintaining a strict chain of custody.

ADigital forensicsCorrect

NIST SP 800-86 explicitly defines digital forensics as 'the application of science to the identification, collection, examination, and analysis of data while preserving the integrity of the information and maintaining a strict chain of custody.' This definition uniquely combines scientific rigor with evidentiary handling requirements that distinguish forensics from other security disciplines.

BVulnerability Assessments

Vulnerability assessments focus on identifying and quantifying security weaknesses in systems, not on scientific evidence collection with chain of custody requirements.

CPenetration Tests

Penetration testing involves authorized simulated attacks to exploit vulnerabilities, not the preservation-focused evidence gathering described in the question.

DIncident Response

Incident response is the broader organizational process of detecting and managing security incidents, whereas digital forensics is the specific scientific discipline focused on evidence integrity and legal admissibility.

Concept tested: NIST SP 800-86 digital forensics definition

Source: https://csrc.nist.gov/publications/detail/sp/800-86/final

Topics

#digital forensics#NIST#chain of custody#data integrity

Community Discussion

No community discussion yet for this question.

Full GSEC Practice