(ISC)2(ISC)2
SSCP · Question #1202
SSCP Question #1202: Real Exam Question with Answer & Explanation
Sign in or unlock SSCP to reveal the answer and full explanation for question #1202. The question stem and answer options stay visible for context.
Submitted by carlos_mx· Apr 18, 2026Incident Response and Recovery
Question
When gathering digital evidence it is very important to do the following: (Choose all that apply)
Options
- AShut down the compromised system to avoid further attacks
- BReboot the victim system offline
- CDocument the chain of evidence by taking good notes
- DPerform a bit-level back up of the data before analysis
Unlock SSCP to see the answer
You've previewed enough free SSCP questions. Unlock SSCP for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Digital forensics#Evidence collection#Chain of custody#Forensic imaging