Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 35 pages
Exam (elaborations)

NIST SP 800-86 Framework & Investigation Process With Verified Questions,Answers And Rationales

Document preview thumbnail
Preview 4 out of 35 pages

What happens during the Examination phase according to NIST SP 800-86? **Answer:** The Examination phase involves bypassing or mitigating operating system features like compression, encryption, and access control, as well as reducing and filtering relevant data for analysis . **Rationale:** This phase transforms raw collected data into a more manageable format, removing irrelevant information while preserving potentially significant evidence .

Content preview

NIST SP 800-86 Framework & Investigation
Process With Verified Questions,Answers And
Rationales

### 1. What is NIST SP 800-86 and why is it important in digital
forensics?
**Answer:** NIST Special Publication 800-86 is the "Guide to
Integrating Forensic Techniques into Incident Response." It provides a
framework for incorporating forensic capabilities into incident
response proceedings, establishing a standardized methodology for
collecting, examining, analyzing, and reporting digital evidence .


**Rationale:** The guide is essential because it bridges the gap
between incident response and forensic investigation, ensuring
evidence is handled in a legally defensible manner while maintaining
operational continuity .


### 2. According to NIST SP 800-86, what are the four main phases of
a digital forensic investigation?
**Answer:** The four phases are: Collection, Examination, Analysis,
and Reporting .


**Rationale:** This framework establishes a systematic approach
where each phase builds upon the previous, ensuring thorough and
methodical investigation while maintaining evidence integrity
throughout the process .

,### 3. What is the primary goal of the Collection phase in NIST SP
800-86?
**Answer:** The Collection phase involves identifying potential
sources of data, proactive data collection (e.g., audits), implementing
centralized logging, and acquiring data based on likely value,
volatility, and effort required, using forensic duplication wherever
possible .


**Rationale:** This phase establishes the foundation of the
investigation by ensuring relevant evidence is properly identified and
preserved before it can be lost or altered .


### 4. What happens during the Examination phase according to
NIST SP 800-86?
**Answer:** The Examination phase involves bypassing or mitigating
operating system features like compression, encryption, and access
control, as well as reducing and filtering relevant data for analysis .


**Rationale:** This phase transforms raw collected data into a more
manageable format, removing irrelevant information while
preserving potentially significant evidence .


### 5. What is the purpose of the Analysis phase in NIST SP 800-86?
**Answer:** The Analysis phase involves studying and analyzing data
to draw conclusions, identifying people, places, items, and events,
determining relationships between identified data, and correlating
data from multiple sources .

,**Rationale:** This phase transforms examined data into actionable
intelligence that can support investigative conclusions and legal
proceedings .


### 6. What is the primary goal of the Reporting phase?
**Answer:** The Reporting phase involves preparing and presenting
information from the analysis, including alternative explanations,
identifying actionable information to collect new sources, tailoring
reports for specific audiences, and identifying procedural
shortcomings .


**Rationale:** This phase ensures investigative findings are
communicated effectively to stakeholders including legal teams,
management, and courts .


### 7. How does NIST SP 800-86 define the progression from media
to evidence?
**Answer:** The progression follows a path from media → data →
information → evidence, with each step representing increasing
contextual value and legal relevance .


**Rationale:** Understanding this progression helps investigators
distinguish between raw data and legally admissible evidence that
can support investigative conclusions .


### 8. What is the "IT view" versus the "law enforcement view" in
NIST SP 800-86?

, **Answer:** NIST SP 800-86 provides an IT view focused on incident
response and operational considerations, rather than a law
enforcement view centered on criminal prosecution .


**Rationale:** This distinction emphasizes that forensic techniques
can be applied proactively for incident response and organizational
security, not just reactive criminal investigations .


### 9. Why does NIST SP 800-86 emphasize documentation
throughout the investigation?
**Answer:** Detailed documentation of each step is required to
maintain evidence integrity, establish chain of custody, and ensure
findings are defensible in legal proceedings .


**Rationale:** Without proper documentation, evidence may be
challenged as unreliable or inadmissible in court .


### 10. How does NIST SP 800-86 address the concept of data
volatility?
**Answer:** The guide recommends prioritizing collection based on
the volatility of data sources, with more volatile data (like memory
and network connections) acquired first .


**Rationale:** Volatile data is easily lost, so collecting it first
maximizes the chance of preserving critical transient evidence .


---

Document information

Uploaded on
July 12, 2026
Number of pages
35
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$20.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
0
Followers
0
Items
118
Last sold
-


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions