• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 40 pages
Exam (elaborations)

Post-Incident Activities & Investigation – Verified Q&A Guide for Forensic Response and Legal Admissibility

Document preview thumbnail
Preview 4 out of 40 pages

This document offers a thorough collection of post-incident activity questions with accurate answers, focusing on forensic analysis, evidence preservation, legal compliance, chain of custody, and incident response review processes. Key topics include memory preservation, image creation, root cause analysis, legal standards, and best practices for conducting investigations and post-incident reviews. Suitable for advanced learners and security professionals in forensic and incident response roles.

Content preview

Post incident Activities & Investigation questions with
accurate answers
A forensic team was commissioned to perform an analysis of
unrecognized processes running on a desktop personal computer. The
lead investigator advised the team against disconnecting the power in
order to:


prevent disk corruption.


conduct a hot-swap of the main disk drive.


avoid loss of data in server logs.


avoid loss of data stored in volatile memory. Ans✓✓✓D is the correct
answer.


Justification


Preventing disk corruption does not address the capture of the data that
exist in volatile memory.


Conducting a hot-swap of the main disk drive does not address the
capture of the data that exist in volatile memory.

,Avoiding loss of data in server logs does not address the capture of the
data that exist in volatile memory.


Disconnecting power from a system results in loss of data stored in
volatile memory. Those data could be vital for the investigation and for
understanding the extent of the impact of the event. Disconnecting
power is not recommended where analysis of running processes or the
content of volatile memory is required.


A root kit was used to capture detailed accounts receivable information.
What is the next step to ensure admissibility of evidence from a legal
standpoint, once the incident has been identified and the server isolated?


Document how the attack occurred.


Notify law enforcement.


Take an image copy of the media.


Close the accounts receivable system. Ans✓✓✓C is the correct answer.


Justification


Documentation is subsequent to taking an image copy and may be
supplementary.

,Notifying law enforcement is subsequent to taking an image copy,
preserving evidence and maintaining the chain of custody.


Taking an image copy of the media along with preserving any other
evidence and maintaining the chain of custody is a recommended
practice to ensure legal admissibility.


Closing the accounts receivable system is not a practical solution.


A security operations center detected an attempted structured query
language injection, but could not determine if it was successful. Which
of the following resources should the information security manager
approach to assess the possible impact?


Application support team


Business process owner


Network management team


System administrator Ans✓✓✓A is the correct answer.


Justification

, Structured query language (SQL) injection is an application-based
attack. Since the security operations center has detected an attempt of
SQL injection and could not determine if it was successful, the
information security manager should approach the application support
group that has access to data in order to identify the impact.


The business process owner may help the application support group
determine the overall impact, once it has been determined if the attack
has been successful.


Because SQL injection is an application-based attack, the network
management team is not the best resource to assess the possible impact.


The system administrator is not the best resource to assess the possible
impact. However, he or she may assist the application support team and
assist with incident response activities, should the attack have been
successful.


A virus incident has been reported and eradicated. The information
security manager is MOST interested in knowing the:


intrusion detection system configuration.


type and payload of the virus.


virus entry path.

Document information

Uploaded on
June 26, 2025
Number of pages
40
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$19.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
cracker
3.8
(401)
Sold
2168
Followers
1346
Items
50099
Last sold
3 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions