ISC2 CISSP Investigations Forensics Evidence And Chain Of Custody Practice Test
7 Security Operations • 20 original questions
This CISSP practice test focuses on investigations forensics evidence and chain of custody through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
After a business change, Coho Insurance discovers that Evidence collection and handling is not handled consistently for the software delivery pipeline. The application security architect needs to address the control objective while keeping the control sustainable for normal operations. Which recommendation BEST addresses the issue? The operating team supports 22 critical systems under documented recovery and escalation procedures.
Correct answer: C
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Evidence collection and handling while keeping the control sustainable for normal operations.
Option review:
A: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address Evidence collection and handling in this scenario.
B: Controlled change reduces outages and security regressions while preserving accountability. That action can be useful in a different security decision, but it does not most directly address Evidence collection and handling in this scenario.
C: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Evidence collection and handling while keeping the control sustainable for normal operations.
D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Evidence collection and handling in this scenario.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
Correct answer: D
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Reporting and documentation while ensuring the decision can be repeated consistently across business units.
Option review:
A: Foundational operations controls reduce concentration of privilege and make accountability visible. That action can be useful in a different security decision, but it does not most directly address Reporting and documentation in this scenario.
B: Personnel safety takes precedence over property and system restoration during emergencies. That action can be useful in a different security decision, but it does not most directly address Reporting and documentation in this scenario.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Reporting and documentation in this scenario.
D: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Reporting and documentation while ensuring the decision can be repeated consistently across business units.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
During a risk workshop for the global collaboration platform, the team identifies Investigative techniques as the deciding issue. The security governance lead is expected to address the control objective while preserving clear accountability and audit evidence. What is the MOST appropriate course of action? The operating team supports 56 critical systems under documented recovery and escalation procedures.
Correct answer: A
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Investigative techniques while preserving clear accountability and audit evidence.
Option review:
A: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Investigative techniques while preserving clear accountability and audit evidence.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Investigative techniques in this scenario.
C: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. That action can be useful in a different security decision, but it does not most directly address Investigative techniques in this scenario.
D: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. That action can be useful in a different security decision, but it does not most directly address Investigative techniques in this scenario.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
A control owner at City Power proposes a quick technical fix for Digital forensics tools, tactics, and procedures in the e-commerce application. The IAM architect must address the control objective while protecting sensitive data throughout the change. What should happen FIRST? The operating team supports 73 critical systems under documented recovery and escalation procedures.
Correct answer: A
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Digital forensics tools, tactics, and procedures while protecting sensitive data throughout the change.
Option review:
A: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Digital forensics tools, tactics, and procedures while protecting sensitive data throughout the change.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Digital forensics tools, tactics, and procedures in this scenario.
C: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. That action can be useful in a different security decision, but it does not most directly address Digital forensics tools, tactics, and procedures in this scenario.
D: Foundational operations controls reduce concentration of privilege and make accountability visible. That action can be useful in a different security decision, but it does not most directly address Digital forensics tools, tactics, and procedures in this scenario.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
Tailspin Logistics is standardizing security across several business units. The clinical records environment raises a question about Data, computer, network, and mobile-device artifacts. The application security architect needs to address the control objective while preserving availability of the critical business service. Which action provides the BEST governance and security outcome? The operating team supports 90 critical systems under documented recovery and escalation procedures.
Correct answer: B
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Data, computer, network, and mobile-device artifacts while preserving availability of the critical business service.
Option review:
A: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Data, computer, network, and mobile-device artifacts in this scenario.
B: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Data, computer, network, and mobile-device artifacts while preserving availability of the critical business service.
C: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. That action can be useful in a different security decision, but it does not most directly address Data, computer, network, and mobile-device artifacts in this scenario.
D: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Data, computer, network, and mobile-device artifacts in this scenario.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
During a secure software initiative, Alpine Sports asks the incident response manager to address Evidence collection and handling for its remote access service. The requirement is to address the control objective without replacing governance with a technology-only shortcut. What should the organization do FIRST? The operating team supports 16 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Evidence collection and handling without replacing governance with a technology-only shortcut.
Option review:
A: Controlled change reduces outages and security regressions while preserving accountability. That action can be useful in a different security decision, but it does not most directly address Evidence collection and handling in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Evidence collection and handling in this scenario.
C: Risk-based vulnerability management is more effective than patching purely by severity score or release date. That action can be useful in a different security decision, but it does not most directly address Evidence collection and handling in this scenario.
D: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Evidence collection and handling without replacing governance with a technology-only shortcut.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
Fabrikam Manufacturing is revising controls for its customer identity platform. A review highlights Reporting and documentation. The security governance lead must address the control objective while keeping the process defensible to auditors and business owners. Which action is the BEST next step? The operating team supports 33 critical systems under documented recovery and escalation procedures.
Correct answer: B
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Reporting and documentation while keeping the process defensible to auditors and business owners.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Reporting and documentation in this scenario.
B: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Reporting and documentation while keeping the process defensible to auditors and business owners.
C: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. That action can be useful in a different security decision, but it does not most directly address Reporting and documentation in this scenario.
D: Foundational operations controls reduce concentration of privilege and make accountability visible. That action can be useful in a different security decision, but it does not most directly address Reporting and documentation in this scenario.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
An auditor asks Trey Research to demonstrate how it handles Investigative techniques in the data analytics lake. The IAM architect must address the control objective while minimizing irreversible action until facts and authority are established. Which response is MOST appropriate? The operating team supports 50 critical systems under documented recovery and escalation procedures.
Correct answer: B
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Investigative techniques while minimizing irreversible action until facts and authority are established.
Option review:
A: Baselines and drift control make systems predictable, auditable, and recoverable. That action can be useful in a different security decision, but it does not most directly address Investigative techniques in this scenario.
B: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Investigative techniques while minimizing irreversible action until facts and authority are established.
C: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Investigative techniques in this scenario.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Investigative techniques in this scenario.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
After a business change, Margie Travel discovers that Digital forensics tools, tactics, and procedures is not handled consistently for the branch-office network. The application security architect needs to address the control objective while preserving evidence needed for later review. Which recommendation BEST addresses the issue? The operating team supports 67 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Digital forensics tools, tactics, and procedures while preserving evidence needed for later review.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Digital forensics tools, tactics, and procedures in this scenario.
B: Resource protection must follow data and media across storage, movement, reuse, and disposal. That action can be useful in a different security decision, but it does not most directly address Digital forensics tools, tactics, and procedures in this scenario.
C: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. That action can be useful in a different security decision, but it does not most directly address Digital forensics tools, tactics, and procedures in this scenario.
D: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Digital forensics tools, tactics, and procedures while preserving evidence needed for later review.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
Wide World Importers is preparing a security decision for the industrial control network. The decision involves Data, computer, network, and mobile-device artifacts. The incident response manager must address the control objective without granting broader privilege than the business need requires. Which option BEST reflects CISSP-level security practice? The operating team supports 84 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Data, computer, network, and mobile-device artifacts without granting broader privilege than the business need requires.
Option review:
A: Resource protection must follow data and media across storage, movement, reuse, and disposal. That action can be useful in a different security decision, but it does not most directly address Data, computer, network, and mobile-device artifacts in this scenario.
B: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Data, computer, network, and mobile-device artifacts in this scenario.
C: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. That action can be useful in a different security decision, but it does not most directly address Data, computer, network, and mobile-device artifacts in this scenario.
D: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Data, computer, network, and mobile-device artifacts without granting broader privilege than the business need requires.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
During a risk workshop for the research data repository, the team identifies Evidence collection and handling as the deciding issue. The security governance lead is expected to address the control objective without creating a new single point of failure. What is the MOST appropriate course of action? The operating team supports 10 critical systems under documented recovery and escalation procedures.
Correct answer: C
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Evidence collection and handling without creating a new single point of failure.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Evidence collection and handling in this scenario.
B: Controlled change reduces outages and security regressions while preserving accountability. That action can be useful in a different security decision, but it does not most directly address Evidence collection and handling in this scenario.
C: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Evidence collection and handling without creating a new single point of failure.
D: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. That action can be useful in a different security decision, but it does not most directly address Evidence collection and handling in this scenario.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
A control owner at Litware Services proposes a quick technical fix for Reporting and documentation in the payment processing service. The IAM architect must address the control objective while ensuring that emergency access cannot become permanent access. What should happen FIRST? The operating team supports 27 critical systems under documented recovery and escalation procedures.
Correct answer: C
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Reporting and documentation while ensuring that emergency access cannot become permanent access.
Option review:
A: Baselines and drift control make systems predictable, auditable, and recoverable. That action can be useful in a different security decision, but it does not most directly address Reporting and documentation in this scenario.
B: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. That action can be useful in a different security decision, but it does not most directly address Reporting and documentation in this scenario.
C: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Reporting and documentation while ensuring that emergency access cannot become permanent access.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Reporting and documentation in this scenario.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
Humongous Insurance is standardizing security across several business units. The software delivery pipeline raises a question about Investigative techniques. The application security architect needs to address the control objective while allowing independent verification of the control outcome. Which action provides the BEST governance and security outcome? The operating team supports 44 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Investigative techniques while allowing independent verification of the control outcome.
Option review:
A: Resource protection must follow data and media across storage, movement, reuse, and disposal. That action can be useful in a different security decision, but it does not most directly address Investigative techniques in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Investigative techniques in this scenario.
C: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Investigative techniques in this scenario.
D: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Investigative techniques while allowing independent verification of the control outcome.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
During a third-party onboarding review, Woodgrove Bank asks the incident response manager to address Digital forensics tools, tactics, and procedures for its AI-assisted customer service platform. The requirement is to address the control objective while accounting for third-party and lifecycle dependencies. What should the organization do FIRST? The operating team supports 61 critical systems under documented recovery and escalation procedures.
Correct answer: A
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Digital forensics tools, tactics, and procedures while accounting for third-party and lifecycle dependencies.
Option review:
A: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Digital forensics tools, tactics, and procedures while accounting for third-party and lifecycle dependencies.
B: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Digital forensics tools, tactics, and procedures in this scenario.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Digital forensics tools, tactics, and procedures in this scenario.
D: Risk-based vulnerability management is more effective than patching purely by severity score or release date. That action can be useful in a different security decision, but it does not most directly address Digital forensics tools, tactics, and procedures in this scenario.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
Relecloud Systems is revising controls for its global collaboration platform. A review highlights Data, computer, network, and mobile-device artifacts. The security governance lead must address the control objective while maintaining the organization’s stated risk appetite. Which action is the BEST next step? The operating team supports 78 critical systems under documented recovery and escalation procedures.
Correct answer: A
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Data, computer, network, and mobile-device artifacts while maintaining the organization’s stated risk appetite.
Option review:
A: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Data, computer, network, and mobile-device artifacts while maintaining the organization’s stated risk appetite.
B: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address Data, computer, network, and mobile-device artifacts in this scenario.
C: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. That action can be useful in a different security decision, but it does not most directly address Data, computer, network, and mobile-device artifacts in this scenario.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Data, computer, network, and mobile-device artifacts in this scenario.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
An auditor asks Contoso Financial to demonstrate how it handles Evidence collection and handling in the e-commerce application. The IAM architect must address the control objective while meeting the business objective with the least unnecessary operational complexity. Which response is MOST appropriate? The operating team supports 4 critical systems under documented recovery and escalation procedures.
Correct answer: B
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Evidence collection and handling while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: Resource protection must follow data and media across storage, movement, reuse, and disposal. That action can be useful in a different security decision, but it does not most directly address Evidence collection and handling in this scenario.
B: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Evidence collection and handling while meeting the business objective with the least unnecessary operational complexity.
C: Foundational operations controls reduce concentration of privilege and make accountability visible. That action can be useful in a different security decision, but it does not most directly address Evidence collection and handling in this scenario.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Evidence collection and handling in this scenario.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
After a business change, Lucerne Publishing discovers that Reporting and documentation is not handled consistently for the clinical records environment. The application security architect needs to address the control objective while keeping the control sustainable for normal operations. Which recommendation BEST addresses the issue? The operating team supports 21 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Reporting and documentation while keeping the control sustainable for normal operations.
Option review:
A: Personnel safety takes precedence over property and system restoration during emergencies. That action can be useful in a different security decision, but it does not most directly address Reporting and documentation in this scenario.
B: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. That action can be useful in a different security decision, but it does not most directly address Reporting and documentation in this scenario.
C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Reporting and documentation in this scenario.
D: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Reporting and documentation while keeping the control sustainable for normal operations.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
Lamna Healthcare is preparing a security decision for the remote access service. The decision involves Investigative techniques. The incident response manager must address the control objective while ensuring the decision can be repeated consistently across business units. Which option BEST reflects CISSP-level security practice? The operating team supports 38 critical systems under documented recovery and escalation procedures.
Correct answer: A
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Investigative techniques while ensuring the decision can be repeated consistently across business units.
Option review:
A: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Investigative techniques while ensuring the decision can be repeated consistently across business units.
B: Foundational operations controls reduce concentration of privilege and make accountability visible. That action can be useful in a different security decision, but it does not most directly address Investigative techniques in this scenario.
C: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. That action can be useful in a different security decision, but it does not most directly address Investigative techniques in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Investigative techniques in this scenario.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
During a risk workshop for the customer identity platform, the team identifies Digital forensics tools, tactics, and procedures as the deciding issue. The security governance lead is expected to address the control objective while preserving clear accountability and audit evidence. What is the MOST appropriate course of action? The operating team supports 55 critical systems under documented recovery and escalation procedures.
Correct answer: B
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Digital forensics tools, tactics, and procedures while preserving clear accountability and audit evidence.
Option review:
A: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Digital forensics tools, tactics, and procedures in this scenario.
B: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Digital forensics tools, tactics, and procedures while preserving clear accountability and audit evidence.
C: Foundational operations controls reduce concentration of privilege and make accountability visible. That action can be useful in a different security decision, but it does not most directly address Digital forensics tools, tactics, and procedures in this scenario.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Digital forensics tools, tactics, and procedures in this scenario.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
A control owner at Consolidated Messenger proposes a quick technical fix for Data, computer, network, and mobile-device artifacts in the data analytics lake. The IAM architect must address the control objective while protecting sensitive data throughout the change. What should happen FIRST? The operating team supports 72 critical systems under documented recovery and escalation procedures.
Correct answer: C
Why: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Data, computer, network, and mobile-device artifacts while protecting sensitive data throughout the change.
Option review:
A: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address Data, computer, network, and mobile-device artifacts in this scenario.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Data, computer, network, and mobile-device artifacts in this scenario.
C: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. It directly addresses Data, computer, network, and mobile-device artifacts while protecting sensitive data throughout the change.
D: Personnel safety takes precedence over property and system restoration during emergencies. That action can be useful in a different security decision, but it does not most directly address Data, computer, network, and mobile-device artifacts in this scenario.
Learning point: Preserve evidence integrity and chain of custody, collect volatile evidence in an appropriate order, document every action, and stay within investigative authority. Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority.
Popular posts
Recent Posts
