CompTIA Security+ SY0-701 Incident Response Practice Test

 

Topic 21 focuses on Incident Response for the CompTIA Security+ certification and the SY0-701 exam, using practical cybersecurity scenarios aligned to the published Security+ objectives. For broader exam preparation, review the CompTIA Security+ SY0-701 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

What is the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs?

  1. Preparation
  2. Eradication
  3. Simulation exercise
  4. Legal hold

Correct Answer: A

 

Correct Answer

Answer A is correct because Preparation means the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.

Incorrect Answers

Answer B is incorrect because Eradication would fit a different scenario. Eradication refers to removal of malware, attacker persistence, compromised accounts, or root causes from the environment.

Answer C is incorrect because Simulation exercise represents a different security function. Simulation exercise refers to practice activity that imitates a more realistic incident and response environment.

Answer D is incorrect because Legal hold addresses a different requirement. Legal hold refers to instruction to preserve relevant information because of litigation, investigation, or legal obligation.

 

Question 2

To identify candidate incidents from alerts, observations, or reports, which security approach should be selected?

  1. Forensic acquisition
  2. Threat hunting
  3. Recovery
  4. Detection

Correct Answer: D

 

Correct Answer

Answer D is correct because Detection means recognition that a potentially security-relevant event has occurred.

Incorrect Answers

Answer A is incorrect because Forensic acquisition addresses a different requirement. Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data.

Answer B is incorrect because Threat hunting would fit a different scenario. Threat hunting refers to proactive search for signs of attackers or compromise not already identified by routine detections.

Answer C is incorrect because Recovery addresses a different security requirement. Recovery refers to restoration of systems and business services to normal operation with appropriate validation and monitoring.

 

Question 3

Which term describes investigation of evidence to determine scope, cause, severity, and likely impact?

  1. Tabletop exercise
  2. Forensic acquisition
  3. Analysis
  4. Lessons learned

Correct Answer: C

 

Correct Answer

Answer C is correct because Analysis means investigation of evidence to determine scope, cause, severity, and likely impact.

Incorrect Answers

Answer A is incorrect because Tabletop exercise addresses a different requirement. Tabletop exercise refers to discussion-based walkthrough of an incident scenario.

Answer B is incorrect because Forensic acquisition would fit a different scenario. Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data.

Answer D is incorrect because Lessons learned represents a different security function. Lessons learned refers to post-incident review of what happened, what worked, what failed, and what should change.

 

Question 4

To isolate affected systems or accounts before the situation worsens, which security approach should be selected?

  1. Containment
  2. E-discovery
  3. Digital forensics
  4. Eradication

Correct Answer: A

 

Correct Answer

Answer A is correct because Containment means actions that limit spread or ongoing damage while preserving the ability to investigate.

Incorrect Answers

Answer B is incorrect because E-discovery would fit a different scenario. E-discovery refers to identification, preservation, collection, and production of electronically stored information for legal proceedings.

Answer C is incorrect because Digital forensics addresses a different requirement. Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence.

Answer D is incorrect because Eradication addresses a different security requirement. Eradication refers to removal of malware, attacker persistence, compromised accounts, or root causes from the environment.

 

Question 5

Which term describes removal of malware, attacker persistence, compromised accounts, or root causes from the environment?

  1. Analysis
  2. Containment
  3. Digital forensics
  4. Eradication

Correct Answer: D

 

Correct Answer

Answer D is correct because Eradication means removal of malware, attacker persistence, compromised accounts, or root causes from the environment.

Incorrect Answers

Answer A is incorrect because Analysis addresses a different requirement. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.

Answer B is incorrect because Containment represents a different security function. Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate.

Answer C is incorrect because Digital forensics would fit a different scenario. Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence.

 

Question 6

To return to production safely after eradication, which security approach should be selected?

  1. Recovery
  2. Tabletop exercise
  3. Containment
  4. Legal hold

Correct Answer: A

 

Correct Answer

Answer A is correct because Recovery means restoration of systems and business services to normal operation with appropriate validation and monitoring.

Incorrect Answers

Answer B is incorrect because Tabletop exercise would fit a different scenario. Tabletop exercise refers to discussion-based walkthrough of an incident scenario.

Answer C is incorrect because Containment addresses a different security requirement. Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate.

Answer D is incorrect because Legal hold addresses a different requirement. Legal hold refers to instruction to preserve relevant information because of litigation, investigation, or legal obligation.

 

Question 7

Which term describes post-incident review of what happened, what worked, what failed, and what should change?

  1. Digital forensics
  2. Threat hunting
  3. Lessons learned
  4. E-discovery

Correct Answer: C

 

Correct Answer

Answer C is correct because Lessons learned means post-incident review of what happened, what worked, what failed, and what should change.

Incorrect Answers

Answer A is incorrect because Digital forensics would fit a different scenario. Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence.

Answer B is incorrect because Threat hunting represents a different security function. Threat hunting refers to proactive search for signs of attackers or compromise not already identified by routine detections.

Answer D is incorrect because E-discovery addresses a different requirement. E-discovery refers to identification, preservation, collection, and production of electronically stored information for legal proceedings.

 

Question 8

To build capability before pressure from a real incident, which security approach should be selected?

  1. Incident-response training
  2. Containment
  3. Tabletop exercise
  4. E-discovery

Correct Answer: A

 

Correct Answer

Answer A is correct because Incident-response training means education that teaches responders and stakeholders their responsibilities and procedures.

Incorrect Answers

Answer B is incorrect because Containment addresses a different requirement. Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate.

Answer C is incorrect because Tabletop exercise would fit a different scenario. Tabletop exercise refers to discussion-based walkthrough of an incident scenario.

Answer D is incorrect because E-discovery addresses a different security requirement. E-discovery refers to identification, preservation, collection, and production of electronically stored information for legal proceedings.

 

Question 9

Which term describes discussion-based walkthrough of an incident scenario?

  1. Simulation exercise
  2. Preparation
  3. Containment
  4. Tabletop exercise

Correct Answer: D

 

Correct Answer

Answer D is correct because Tabletop exercise means discussion-based walkthrough of an incident scenario.

Incorrect Answers

Answer A is incorrect because Simulation exercise would fit a different scenario. Simulation exercise refers to practice activity that imitates a more realistic incident and response environment.

Answer B is incorrect because Preparation represents a different security function. Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.

Answer C is incorrect because Containment addresses a different requirement. Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate.

 

Question 10

To evaluate operational behavior under conditions closer to a real event, which security approach should be selected?

  1. Analysis
  2. Threat hunting
  3. Simulation exercise
  4. Detection

Correct Answer: C

 

Correct Answer

Answer C is correct because Simulation exercise means practice activity that imitates a more realistic incident and response environment.

Incorrect Answers

Answer A is incorrect because Analysis addresses a different requirement. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.

Answer B is incorrect because Threat hunting would fit a different scenario. Threat hunting refers to proactive search for signs of attackers or compromise not already identified by routine detections.

Answer D is incorrect because Detection addresses a different security requirement. Detection refers to recognition that a potentially security-relevant event has occurred.

 

Question 11

Which term describes structured effort to identify the underlying condition that allowed an incident to occur?

  1. Detection
  2. Digital forensics
  3. Root cause analysis
  4. Analysis

Correct Answer: C

 

Correct Answer

Answer C is correct because Root cause analysis means structured effort to identify the underlying condition that allowed an incident to occur.

Incorrect Answers

Answer A is incorrect because Detection addresses a different requirement. Detection refers to recognition that a potentially security-relevant event has occurred.

Answer B is incorrect because Digital forensics represents a different security function. Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence.

Answer D is incorrect because Analysis would fit a different scenario. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.

 

Question 12

To discover hidden threats using hypotheses and available telemetry, which security approach should be selected?

  1. Lessons learned
  2. Threat hunting
  3. Digital forensics
  4. Detection

Correct Answer: B

 

Correct Answer

Answer B is correct because Threat hunting means proactive search for signs of attackers or compromise not already identified by routine detections.

Incorrect Answers

Answer A is incorrect because Lessons learned would fit a different scenario. Lessons learned refers to post-incident review of what happened, what worked, what failed, and what should change.

Answer C is incorrect because Digital forensics addresses a different requirement. Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence.

Answer D is incorrect because Detection addresses a different security requirement. Detection refers to recognition that a potentially security-relevant event has occurred.

 

Question 13

Which term describes disciplined collection, preservation, examination, and reporting of digital evidence?

  1. Digital forensics
  2. E-discovery
  3. Analysis
  4. Preparation

Correct Answer: A

 

Correct Answer

Answer A is correct because Digital forensics means disciplined collection, preservation, examination, and reporting of digital evidence.

Incorrect Answers

Answer B is incorrect because E-discovery addresses a different requirement. E-discovery refers to identification, preservation, collection, and production of electronically stored information for legal proceedings.

Answer C is incorrect because Analysis would fit a different scenario. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.

Answer D is incorrect because Preparation represents a different security function. Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.

 

Question 14

To prevent normal deletion or modification of potentially discoverable evidence, which security approach should be selected?

  1. Legal hold
  2. Digital forensics
  3. Forensic acquisition
  4. Tabletop exercise

Correct Answer: A

 

Correct Answer

Answer A is correct because Legal hold means instruction to preserve relevant information because of litigation, investigation, or legal obligation.

Incorrect Answers

Answer B is incorrect because Digital forensics addresses a different requirement. Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence.

Answer C is incorrect because Forensic acquisition would fit a different scenario. Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data.

Answer D is incorrect because Tabletop exercise addresses a different security requirement. Tabletop exercise refers to discussion-based walkthrough of an incident scenario.

 

Question 15

Which term describes documentation showing who collected, handled, transferred, stored, and examined evidence?

  1. Tabletop exercise
  2. Chain of custody
  3. Root cause analysis
  4. Containment

Correct Answer: B

 

Correct Answer

Answer B is correct because Chain of custody means documentation showing who collected, handled, transferred, stored, and examined evidence.

Incorrect Answers

Answer A is incorrect because Tabletop exercise would fit a different scenario. Tabletop exercise refers to discussion-based walkthrough of an incident scenario.

Answer C is incorrect because Root cause analysis addresses a different requirement. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.

Answer D is incorrect because Containment represents a different security function. Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate.

 

Question 16

To analyze evidence without unnecessarily modifying the source, which security approach should be selected?

  1. E-discovery
  2. Forensic acquisition
  3. Incident-response training
  4. Root cause analysis

Correct Answer: B

 

Correct Answer

Answer B is correct because Forensic acquisition means creation of a defensible copy of digital evidence using methods that preserve original data.

Incorrect Answers

Answer A is incorrect because E-discovery would fit a different scenario. E-discovery refers to identification, preservation, collection, and production of electronically stored information for legal proceedings.

Answer C is incorrect because Incident-response training addresses a different requirement. Incident-response training refers to education that teaches responders and stakeholders their responsibilities and procedures.

Answer D is incorrect because Root cause analysis addresses a different security requirement. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.

 

Question 17

Which term describes protection of evidence from alteration, loss, or unauthorized access?

  1. Eradication
  2. Evidence preservation
  3. Simulation exercise
  4. Root cause analysis

Correct Answer: B

 

Correct Answer

Answer B is correct because Evidence preservation means protection of evidence from alteration, loss, or unauthorized access.

Incorrect Answers

Answer A is incorrect because Eradication would fit a different scenario. Eradication refers to removal of malware, attacker persistence, compromised accounts, or root causes from the environment.

Answer C is incorrect because Simulation exercise represents a different security function. Simulation exercise refers to practice activity that imitates a more realistic incident and response environment.

Answer D is incorrect because Root cause analysis addresses a different requirement. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.

 

Question 18

To satisfy litigation or regulatory information requests, which security approach should be selected?

  1. E-discovery
  2. Simulation exercise
  3. Root cause analysis
  4. Evidence preservation

Correct Answer: A

 

Correct Answer

Answer A is correct because E-discovery means identification, preservation, collection, and production of electronically stored information for legal proceedings.

Incorrect Answers

Answer B is incorrect because Simulation exercise would fit a different scenario. Simulation exercise refers to practice activity that imitates a more realistic incident and response environment.

Answer C is incorrect because Root cause analysis addresses a different security requirement. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.

Answer D is incorrect because Evidence preservation addresses a different requirement. Evidence preservation refers to protection of evidence from alteration, loss, or unauthorized access.

 

Question 19

To make the organization capable of responding effectively before a real event, which security approach should be selected?

  1. Digital forensics
  2. Preparation
  3. Analysis
  4. Legal hold

Correct Answer: B

 

Correct Answer

Answer B is correct because Preparation means the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.

Incorrect Answers

Answer A is incorrect because Digital forensics represents a different security function. Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence.

Answer C is incorrect because Analysis addresses a different security requirement. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.

Answer D is incorrect because Legal hold would fit a different scenario. Legal hold refers to instruction to preserve relevant information because of litigation, investigation, or legal obligation.

 

Question 20

Which term describes recognition that a potentially security-relevant event has occurred?

  1. Preparation
  2. Evidence preservation
  3. Forensic acquisition
  4. Detection

Correct Answer: D

 

Correct Answer

Answer D is correct because Detection means recognition that a potentially security-relevant event has occurred.

Incorrect Answers

Answer A is incorrect because Preparation represents a different security function. Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.

Answer B is incorrect because Evidence preservation addresses a different requirement. Evidence preservation refers to protection of evidence from alteration, loss, or unauthorized access.

Answer C is incorrect because Forensic acquisition addresses a different security requirement. Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data.

 

Question 21

To decide whether an event is an incident and understand what happened, which security approach should be selected?

  1. Analysis
  2. Root cause analysis
  3. Preparation
  4. Recovery

Correct Answer: A

 

Correct Answer

Answer A is correct because Analysis means investigation of evidence to determine scope, cause, severity, and likely impact.

Incorrect Answers

Answer B is incorrect because Root cause analysis would fit a different scenario. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.

Answer C is incorrect because Preparation represents a different security function. Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.

Answer D is incorrect because Recovery addresses a different security requirement. Recovery refers to restoration of systems and business services to normal operation with appropriate validation and monitoring.

 

Question 22

Which term describes actions that limit spread or ongoing damage while preserving the ability to investigate?

  1. Chain of custody
  2. Simulation exercise
  3. Containment
  4. Root cause analysis

Correct Answer: C

 

Correct Answer

Answer C is correct because Containment means actions that limit spread or ongoing damage while preserving the ability to investigate.

Incorrect Answers

Answer A is incorrect because Chain of custody addresses a different security requirement. Chain of custody refers to documentation showing who collected, handled, transferred, stored, and examined evidence.

Answer B is incorrect because Simulation exercise represents a different security function. Simulation exercise refers to practice activity that imitates a more realistic incident and response environment.

Answer D is incorrect because Root cause analysis addresses a different requirement. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.

 

Question 23

To eliminate the threat after it has been contained, which security approach should be selected?

  1. Tabletop exercise
  2. Preparation
  3. Analysis
  4. Eradication

Correct Answer: D

 

Correct Answer

Answer D is correct because Eradication means removal of malware, attacker persistence, compromised accounts, or root causes from the environment.

Incorrect Answers

Answer A is incorrect because Tabletop exercise represents a different security function. Tabletop exercise refers to discussion-based walkthrough of an incident scenario.

Answer B is incorrect because Preparation would fit a different scenario. Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.

Answer C is incorrect because Analysis addresses a different security requirement. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.

 

Question 24

Which term describes restoration of systems and business services to normal operation with appropriate validation and monitoring?

  1. Simulation exercise
  2. Preparation
  3. Incident-response training
  4. Recovery

Correct Answer: D

 

Correct Answer

Answer D is correct because Recovery means restoration of systems and business services to normal operation with appropriate validation and monitoring.

Incorrect Answers

Answer A is incorrect because Simulation exercise represents a different security function. Simulation exercise refers to practice activity that imitates a more realistic incident and response environment.

Answer B is incorrect because Preparation addresses a different requirement. Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.

Answer C is incorrect because Incident-response training addresses a different security requirement. Incident-response training refers to education that teaches responders and stakeholders their responsibilities and procedures.

 

Question 25

To improve controls and response processes after an event, which security approach should be selected?

  1. Analysis
  2. Simulation exercise
  3. Lessons learned
  4. Detection

Correct Answer: C

 

Correct Answer

Answer C is correct because Lessons learned means post-incident review of what happened, what worked, what failed, and what should change.

Incorrect Answers

Answer A is incorrect because Analysis addresses a different security requirement. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.

Answer B is incorrect because Simulation exercise would fit a different scenario. Simulation exercise refers to practice activity that imitates a more realistic incident and response environment.

Answer D is incorrect because Detection represents a different security function. Detection refers to recognition that a potentially security-relevant event has occurred.

 

Question 26

Which term describes education that teaches responders and stakeholders their responsibilities and procedures?

  1. Preparation
  2. Incident-response training
  3. Root cause analysis
  4. Legal hold

Correct Answer: B

 

Correct Answer

Answer B is correct because Incident-response training means education that teaches responders and stakeholders their responsibilities and procedures.

Incorrect Answers

Answer A is incorrect because Preparation represents a different security function. Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.

Answer C is incorrect because Root cause analysis addresses a different requirement. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.

Answer D is incorrect because Legal hold addresses a different security requirement. Legal hold refers to instruction to preserve relevant information because of litigation, investigation, or legal obligation.

 

Question 27

To test decisions, communications, and plan completeness without affecting production, which security approach should be selected?

  1. Analysis
  2. Root cause analysis
  3. Containment
  4. Tabletop exercise

Correct Answer: D

 

Correct Answer

Answer D is correct because Tabletop exercise means discussion-based walkthrough of an incident scenario.

Incorrect Answers

Answer A is incorrect because Analysis represents a different security function. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.

Answer B is incorrect because Root cause analysis would fit a different scenario. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.

Answer C is incorrect because Containment addresses a different security requirement. Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate.

 

Question 28

Which term describes practice activity that imitates a more realistic incident and response environment?

  1. Threat hunting
  2. Detection
  3. Simulation exercise
  4. Legal hold

Correct Answer: C

 

Correct Answer

Answer C is correct because Simulation exercise means practice activity that imitates a more realistic incident and response environment.

Incorrect Answers

Answer A is incorrect because Threat hunting addresses a different requirement. Threat hunting refers to proactive search for signs of attackers or compromise not already identified by routine detections.

Answer B is incorrect because Detection represents a different security function. Detection refers to recognition that a potentially security-relevant event has occurred.

Answer D is incorrect because Legal hold addresses a different security requirement. Legal hold refers to instruction to preserve relevant information because of litigation, investigation, or legal obligation.

 

Question 29

To prevent recurrence by fixing causes rather than symptoms alone, which security approach should be selected?

  1. Lessons learned
  2. Forensic acquisition
  3. Recovery
  4. Root cause analysis

Correct Answer: D

 

Correct Answer

Answer D is correct because Root cause analysis means structured effort to identify the underlying condition that allowed an incident to occur.

Incorrect Answers

Answer A is incorrect because Lessons learned addresses a different security requirement. Lessons learned refers to post-incident review of what happened, what worked, what failed, and what should change.

Answer B is incorrect because Forensic acquisition represents a different security function. Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data.

Answer C is incorrect because Recovery would fit a different scenario. Recovery refers to restoration of systems and business services to normal operation with appropriate validation and monitoring.

 

Question 30

Which term describes proactive search for signs of attackers or compromise not already identified by routine detections?

  1. Root cause analysis
  2. Threat hunting
  3. Incident-response training
  4. Eradication

Correct Answer: B

 

Correct Answer

Answer B is correct because Threat hunting means proactive search for signs of attackers or compromise not already identified by routine detections.

Incorrect Answers

Answer A is incorrect because Root cause analysis represents a different security function. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.

Answer C is incorrect because Incident-response training addresses a different requirement. Incident-response training refers to education that teaches responders and stakeholders their responsibilities and procedures.

Answer D is incorrect because Eradication addresses a different security requirement. Eradication refers to removal of malware, attacker persistence, compromised accounts, or root causes from the environment.

 

Question 31

To support incident understanding while maintaining evidentiary integrity, which security approach should be selected?

  1. E-discovery
  2. Digital forensics
  3. Simulation exercise
  4. Tabletop exercise

Correct Answer: B

 

Correct Answer

Answer B is correct because Digital forensics means disciplined collection, preservation, examination, and reporting of digital evidence.

Incorrect Answers

Answer A is incorrect because E-discovery represents a different security function. E-discovery refers to identification, preservation, collection, and production of electronically stored information for legal proceedings.

Answer C is incorrect because Simulation exercise would fit a different scenario. Simulation exercise refers to practice activity that imitates a more realistic incident and response environment.

Answer D is incorrect because Tabletop exercise addresses a different security requirement. Tabletop exercise refers to discussion-based walkthrough of an incident scenario.

 

Question 32

Which term describes instruction to preserve relevant information because of litigation, investigation, or legal obligation?

  1. Eradication
  2. Legal hold
  3. Analysis
  4. Incident-response training

Correct Answer: B

 

Correct Answer

Answer B is correct because Legal hold means instruction to preserve relevant information because of litigation, investigation, or legal obligation.

Incorrect Answers

Answer A is incorrect because Eradication addresses a different requirement. Eradication refers to removal of malware, attacker persistence, compromised accounts, or root causes from the environment.

Answer C is incorrect because Analysis represents a different security function. Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact.

Answer D is incorrect because Incident-response training addresses a different security requirement. Incident-response training refers to education that teaches responders and stakeholders their responsibilities and procedures.

 

Question 33

To demonstrate integrity and accountability for evidence handling, which security approach should be selected?

  1. Chain of custody
  2. Forensic acquisition
  3. Evidence preservation
  4. Root cause analysis

Correct Answer: A

 

Correct Answer

Answer A is correct because Chain of custody means documentation showing who collected, handled, transferred, stored, and examined evidence.

Incorrect Answers

Answer B is incorrect because Forensic acquisition represents a different security function. Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data.

Answer C is incorrect because Evidence preservation would fit a different scenario. Evidence preservation refers to protection of evidence from alteration, loss, or unauthorized access.

Answer D is incorrect because Root cause analysis addresses a different security requirement. Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur.

 

Question 34

Which term describes creation of a defensible copy of digital evidence using methods that preserve original data?

  1. Incident-response training
  2. Lessons learned
  3. Forensic acquisition
  4. Preparation

Correct Answer: C

 

Correct Answer

Answer C is correct because Forensic acquisition means creation of a defensible copy of digital evidence using methods that preserve original data.

Incorrect Answers

Answer A is incorrect because Incident-response training represents a different security function. Incident-response training refers to education that teaches responders and stakeholders their responsibilities and procedures.

Answer B is incorrect because Lessons learned addresses a different security requirement. Lessons learned refers to post-incident review of what happened, what worked, what failed, and what should change.

Answer D is incorrect because Preparation addresses a different requirement. Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.

 

Question 35

To maintain reliability of information needed for investigation or legal use, which security approach should be selected?

  1. Forensic acquisition
  2. Detection
  3. Evidence preservation
  4. Tabletop exercise

Correct Answer: C

 

Correct Answer

Answer C is correct because Evidence preservation means protection of evidence from alteration, loss, or unauthorized access.

Incorrect Answers

Answer A is incorrect because Forensic acquisition represents a different security function. Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data.

Answer B is incorrect because Detection would fit a different scenario. Detection refers to recognition that a potentially security-relevant event has occurred.

Answer D is incorrect because Tabletop exercise addresses a different security requirement. Tabletop exercise refers to discussion-based walkthrough of an incident scenario.

img