100-160 Question 244
Single answerA cybersecurity analyst is investigating a potential data breach at an organization. During the investigation, they observe unusual outbound traffic that matches a known TTP from the MITRE ATT&CK Matrix. The analyst collects logs from the firewall and endpoint devices for further analysis. What should the analyst do next to preserve the integrity of the evidence?
- A
Immediately analyze the logs using an online tool to identify the attacker's IP address.
- B
Ensure the logs are copied to a secure location and document the chain of custody for the evidence.
- C
Share the logs with all team members through email for collaborative analysis.
- D
Delete duplicate copies of the logs to prevent confusion during the investigation.
Show answer and explanation
Correct answer: B
Explanation
When handling digital evidence, it is crucial to follow best practices for preserving its integrity. This includes securing the evidence in a trusted location, documenting the chain of custody, and preventing unauthorized access or tampering. These steps ensure the evidence remains admissible in legal or forensic contexts and supports accurate analysis.
- A. Incorrect.
Immediately analyzing the logs online without preserving the original evidence may compromise its integrity. Evidence must first be secured before any analysis.
- B. Correct.
Ensuring the logs are copied to a secure location and documenting the chain of custody is the correct step to preserve the integrity of the evidence. This ensures the evidence remains admissible and untampered.
- C. Incorrect.
Sharing the logs through email can result in unauthorized access or modification, which jeopardizes the integrity of the evidence.
- D. Incorrect.
Deleting duplicate copies without ensuring proper preservation and documentation can lead to loss of critical data and evidence tampering concerns.