200-201 Question 356
Select 4You are a cybersecurity analyst investigating a potential security incident at a financial institution. Following the NIST SP 800-86 guidelines, which of the following steps should you prioritize during the 'Collection' phase of the digital forensic process?
- A
Identify and acquire volatile data from active systems before it is lost.
- B
Establish a chain of custody for collected evidence to maintain its integrity.
- C
Analyze the collected data to identify patterns or anomalies related to the incident.
- D
Preserve raw data in its original state to prevent any alteration.
- E
Document every action taken during the collection process for auditing purposes.
Show answer and explanation
Correct answers: A, B, D, E
Explanation
The 'Collection' phase, as described in NIST SP 800-86, focuses on identifying, acquiring, preserving, and documenting data that could serve as evidence. Actions such as collecting volatile data, maintaining a chain of custody, preserving data integrity, and documenting procedures are critical to ensure the reliability and usefulness of the evidence. Analysis and examination are handled in subsequent phases, making option 3 incorrect.
- A. Correct.
Identifying and acquiring volatile data, such as memory or network activity, is critical in the 'Collection' phase as this data can be lost quickly.
- B. Correct.
Establishing a chain of custody ensures the integrity and admissibility of the evidence in legal or investigative contexts.
- C. Incorrect.
Data analysis is part of the 'Examination' or 'Analysis' phases, not the 'Collection' phase, so this step is not prioritized here.
- D. Correct.
Preserving raw data in its original state is a key component of the 'Collection' phase to ensure the evidence is not altered.
- E. Correct.
Documenting all actions is essential in the 'Collection' phase for accountability and traceability.