200-201 exam dumps

200-201 practice question 358 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 358

Single answer

You are a cybersecurity analyst responding to a suspected data breach in your organization's network. During the investigation, you need to collect evidence in a manner that ensures it can be used in legal proceedings. Which of the following represents the correct evidence collection order to maximize the integrity of the evidence?

  1. A

    Collect data from volatile memory (RAM) first, followed by logs and hard drive contents.

  2. B

    Start with physical evidence such as hard drives, then collect data from volatile memory (RAM) and logs.

  3. C

    Capture network traffic first, then gather data from RAM, followed by logs and hard drives.

  4. D

    Prioritize collecting logs from the server before attempting to access volatile memory (RAM) or network traffic.

Show answer and explanation

Correct answer: A

Explanation

The evidence collection order is crucial in incident response to ensure the integrity and admissibility of evidence. Volatile data, such as RAM and live network traffic, is the most susceptible to loss and should be collected first. Less volatile data, like logs and hard drive contents, can be collected later as they are more persistent. Following this order helps maintain the chain of custody and ensures no critical evidence is lost.

  • A. Correct.

    Collecting data from volatile memory (RAM) first is correct because it is the most volatile form of evidence and can be lost quickly if the system is powered off or altered. Logs and hard drive contents are less volatile and can be collected after volatile evidence is secured.

  • B. Incorrect.

    Starting with physical evidence, such as hard drives, is incorrect because hard drives are less volatile compared to data in RAM or network traffic, which should be prioritized.

  • C. Incorrect.

    Capturing network traffic first is incorrect because while network traffic is important, data in RAM is typically more volatile and should be collected before network traffic to preserve evidence integrity.

  • D. Incorrect.

    Prioritizing logs from the server over volatile memory or network traffic is incorrect because logs are less volatile than RAM and network traffic, which should be collected first.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam