Certified Information Systems Security Professional CISSP · Free Practice Question Easy
Question 93
We have had a breach, and an attacker gained access to some of our servers and workstations. We are planning to use digital forensics from the time of the attack in a court of law. What should the evidence NOT be?
- A Admissible.
- B Altered.
- C Accurate.
- D Authentic.
Reveal correct answer
Correct answer: B
Explanation
The correct answer: Altered evidence would not be acceptable in a court of law because it would not accurately represent what occurred during the attack. Altering the original evidence can lead to a loss of credibility and could potentially make the evidence inadmissible in a court of law. Any analysis or testing should be performed on a copy of the original evidence, and every step in the process should be carefully documented to maintain the integrity of the investigation. The incorrect answers: Evidence in digital forensics should indeed be accurate. Accurate evidence refers to the precision and correctness of the information presented. Accurate evidence helps in establishing a truthful account of the events. Authenticity of evidence is paramount in any legal proceedings. Authentic evidence means that it is genuine and not a fraudulent or altered copy. In digital forensics, authenticity is ensured by utilizing a proper chain of custody and using proven, accepted methodologies to collect and analyze the evidence. Evidence should be admissible in a court of law. Admissible evidence refers to any testimonial, documentary, or tangible evidence that may be introduced to a factfinder—usually a judge or jury—in order to establish or to bolster a point put forth by a party to the proceeding. If the evidence is not admissible, it cannot be considered by the court.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
