Certified Information Security Manager CISM · Free Practice Question Easy
Question 38
-
A
Identify the malware responsible for an incident.
-
B
Preserve evidence used in later legal proceedings.
-
C
Satisfy regulatory requirements such as NYDFS and HIPAA.
-
D
Identify events and artifacts on a system or network that could be related to an incident.
Reveal correct answer
Correct answer: D
Explanation
Correct Answer:
"Identify events and artifacts on a system or network that could be related to an incident." is correct. The purpose of forensic analysis tools is to examine systems and networks closely to determine whether any events exist that are related to an incident.
Incorrect Answers:
"Preserve evidence used in later legal proceedings."
is incorrect because although forensic analysis tools are used to determine what happened on information systems or networks, their focus does not typically include evidence preservation.
"Satisfy regulatory requirements such as NYDFS and HIPAA." is incorrect because forensic analysis tools are not designed to meet regulatory requirements, but instead are used to determine what happened in information systems and networks.
"Identify the malware responsible for an incident." is incorrect because forensic analysis tools look at what actions malware performed on a system but do not identify the specific malware used.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
