Incident Response

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/7

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 12:43 AM on 8/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

8 Terms

1
New cards

Which of the following best describes the primary purpose of maintaining a chain of custody?

To preserve the integrity of evidence for potential legal proceedings

2
New cards

Which items must always be included when documenting a chain of custody?

Chronological log of everyone who handled the evidence

Date and time of evidence transfer

3
New cards

A technician discovers evidence of credit card data theft on a company server. What is the most appropriate next step?

Notify management and follow escalation procedures

4
New cards

Which of the terms listed below is used to describe a forensic copy of a storage device that captures every sector of the drive, including deleted files, hidden partitions, and unallocated space?

Bit-by-bit image

5
New cards

During an incident investigation, a technician must acquire data from a suspect’s storage drive without altering any information. Which of the following ensures the contents of the drive cannot be modified during this process?

Write blocker

6
New cards

A technician needs to confirm that a forensic image has not been altered since its creation. Which method provides this assurance?

Comparing hash values

7
New cards

When documenting a security incident, which type of detail should be strictly avoided to maintain the integrity of the report?

Speculative statements

8
New cards

Which of the answers listed below shows the basic order of volatility for a typical system?

CPU registers/cache, RAM, Disk, Archival media