1/39
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
A security strategy is important for an enterprise PRIMARILY because it:
A. provides a basis for determining the best logical security architecture.
B. provides the approach to achieving the outcomes management wants.
C. provides users guidance on how to operate securely in everyday tasks.
D. helps IT auditors ensure compliance with rules and regulations.
B. A security strategy will define the approach to achieving the security program outcomes management wants. It should also be a statement or now security angns wit and supports business objecuves. It provides te basis for good security governance.
A. Policies have to be developed to support the security strategy, and an architecture can only be developed after policies are completed (i.e., the security strategy is not the basis for architecture—policies are).
C. A security strategy may include requirements for users to operate securely, but it does not address how that is to be accomplished.
D. IT auditors do not determine compliance based on strategy but, rather, on elements such as standards and control objectives.
Which of the following is the MOST important reason to provide effective communication about information security?
A. It makes information security more palatable to resistant employees.
B. It mitigates the weakest link in the information security landscape.
C. It informs business units about the information security strategy.
D. It helps the enterprise conform to regulatory information security requirements.
B. Security failures are, in the majority of instances, directly attributable to lack of awareness or failure of employees to follow policies or procedures. Communication is important to ensure continued awareness of security policies and procedures among staff and business partners.
A. Effective communication may assist in making information security more palatable, but that is not the most important aspect.
C. A security strategy may include requirements for users to operate securely, but it does not address how that is to be accomplished.
D. IT auditors do not determine compliance based on strategy but, rather, on elements such as standards and control objectives.
Which of the following approaches BEST helps the information security manager achieve compliance with various regulatory requirements?
A. Rely on corporate counsel to advise which regulations are the most relevant.
B. Stay current with all relevant regulations and request legal interpretation.
C. Involve all impacted departments and treat regulations as just another risk.
D. Ignore many of the regulations that have no penalties.
C. Because departments such as human resources, finance and legal are most often subject to new regulations and must be involved in determining how best to meet the existing and emerging requirements, they typically would be most aware of these regulations. Treating regulations as another risk puts them in the proper perspective, and the mechanisms to deal with them should already exist. The fact that there are so many regulations makes it unlikely that they can all be specifically addressed efficiently. Many do not currently have significant consequences and may be addressed by compliance with other regulations. The most relevant response to regulatory requirements is to determine potential impact to the enterprise, just as with any other risk.
A. Corporate counsel is generally involved primarily with stock issues and the associated filings required by regulators and with contract matters. It is unlikely that legal staff will be current on information security regulations and legal requirements.
B. While it can be useful to stay abreast of all current and emerging regulations, it is, as a practical matter, nearly impossible—especially for a multinational company.
D. Even if certain regulations have few or no penalties, ignoring them without consideration for other potential impacts (e.g.,reputational damage) and whether they might be relevant to the enterprise is not a prudent approach.
The MOST important consideration in developing security policies is that:
A. they are based on a threat profile
B. they are complete and no detail is left out.
C. management signs off on them.
D. all employees read and understand them.
A. The basis for developing relevant security policies is addressing viable threats to the enterprise, prioritized by the likelihood of occurrence and their potential impact on the business. The strictest policies apply to the areas of greatest business value. This ensures that protection proportionality is maintained.
A. Corporate counsel is generally involved primarily with stock issues and the associated filings required by regulators and with contract matters. It is unlikely that legal staff will be current on information security regulations and legal requirements.
B. While it can be useful to stay abreast of all current and emerging regulations, it is, as a practical matter, nearly impossible— especially for a multinational company.
D. Even if certain regulations have few or no penalties, ignoring them without consideration for other potential impacts (e.g., reputational damage) and whether they might be relevant to the enterprise is not a prudent approach.
The PRIMARY security objective in creating good procedures is:
A. to make sure they work as intended.
B. that they are unambiguous and meet the standards.
C. that they are written in plain language and are widely distributed.
D. that compliance can be monitored.
B. All the answers are important, but the first criterion must be to ensure that there is no ambiguity in the procedures and that, from a security perspective, they meet the applicable standards and comply with policy.
A. While it is important to make sure that procedures work as intended, their failure may not be a security issue.
C. Having clearly written procedures that are provided to all staff as needed is important, but it is not as important as ensuring that procedures comply with policy.
D. Compliance is important, but it is essential that compliance is achieved with a correct procedure.
Which of the following MOST helps ensure that assignment of roles and responsibilities is effective?
A. Senior management is in support of the assignments.
B. The assignments are consistent with existing proficiencies.
C. The assignments are mapped to required skills.
D. The assignments are given on a voluntary basis.
B. The level of effectiveness of employees will be determined by their existing knowledge and capabilities—in other words, their proficiencies.
A. Senior management support is always important, but it is not crucial to the effectiveness of employee activities.
C. Mapping roles to the tasks that are required can be useful, but it is no guarantee that people can perform the required tasks.
D. While employees are more likely to be enthusiastic about a job they have volunteered for, it is not a requirement for them to be Maintaining appropriate regulatory compliance is a useful, but secondary, outcome.
Which of the following benefits is the MOST important to an enterprise with effective information security governance?
A. Maintaining appropriate regulatory compliance
B. Ensuring disruptions are within acceptable levels
C. Prioritizing allocation of remedial resources
D. Maximizing return on security investments
B. The bottom line of security efforts is to ensure that business can continue to operate with an acceptable level of disruption that does not unduly constrain revenue-producing activities.
A. Maintaining appropriate regulatory compliance is a useful, but secondary, outcome.
C. Prioritizing allocation of remedial resources is a useful, but secondary, outcome.
D. Maximizing return on security investments is a useful, but secondary, outcome.
From an information security manager's perspective, the MOST important factors regarding data retention are:
A. business and regulatory requirements.
B. document integrity and destruction.
C. media availability and storage.
D. data confidentiality and encryption.
A. Business and regulatory requirements are the driving factors for data retention.
B. Integrity is a key factor for information security; however, business and regulatory requirements are the driving factors for data retention.
C. Availability is a key factor for information security; however, business and regulatory requirements are the driving factors for data retention.
D. Confidentiality is a key factor for information security; however, business and regulatory requirements are the driving factors for data retention.
Which role is in the BEST position to review and confirm the appropriateness of a list of approved users?
A. Data owner
B. Information security manager
C. Domain administrator
D. Business manager
A. Data owners are responsible for periodic reconfirmation of access lists for systems they own.
B. Information security managers are in charge of coordinating user access list reviews, but they do not have any responsibility for data access.
C. Domain administrators may technically provide access, but they do not approve it.
D. Business manager is incorrect because the business managers may not be the data owners.
In implementing information security governance, the information security manager is PRIMARILY responsible for:
A. developing the security strategy.
B. reviewing the security strategy.
C. communicating the security strategy.
D. approving the security strategy.
A. The information security manager is responsible for developing a security strategy based on business objectives with the help of business process owners and senior management.
B. The information security strategy is the responsibility of a steering committee and/or senior management.
C. The information security manager is not necessarily responsible for communicating the security strategy.
D. Final approval of the information security strategy must be made by senior management.
The overall objective of risk management is to:
A. eliminate all possible vulnerabilities.
B. reduce risk to the lowest possible level.
C. manage risk to an acceptable level.
D. implement effective countermeasures.
C. The objective of risk management is managing risk to a level acceptable to the enterprise.
A. It is not possible to eliminate all vulnerabilities, and vulnerabilities that have no impact or exposure do not require the expenditure of resources to remediate or achieve elimination.
B. Reduction of risk to the lowest level generally is more costly and unnecessarily restrictive. The goal is to achieve control objectives that will result in acceptable levels of risk.
The information security manager should treat regulatory compliance as:
A. an organizational mandate.
B. a risk management priority.
C. a purely operational issue.
D. another risk to be managed.
D. There are numerous regulations that may affect an enterprise. Priority will be a management decision based on those regulations with the greatest level of enforcement (risk) and the most severe sanctions (consequences or impact) in addition to the cost of compliance (mitigation), just as with any other risk. In some cases, management may decide that the cost of potential sanctions will be less than the cost of compliance. While it is generally preferable to be as compliant as reasonably possible, the extent of regulatory compliance is a management decision, not a security decision. All risk must be prioritized, and compliance may not pose the greatest risk.
A. A regulatory requirement, regardless of whether it is mandated by the enterprise, should be treated as any other risk.
B. A regulatory requirement is a priority to the extent the level of risk compares to other risk. Priorities for risk management are usually based on probability and impact —the more likely the compromise and the more severe the consequences, the higher the priority.
C. Regulatory compliance is not just an operational issue, but a management issue.
To address changes in risk, an effective risk management program should:
A. ensure that continuous monitoring processes are in place.
B. establish proper security baselines for all information resources.
C. implement a complete data classification process.
D. change security policies on a timely basis to address changing risk.
A. Risk changes as threats, vulnerabilities or potential impacts change over time. The risk management program must have processes in place to monitor those changes and modify countermeasures, as appropriate, to maintain acceptable levels of residual risk.
B. Security baselines are set to achieve acceptable levels of particular levels of identified risk. Baselines do not address changes in risk and may need to be changed when risk changes.
C. Data classification is based on business value of the data (i.e., the data’s sensitivity or criticality) and does not address changes in risk.
D. Policies should not require changes as a result of changes in risk. Standards and procedures may need to be changed to address significant changes in risk.
Information classification is important to properly manage risk PRIMARILY because:
A. it ensures accountability for information resources as required by roles and responsibilities.
B. it is a legal requirement under various regulations.
C. it ensures adequate protection of assets commensurate with the degree of risk.
D. asset protection can then be based on the potential consequences of compromise.
D. Classification is based on potential impact or consequences of compromise.
A. Classification does not ensure accountability.
B. Classification is not generally a legal requirement.
C. Classification is not based on risk.
Vulnerabilities discovered during an assessment should be:
A. handled as a risk, even though there is no threat.
B. prioritized for remediation solely based on impact.
C. a basis for analyzing the effectiveness of controls.
D. evaluated for threat, impact and cost of mitigation.
D. Vulnerabilities uncovered should be evaluated and prioritized based on whether there is a credible threat, the impact if the vulnerability is exploited and the cost of mitigation. If there is a potential threat but little or no impact if the vulnerability is exploited, there is little risk, and it may not be cost-effective to address it.
A. Vulnerabilities may not be exposed to potential threats. Also, there may be no threat or possibly little or no impact even if exploited. While threats are always evolving, without additional information, the appropriate treatment cannot be determined.
B. Vulnerabilities should be prioritized for remediation based on probability of compromise (which is affected by the level of exposure), impact and cost of remediation.
C. Vulnerabilities discovered will, to some extent, show whether existing controls are in place to address a potential risk, but they do not indicate the controls’ effectiveness.
Indemnity agreements can be used to:
A. ensure an agreed-upon level of service.
B. reduce impacts on organizational resources.
C. transfer responsibility to a third party.
D. provide an effective countermeasure to threats.
B. Indemnity agreements serve to reduce financial impacts by providing compensation for adverse events in the scope of the agreement.
A. Indemnity agreements are not used to define service levels; they are provided by service level agreements.
C. Legal responsibility cannot be transferred by indemnity agreements or any other instrument.
D. Indemnity agreements are not a countermeasure to threats, but they can be considered a compensating control.
Residual risk can be determined by:
A. assessing remaining vulnerabilities.
B. performing a threat analysis.
C. conducting a risk assessment.
D. implementing risk transfer.
C. Regardless of whether risk is residual, it is determined by a risk assessment.
A. Determining remaining vulnerabilities after countermeasures are in place says nothing about threats; therefore, risk cannot be determined.
B. Risk cannot be determined by threat analysis alone
D. Transferring all risk is not relevant to determining residual risk.
Data owners are PRIMARILY responsible for creating risk mitigation strategies to address which of the following areas?
A. Platform security
B. Entitlement changes
C. Intrusion detection
D. Antivirus controls
B. Data owners are concerned with, and responsible for, who has access to their resources; therefore, they need to be concerned with the strategy of how to mitigate risk of data resource usage.
A. Platform security is the responsibility of IT.
C. Intrusion detection is the responsibility of IT.
D. Antivirus controls are typically IT security concerns.
A risk analysis should:
A. limit the scope to a benchmark of similar companies.
B. assume an equal degree of protection for all assets.
C. address the potential size and likelihood of loss.
D. give more weight to the likelihood versus the size of the loss.
C. A risk analysis deals with the potential size and likelihood of loss.
A. A risk analysis would not normally consider the benchmark of similar companies as providing relevant information other than for comparison purposes.
B. Assuming an equal degree of protection would be rational only in the rare event that all assets are similar in sensitivity and criticality.
D. Because the likelihood determines (on an annualized basis) the size of the loss, both elements must be considered in the calculation.
Which of the following is the FIRST step in selecting the appropriate controls to be implemented in a new business application?
A. Business impact analysis
B. Cost-benefit analysis
C. Return on investment analysis
D. Risk assessment
D. It is necessary to first consider the risk and determine whether it is acceptable to the enterprise. Risk assessment can identify threats and vulnerabilities and calculate the risk. Controls are evaluated by comparing the cost of the control against the potential impact if the risk were exploited.
A. If the risk is determined to be unacceptable, a business impact analysis (BIA) can be used to determine the level of mitigation necessary.
B. A cost-benefit analysis can be used to determine whether mitigation cost is appropriate, considering the potential impact after a BIA has been performed.
C. Return on investment analysis focuses on the business value of the control compared to its cost over time.
When implementing an intrusion detection system for Internet traffic, the information security manager should recommend that it be placed:
A. outside the firewall.
B. on the firewall server.
C. on a screened subnet.
D. on the external router.
C. An IDS should be placed on a screened subnet, which is a demilitarized zone.
A. Placing an intrusion detection system (IDS) on the Internet side of the firewall is not usually advised (except to assess the traffic hitting the firewall) because the system will generate alerts on all malicious traffic—even though most traffic will be stopped by the firewall and never reach the internal network.
B. Because firewalls should be installed on hardened servers with minimal services enabled, it would be inappropriate to install an IDS on the same physical device.
D. If placing it on the external router were feasible, it would not be advised (except to assess the traffic hitting the firewall) because the system will generate alerts on all malicious traffic—even though most traffic will be stopped by the firewall and never reach the internal network.
Which of the following is the BEST metric for evaluating the effectiveness of security awareness training? The number of:
A. password resets
B. reported incidents
C. incidents resolved
D. access rule violations
B. Reported incidents will provide an indicator of the awareness level of staff. An increase in reported incidents could indicate that the staff is paying more attention to security.
A. Password resets may or may not have anything to do with awareness levels.
C. The number of incidents resolved may not correlate to staff awareness.
D. Access rule violations may or may not have anything to do with awareness levels.
Security monitoring mechanisms should PRIMARILY:
A. focus on business-critical information.
B. assist owners to manage and control risk.
C. focus on detecting network intrusions.
D. record all security violations.
A. Security monitoring must focus on business-critical information to remain effectively usable by and credible to business users.
B. Control risk is the possibility that controls would not detect an incident or error condition and, therefore, is not a correct answer because monitoring would not directly assist in managing this risk.
C. Network intrusions are not the only focus of monitoring mechanisms.
D. Although ideally all security violations should be recorded, this is only one objective of security monitoring.
When contracting with an outsourcer to provide security administration, the MOST important contractual element is the:
A. right-to-terminate clause.
B. limitations of liability.
C. service level agreement.
D. financial penalties clause.
C. SLAs provide metrics to which outsourcing firms can be held accountable and will typically cover the other choices as well.
A. Right to terminate is usually a part of the service level agreement (SLA) that can be invoked on failure of the outsourcer to meet the terms of the SLA.
B. The element of limitations of liability is also typically covered as a part of the SLA.
D. Financial penalties are covered by the SLA in the event of failure of performance as specified in the SLA.
Which of the following is MOST effective in preventing security weaknesses in operating systems?
A. Patch management
B. Change management
C. Security baselines
D. Configuration management
A. Patch management is a preventive control in that it corrects discovered weaknesses by applying a patch to the original program code that eliminates the weakness preventing exploitation.
B. Change management controls the process of introducing changes to systems that may introduce new vulnerabilities.
C. Security baselines provide minimum recommended settings to provide a consistent minimum level of security across the enterprise.
D. Configuration management ensures that incorrect configuration does not result in increased risk and controls the updates to the production environment.
Which of the following is the MOST effective solution for preventing internal users from modifying sensitive and classified information?
A. Baseline security standards
B. System access violation logs
C. Role-based access control
D. Background investigations
C. Role-based access control helps ensure that users have access only to files and systems appropriate for their job role and is a preventive control.
A. Baseline security standards may require access controls, but alone do not prevent unauthorized access.
B. Violation logs are detective and do not prevent unauthorized access.
D. Background checks are not a preventive control although they may be predictive based on past events.
Which of the following is the MOST important consideration when implementing an intrusion detection system?
A. Tuning
B. Patching
C. Encryption
D. Packet filtering
A. If an intrusion detection system (IDS) is not properly tuned, it will generate an unacceptable number of false positives and/or fail to sound an alarm when an actual attack is underway.
B. Patching is more related to system hardening and typically a part of maintenance activities.
C. Encryption is not a significant consideration when implementing an IDS.
D. Packet filtering is not used in an IDS.
Which of the following practices is BEST used to remove system access for contractors and other temporary users when it is no longer required?
A. Log all account usage and send regular reports to their managers.
B. Establish predetermined automatic expiration dates.
C. Require managers to email the security department when the user leaves.
D. Ensure that each individual has signed a security acknowledgment.
B. Predetermined expiration dates that automatically remove access are the most effective means of removing systems access for temporary users.
A. Logging account usage does nothing to remove access for temporary employees.
C. Reliance on managers to promptly send in termination notices cannot always be counted on and by itself does not ensure access termination.
D. Requiring each individual to sign a security acknowledgment would have little effect in this case.
Which of the following is MOST important for a successful information security program?
A. Adequate training on emerging security technologies
B. Open communication with key process owners
C. Adequate policies, standards and procedures
D. Executive management commitment
D. Sufficient executive management support is the most important factor for the success of an information security program.
A. Adequate training on new technologies is one of many requirements for an effective security program, but it is not as crucial as management support.
B. Open communication with process owners is an important element, but by itself it is not sufficient to ensure a successful program.
C. Adequate policies, standards and procedures are essential, but they will not be effective absent management support for adequate resources and enforcement.
An enterprise is implementing an information security program. During which phase should metrics be established to assess the effectiveness of the program over time?
A. Testing
B. Initiation
C. Design
D. Development
C. In the design phase, security checkpoints are defined and a test plan is developed.
A. The testing phase is too late because the system has already been developed and is in production testing.
B. In the initiation phase, the basic security objective of the project is acknowledged, but it is premature to consider where security checkpoints should be located in the development of a test plan.
D. Development is the coding phase and is too late to consider security test points and test plans.
The PRIMARY goal of a post-incident review is to:
A. gather evidence for subsequent legal action.
B. identify individuals who failed to take appropriate action.
C. prepare a report on the incident for management.
D. derive ways to improve the response process.
D. The primary goal of a post-incident review is to derive ways in which the incident response process can be improved.
A. Forensic evidence should have been gathered earlier in the process.
B. A post-incident review should not focus on finding and punishing individuals who did not take appropriate action or learning the identity of the attacker.
C. Although a post-incident review can be used to prepare a report/presentation to management, it is not the primary goal.
Which of the following is the MOST appropriate quality that an incident handler should possess?
A. Presentation skills for management report
B. Ability to follow policy and procedures
C. Integrity in all actions D. Ability to cope with stress
D. Incident handlers work in high-stress environments when dealing with incidents. Incorrect decisions are likely made if the person is unable to cope with stress; thus, the primary quality of incident handlers is to cope with stress.
A. Presentation skills are useful for preparing management reports but not the most essential
quality.
B. The ability to follow policy and procedures is important, but incidents are unanticipated
and chaotic. It is likely that there are no specific policies or procedures to deal with them, and
if the individual cannot cope with the stress of an incident, the ability is of little value.
C. Integrity is an essential quality, but if an employee lacks it, they probably should not be
employed by the enterprise.
What is the PRIMARY reason for conducting triage?
A. To prioritize limited resources when handling incidents
B. To align with mandatory process steps in the incident handling process
C. To mitigate the chance of an incident occurring
D. To detect an incident before it can spread further
A. The primary reason for conducting triage is that incident handling resources are limited, and they must be used to the greatest benefit. With categorization, prioritization and assignment of incidents based on their criticality, resources can be allocated more efficiently.
B. Triage is not generally considered a mandatory process in incident handling.
C. Triage does not mitigate an incident, but applies available resources most effectively to address the impact.
D. Triage does not serve to detect incidents.
Which of the following is MOST important when deciding whether to build an alternate facility or subscribe to a hot site operated by a third party?
A. Cost to rebuild information processing facilities
B. Incremental daily cost of losing different systems
C. Location and cost of commercial recovery facilities
D. Estimated annual loss expectancy from key risk
C. The decision whether to build an alternate facility or rent hot site facilities from a third party should be based entirely on business decisions of cost and ensuring the location is not susceptible to the same environmental risk as the primary facility.
A. The cost of rebuilding the primary processing facility is not a factor in choosing an alternate recovery site.
B. The daily cost of losing systems is the same whether the alternate site is built or rented.
D. Annual loss expectancy is not a factor in choosing to build or rent an alternate site.
Which of the following documents should be contained in a computer incident response team manual?
A. Risk assessment
B. Severity criteria
C. Employee phone directory
D. Table of all backup files
B. Severity criteria will remain relatively static and is the only one of the choices that is appropriate for the manual. The other choices will change frequently, and it would not make sense to reprint the manual every time phone numbers or backup files change.
A. Risk assessments would be available to the response team. However, they typically change at least annually, so it would not make sense to include them in the manual.
C. A phone directory will change frequently and would not be included in the manual.
D. A table of backup files would typically be very large and change frequently and would not be included in the manual.
Which of the following types of insurance coverage would protect an enterprise against dishonest or fraudulent behavior by its own employees?
A. Fidelity
B. Business interruption
C. Valuable papers and records
D. Business continuity
A. Fidelity coverage means insurance coverage against loss from dishonesty or fraud by employees.
B. Business interruption insurance protects against losses from events that prevent the business from operating.
C. Valuable papers and records insurance protects against the costs associated with the destruction of business records due to fire, flood or other incident.
D. Business continuity insurance is similar to business interruption coverage, but generally provides broader protection.
Which of the following practices would BEST ensure the adequacy of a disaster recovery plan?
A. Regular reviews of recovery plan information
B. Tabletop walkthrough of disaster recovery plans
C. Regular recovery exercises using expert personnel
D. Regular audits of disaster recovery facilities
A. The most common failure of disaster recovery plans is a lack of maintaining the current essential operational information.
B. Tabletop walkthroughs are useful only if the information about systems and versions is current and up to date.
C. Recovery exercises are critical for testing plans and procedures, but expert personnel have the knowledge to recover systems without using the plans and written procedures, which makes the recovery test less useful because there is no assurance that in a real disaster those individuals would be available.
D. Audits can be helpful, but they are typically infrequent and use sampling; therefore, they provide limited and only occasional assurance that information in recovery plans is current and up to date.
Which of the following procedures would provide the BEST protection if an intruder or malicious program has gained super user (e.g., root) access to a system?
A. Prevent the system administrator(s) from accessing the system pending investigation of the incident.
B. Inspect the system and intrusion detection output to identify all changes and then undo them.
C. Rebuild the system using original media.
D. Change all passwords, then resume normal operations.
C. If someone, or a malicious program, gains superuser privileges to a system without authorization, the enterprise never really knows what the perpetrator or program has done to the system. The only way to assure the integrity of the system is to wipe it clean by either performing a low-level format on the hard disk or replacing it with a new one (usually after making a bit copy backup for the purpose of further analysis and to prevent the destruction of data that may not exist elsewhere) and starting over again by reinstalling the operating system and applications using original media.
A. Preventing access by system administrator(s) provides no protection and does nothing to restore the system.
B. Root access makes it possible to initiate changes that are difficult or impossible to locate and is not an acceptable choice to resolve the issue.
D. Changing passwords provides no protections against any malicious changes made to the system.
Which of the following is likely to be the MOST significant challenge when developing an incident management plan?
A. Misalignment between plan and organizational goals
B. Implementation of log centralization, correlation and event tracking
C. Development of incident metrics
D. Lack of management support and organizational consensus
D. Getting senior management buy-in is often difficult, but it is the necessary first step to move forward with any incident management plan.
A. The incident management plan is a subset of the security strategy, which already aligns to organizational goals and, therefore, does not represent a major challenge.
B. Implementation of log centralization, correlation and event tracking is required, but it is not the most significant challenge.
C. Incident metrics must be developed, but they are straightforward and not a significant challenge.
If a forensics copy of a hard drive is needed, which of the following would be the MOST defensible from a legal standpoint if used?
A. A compressed copy of all contents of the hard drive
B. A copy that includes all files and directories
C. A bit-by-bit copy of all data
D. An encrypted copy of all contents of the hard drive
C. There is no alternative to making a bit-by-bit copy. For legally sufficient evidence, only a bit copy will result in a true image of the hard drive.
A. Whether a copy is compressed is irrelevant, and a straight copy operation will not include everything on the hard disk that is not identified by the operating system as a standard file.
B. A copy of all files and directories will not be an image of the hard disk and will fail to copy a variety of data, including data between the end of a file and the end of the disk sector (slack space) and deleted files that have not been overwritten.
D. Whether the data are encrypted is not relevant, and copying all files and folders will miss certain data such as data between the end of a file and the end of the disk sector (slack space).