اختبار شهادة محلل الأمن السيبراني CompTIA CySA+

السؤال 596 من 1040

كل الأسئلة

During an incident response procedure, a security analyst acquired the needed evidence from the hard drive of a compromised machine. Which of the following actions should the analyst perform next to ensure the data integrity of the evidence?

الخيارات

  • A Generate hashes for each file from the hard drive.
  • B Create a chain of custody document.
  • C Determine a timeline of events using correct time synchronization.
  • D Keep the cloned hard drive in a safe place.

النقاشات

لا توجد نقاشات منشورة لهذا السؤال حالياً.