ISO/IEC 27037:2012 - Digital Forensics First Responder Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A digital forensics first responder arrives at a scene where a suspect\'s laptop is found powered on and actively displaying a spreadsheet that appears to contain financial transaction records. The suspect is not present. Considering the principles outlined in ISO/IEC 27037:2012, what is the most appropriate initial action to preserve the integrity of potential digital evidence on this device?

Immediately power off the laptop to prevent further data modification and ensure a stable state for imaging.
Attempt to capture the contents of the Random Access Memory (RAM) before powering down the device.
Disconnect the laptop from any network connections to prevent remote wiping or data exfiltration.
Secure the laptop in an anti-static bag without altering its current powered-on state.

About the ISO/IEC 27037:2012 - Digital Forensics First Responder Certification

These free practice questions are designed to help you assess your readiness for the ISO/IEC 27037:2012 - Digital Forensics First Responder exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.