ISO/IEC 27043:2015 - Incident Investigation Foundation Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

Consider a scenario where a critical data breach has occurred within a financial institution, and digital forensic investigators are tasked with collecting evidence from compromised servers. According to the principles outlined in ISO/IEC 27043:2015, which of the following actions best exemplifies the foundational requirement for maintaining the integrity and authenticity of the collected digital evidence throughout the investigation process?

Creating a bit-for-bit forensic image of the affected storage media and verifying its integrity using a cryptographic hash function, while meticulously documenting all handling procedures in a chain of custody log.
Immediately transferring the original storage media to a secure off-site location for analysis by a third-party vendor without creating an intermediate forensic copy.
Conducting an initial visual inspection of the server hardware for any obvious physical tampering before powering it on for data extraction.
Relying solely on system logs and event viewer entries to reconstruct the timeline of the incident, without directly acquiring data from the compromised storage devices.

About the ISO/IEC 27043:2015 - Incident Investigation Foundation Certification

These free practice questions are designed to help you assess your readiness for the ISO/IEC 27043:2015 - Incident Investigation Foundation exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.