Question 1 of 30
A cybersecurity analyst is investigating a potential data breach in a corporate network. During the forensic analysis, they discover a series of suspicious log entries indicating unauthorized access attempts to a sensitive database. The analyst needs to determine the best approach to preserve the integrity of the evidence while also ensuring compliance with legal standards. Which of the following actions should the analyst prioritize to maintain the chain of custody and ensure the admissibility of the evidence in court?
Create a bit-by-bit image of the affected storage device and document the imaging process meticulously.
Immediately delete the suspicious log entries to prevent further unauthorized access.
Analyze the logs directly on the affected system to gather real-time data about the breach.
Share the log files with external parties for a second opinion before taking any further action.

Preparing for CISCO 200-201 Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free