Question 1 of 30
In a corporate environment, a security analyst is tasked with collecting evidence from a compromised server suspected of being involved in a data breach. The analyst must ensure that the evidence collection process adheres to legal and regulatory standards while maintaining the integrity of the data. Which of the following best describes the most critical step the analyst should take before initiating the evidence collection process?
Create a forensic image of the server's hard drive to preserve the original data.
Document the server's current state and running processes without taking any action.
Disconnect the server from the network to prevent further data loss.
Notify the legal department to obtain permission for evidence collection.

Preparing for CISCO 500-651 Security Architecture for Systems Engineer (SASE)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free