Question 1 of 30
The assessment process reveals a suspected insider threat involving the unauthorized exfiltration of sensitive customer data from a cloud-based customer relationship management (CRM) system. The security team has been alerted and needs to initiate an investigation to determine the scope of the breach and identify the responsible party. What is the most appropriate initial action to preserve the integrity of potential digital evidence?
Immediately create forensically sound, bit-for-bit images of the affected cloud storage volumes and associated server logs, meticulously documenting all steps, personnel, and timestamps involved in the imaging process.
Begin a live analysis of the CRM system's user activity logs and network traffic to identify suspicious patterns and potential data access points.
Request a full system restore from the most recent cloud backup to revert the system to a known good state and then investigate the logs from the restored environment.
Distribute the raw data files from the CRM system to the legal and HR departments for their initial review to expedite the investigation.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free