Question 1 of 30
Consider a scenario where a critical data breach has occurred within a financial institution, and digital forensic investigators are tasked with collecting evidence from compromised servers. According to the principles outlined in ISO/IEC 27043:2015, which of the following actions best exemplifies the foundational requirement for maintaining the integrity and authenticity of the collected digital evidence throughout the investigation process?
Creating a bit-for-bit forensic image of the affected storage media and verifying its integrity using a cryptographic hash function, while meticulously documenting all handling procedures in a chain of custody log.
Immediately transferring the original storage media to a secure off-site location for analysis by a third-party vendor without creating an intermediate forensic copy.
Conducting an initial visual inspection of the server hardware for any obvious physical tampering before powering it on for data extraction.
Relying solely on system logs and event viewer entries to reconstruct the timeline of the incident, without directly acquiring data from the compromised storage devices.

Preparing for ISO/IEC 27043:2015 - Incident Investigation Foundation? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free