Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA Exam CAS-004 Topic 4 Question 56 Discussion

Actual exam question for CompTIA's CAS-004 exam
Question #: 56
Topic #: 4
[All CAS-004 Questions]

During a recent security incident investigation, a security analyst mistakenly turned off the infected machine prior to consulting with a forensic analyst. upon rebooting the machine, a malicious script that

was running as a background process was no longer present. As a result, potentially useful evidence was lost. Which of the following should the security analyst have followed?

Show Suggested Answer Hide Answer
Suggested Answer: A

A legal hold is a process by which an organization instructs its employees or other relevant parties to preserve specific data for potential litigation. A legal hold is triggered when litigation is reasonably anticipated, such as when law enforcement officials inform an organization that an investigation has begun. The first step the organization should take is to initiate a legal hold to ensure that relevant evidence is not deleted, destroyed, or altered. A legal hold also demonstrates the organization's good faith and compliance with its duty to preserve evidence. Verified Reference:

https://percipient.co/litigation-hold-triggers-and-the-duty-to-preserve-evidence/


Contribute your Thoughts:

Glory
2 days ago
Yes, the order of volatility ensures that the most volatile evidence is collected first to prevent data loss.
upvoted 0 times
...
Bettye
3 days ago
I agree with Cassandra, the order of volatility is important in preserving evidence.
upvoted 0 times
...
Cassandra
5 days ago
The security analyst should have followed the order of volatility.
upvoted 0 times
...

Save Cancel