The correct answer is to create a detailed initial report. This is the first and most crucial step in documenting an incident. It establishes the foundation for the entire incident response process and helps maintain the integrity of the investigation. The initial report should include the date, time, and nature of the incident, as well as any immediate observations or actions taken. This document becomes the starting point for the chain of custody, which is essential for potential legal proceedings.
While contacting law enforcement is important, it's not the first step in documentation. Similarly, creating a final report comes after the investigation is complete, not at the beginning. Deleting log files is never a correct action, as it destroys valuable evidence and violates proper incident response procedures.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What details should be included in a detailed initial report?
Open an interactive chat with Bash
Why is the initial report crucial for the incident response process?
Open an interactive chat with Bash
What is the chain of custody and why is it important in incident reporting?