ISC2 CISSP Practice Question

During a digital forensics investigation into a server suspected of hosting illicit materials, an investigator needs to collect evidence from the primary storage drive. To best ensure the collected data's integrity and admissibility in legal proceedings, which of the following actions should be performed?

  • Boot the server using a forensic live CD and copy all user-generated files to an external drive.

  • Remove the drive from the server and connect it to a forensic workstation to run a data recovery tool.

  • Create a bit-for-bit copy of the original drive onto sterile media and calculate cryptographic hashes of both.

  • Document the system time from the BIOS and take photographs of the running processes on the screen.

ISC2 CISSP
Security Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot