Topic 21 Practice Test 1 covers Incident Response for CompTIA Security+ SY0-701 and maps to objective 4.8: Explain appropriate incident response activities. For broader exam preparation, review the CompTIA Security+ Exam Dumps. Every option includes focused editorial reasoning explaining both the concept and its fit to the scenario.
Question 1
To decide whether an event is an incident and understand what happened, which security approach should be selected?
- Analysis
- Preparation
- Root cause analysis
- Recovery
Correct Answer: A
Correct Answer
Answer A is correct because Analysis means investigation of evidence to determine scope, cause, severity, and likely impact. The requirement maps directly to this function, whereas Root cause analysis is aimed at structured effort to identify the underlying condition that allowed an incident to occur.
Incorrect Answers
Answer B is incorrect because Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs. This could be appropriate elsewhere, but the required function is investigation of evidence to determine scope, cause, severity, and likely impact; that makes Analysis the precise choice.
Answer C is incorrect because Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur. The key mismatch is functional: Analysis addresses investigation of evidence to determine scope, cause, severity, and likely impact, the need stated by the question.
Answer D is incorrect because Recovery refers to restoration of systems and business services to normal operation with appropriate validation and monitoring. The key mismatch is functional: Analysis addresses investigation of evidence to determine scope, cause, severity, and likely impact, the need stated by the question.
Question 2
Which term describes protection of evidence from alteration, loss, or unauthorized access?
- Root cause analysis
- Evidence preservation
- Eradication
- Simulation exercise
Correct Answer: B
Correct Answer
Answer B is correct because Evidence preservation means protection of evidence from alteration, loss, or unauthorized access. That is the function the question is testing. Simulation exercise would instead be used for practice activity that imitates a more realistic incident and response environment.
Incorrect Answers
Answer A is incorrect because Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur. The scenario instead requires protection of evidence from alteration, loss, or unauthorized access, which is why Evidence preservation is the better answer; this option serves the different function defined above.
Answer C is incorrect because Eradication refers to removal of malware, attacker persistence, compromised accounts, or root causes from the environment. This could be appropriate elsewhere, but the required function is protection of evidence from alteration, loss, or unauthorized access; that makes Evidence preservation the precise choice.
Answer D is incorrect because Simulation exercise refers to practice activity that imitates a more realistic incident and response environment. That concept can be valid in another scenario, but this question is testing protection of evidence from alteration, loss, or unauthorized access; Evidence preservation therefore fits the requirement more directly.
Question 3
The control set for an incident-response exercise must address both education that teaches responders and stakeholders their responsibilities and procedures and instruction to preserve relevant information because of litigation, investigation, or legal obligation. Which TWO choices map directly to those needs? Choose TWO.
- Legal hold
- Preparation
- Eradication
- Incident-response training
- Recovery
Correct Answers: A, D
Correct Answers
Answer A is correct because Legal hold means instruction to preserve relevant information because of litigation, investigation, or legal obligation. One required function is exactly what this option provides. Recovery may be useful elsewhere, but it is used for restoration of systems and business services to normal operation with appropriate validation and monitoring.
Answer D is correct because Incident-response training means education that teaches responders and stakeholders their responsibilities and procedures. This option satisfies a specific requirement in the stem; Preparation serves the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs and therefore is not interchangeable with it.
Incorrect Answers
Answer B is incorrect because Preparation means the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs. The scenario calls for Legal hold, Incident-response training. Selecting this option would leave one of those required functions uncovered.
Answer C is incorrect because Eradication means removal of malware, attacker persistence, compromised accounts, or root causes from the environment. The fixed-count answer set is Legal hold, Incident-response training; this option does not fill one of those named functions.
Answer E is incorrect because Recovery means restoration of systems and business services to normal operation with appropriate validation and monitoring. The question requires exactly 2 selections: Legal hold, Incident-response training. This option falls outside that required set. For example, Incident-response training is required for education that teaches responders and stakeholders their responsibilities and procedures.
Question 4
Which term describes instruction to preserve relevant information because of litigation, investigation, or legal obligation?
- Eradication
- Incident-response training
- Analysis
- Legal hold
Correct Answer: D
Correct Answer
Answer D is correct because Legal hold means instruction to preserve relevant information because of litigation, investigation, or legal obligation. The requirement maps directly to this function, whereas Incident-response training is aimed at education that teaches responders and stakeholders their responsibilities and procedures.
Incorrect Answers
Answer A is incorrect because Eradication refers to removal of malware, attacker persistence, compromised accounts, or root causes from the environment. That concept can be valid in another scenario, but this question is testing instruction to preserve relevant information because of litigation, investigation, or legal obligation; Legal hold therefore fits the requirement more directly.
Answer B is incorrect because Incident-response training refers to education that teaches responders and stakeholders their responsibilities and procedures. That concept can be valid in another scenario, but this question is testing instruction to preserve relevant information because of litigation, investigation, or legal obligation; Legal hold therefore fits the requirement more directly.
Answer C is incorrect because Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact. That concept can be valid in another scenario, but this question is testing instruction to preserve relevant information because of litigation, investigation, or legal obligation; Legal hold therefore fits the requirement more directly.
Question 5
To test decisions, communications, and plan completeness without affecting production, which security approach should be selected?
- Analysis
- Containment
- Root cause analysis
- Tabletop exercise
Correct Answer: D
Correct Answer
Answer D is correct because Tabletop exercise means discussion-based walkthrough of an incident scenario. That is the function the question is testing. Containment would instead be used for actions that limit spread or ongoing damage while preserving the ability to investigate.
Incorrect Answers
Answer A is incorrect because Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact. The key mismatch is functional: Tabletop exercise addresses discussion-based walkthrough of an incident scenario, the need stated by the question.
Answer B is incorrect because Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate. The scenario instead requires discussion-based walkthrough of an incident scenario, which is why Tabletop exercise is the better answer; this option serves the different function defined above.
Answer C is incorrect because Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur. The question is not asking for this function. It is testing discussion-based walkthrough of an incident scenario, so Tabletop exercise is the stronger fit.
Question 6
Which term describes removal of malware, attacker persistence, compromised accounts, or root causes from the environment?
- Containment
- Digital forensics
- Eradication
- Analysis
Correct Answer: C
Correct Answer
Answer C is correct because Eradication means removal of malware, attacker persistence, compromised accounts, or root causes from the environment. The requirement maps directly to this function, whereas Digital forensics is aimed at disciplined collection, preservation, examination, and reporting of digital evidence.
Incorrect Answers
Answer A is incorrect because Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate. The scenario instead requires removal of malware, attacker persistence, compromised accounts, or root causes from the environment, which is why Eradication is the better answer; this option serves the different function defined above.
Answer B is incorrect because Digital forensics refers to disciplined collection, preservation, examination, and reporting of digital evidence. This could be appropriate elsewhere, but the required function is removal of malware, attacker persistence, compromised accounts, or root causes from the environment; that makes Eradication the precise choice.
Answer D is incorrect because Analysis refers to investigation of evidence to determine scope, cause, severity, and likely impact. That concept can be valid in another scenario, but this question is testing removal of malware, attacker persistence, compromised accounts, or root causes from the environment; Eradication therefore fits the requirement more directly.
Question 7
Which term describes investigation of evidence to determine scope, cause, severity, and likely impact?
- Lessons learned
- Analysis
- Forensic acquisition
- Tabletop exercise
Correct Answer: B
Correct Answer
Answer B is correct because Analysis means investigation of evidence to determine scope, cause, severity, and likely impact. That is the function the question is testing. Lessons learned would instead be used for post-incident review of what happened, what worked, what failed, and what should change.
Incorrect Answers
Answer A is incorrect because Lessons learned refers to post-incident review of what happened, what worked, what failed, and what should change. This could be appropriate elsewhere, but the required function is investigation of evidence to determine scope, cause, severity, and likely impact; that makes Analysis the precise choice.
Answer C is incorrect because Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data. The concept is valid, but it does not match this stem. The required function is investigation of evidence to determine scope, cause, severity, and likely impact, which maps to Analysis.
Answer D is incorrect because Tabletop exercise refers to discussion-based walkthrough of an incident scenario. The scenario instead requires investigation of evidence to determine scope, cause, severity, and likely impact, which is why Analysis is the better answer; this option serves the different function defined above.
Question 8
Reviewers working through an incident-response exercise identify three separate needs: actions that limit spread or ongoing damage while preserving the ability to investigate; practice activity that imitates a more realistic incident and response environment; disciplined collection, preservation, examination, and reporting of digital evidence. Which THREE choices map to those needs? Choose THREE.
- Digital forensics
- Recovery
- Root cause analysis
- Containment
- Detection
- Simulation exercise
Correct Answers: A, D, F
Correct Answers
Answer A is correct because Digital forensics means disciplined collection, preservation, examination, and reporting of digital evidence. The fixed-count item needs this function in the answer set. Root cause analysis covers structured effort to identify the underlying condition that allowed an incident to occur, a different requirement.
Answer D is correct because Containment means actions that limit spread or ongoing damage while preserving the ability to investigate. It belongs in the fixed-count answer set because it covers one of the stated requirements. Recovery instead serves restoration of systems and business services to normal operation with appropriate validation and monitoring and cannot replace this function.
Answer F is correct because Simulation exercise means practice activity that imitates a more realistic incident and response environment. The fixed-count item needs this function in the answer set. Recovery covers restoration of systems and business services to normal operation with appropriate validation and monitoring, a different requirement.
Incorrect Answers
Answer B is incorrect because Recovery means restoration of systems and business services to normal operation with appropriate validation and monitoring. The fixed-count answer set is Containment, Digital forensics, Simulation exercise; this option does not fill one of those named functions.
Answer C is incorrect because Root cause analysis means structured effort to identify the underlying condition that allowed an incident to occur. The scenario calls for Containment, Digital forensics, Simulation exercise. Selecting this option would leave one of those required functions uncovered.
Answer E is incorrect because Detection means recognition that a potentially security-relevant event has occurred. The question requires exactly 3 selections: Containment, Digital forensics, Simulation exercise. This option falls outside that required set. For example, Containment is required for actions that limit spread or ongoing damage while preserving the ability to investigate.
Question 9
Which term describes education that teaches responders and stakeholders their responsibilities and procedures?
- Root cause analysis
- Incident-response training
- Legal hold
- Preparation
Correct Answer: B
Correct Answer
Answer B is correct because Incident-response training means education that teaches responders and stakeholders their responsibilities and procedures. This matches the requirement as written. Preparation can be valid in another context, but it is used for the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.
Incorrect Answers
Answer A is incorrect because Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur. The concept is valid, but it does not match this stem. The required function is education that teaches responders and stakeholders their responsibilities and procedures, which maps to Incident-response training.
Answer C is incorrect because Legal hold refers to instruction to preserve relevant information because of litigation, investigation, or legal obligation. That concept can be valid in another scenario, but this question is testing education that teaches responders and stakeholders their responsibilities and procedures; Incident-response training therefore fits the requirement more directly.
Answer D is incorrect because Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs. The key mismatch is functional: Incident-response training addresses education that teaches responders and stakeholders their responsibilities and procedures, the need stated by the question.
Question 10
Which term describes documentation showing who collected, handled, transferred, stored, and examined evidence?
- Tabletop exercise
- Root cause analysis
- Chain of custody
- Containment
Correct Answer: C
Correct Answer
Answer C is correct because Chain of custody means documentation showing who collected, handled, transferred, stored, and examined evidence. The requirement maps directly to this function, whereas Root cause analysis is aimed at structured effort to identify the underlying condition that allowed an incident to occur.
Incorrect Answers
Answer A is incorrect because Tabletop exercise refers to discussion-based walkthrough of an incident scenario. The question is not asking for this function. It is testing documentation showing who collected, handled, transferred, stored, and examined evidence, so Chain of custody is the stronger fit.
Answer B is incorrect because Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur. This could be appropriate elsewhere, but the required function is documentation showing who collected, handled, transferred, stored, and examined evidence; that makes Chain of custody the precise choice.
Answer D is incorrect because Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate. The question is not asking for this function. It is testing documentation showing who collected, handled, transferred, stored, and examined evidence, so Chain of custody is the stronger fit.
Question 11
The control set for an incident-response exercise must address both instruction to preserve relevant information because of litigation, investigation, or legal obligation and identification, preservation, collection, and production of electronically stored information for legal proceedings. Which TWO choices map directly to those needs? Choose TWO.
- Recovery
- Legal hold
- Chain of custody
- Digital forensics
- E-discovery
Correct Answers: B, E
Correct Answers
Answer B is correct because Legal hold means instruction to preserve relevant information because of litigation, investigation, or legal obligation. One required function is exactly what this option provides. Chain of custody may be useful elsewhere, but it is used for documentation showing who collected, handled, transferred, stored, and examined evidence.
Answer E is correct because E-discovery means identification, preservation, collection, and production of electronically stored information for legal proceedings. It belongs in the fixed-count answer set because it covers one of the stated requirements. Chain of custody instead serves documentation showing who collected, handled, transferred, stored, and examined evidence and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Recovery means restoration of systems and business services to normal operation with appropriate validation and monitoring. The fixed-count answer set is Legal hold, E-discovery; this option does not fill one of those named functions.
Answer C is incorrect because Chain of custody means documentation showing who collected, handled, transferred, stored, and examined evidence. The scenario calls for Legal hold, E-discovery. Selecting this option would leave one of those required functions uncovered. For example, E-discovery is required for identification, preservation, collection, and production of electronically stored information for legal proceedings.
Answer D is incorrect because Digital forensics means disciplined collection, preservation, examination, and reporting of digital evidence. Every answer slot must map to a stated requirement. The correct set is Legal hold, E-discovery, so this option cannot replace one of those selections.
Question 12
Which term describes discussion-based walkthrough of an incident scenario?
- Containment
- Preparation
- Tabletop exercise
- Simulation exercise
Correct Answer: C
Correct Answer
Answer C is correct because Tabletop exercise means discussion-based walkthrough of an incident scenario. This is the precise fit for the scenario. Preparation serves the different purpose of the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.
Incorrect Answers
Answer A is incorrect because Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate. The key mismatch is functional: Tabletop exercise addresses discussion-based walkthrough of an incident scenario, the need stated by the question.
Answer B is incorrect because Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs. The question is not asking for this function. It is testing discussion-based walkthrough of an incident scenario, so Tabletop exercise is the stronger fit.
Answer D is incorrect because Simulation exercise refers to practice activity that imitates a more realistic incident and response environment. The concept is valid, but it does not match this stem. The required function is discussion-based walkthrough of an incident scenario, which maps to Tabletop exercise.
Question 13
Which term describes proactive search for signs of attackers or compromise not already identified by routine detections?
- Threat hunting
- Eradication
- Incident-response training
- Root cause analysis
Correct Answer: A
Correct Answer
Answer A is correct because Threat hunting means proactive search for signs of attackers or compromise not already identified by routine detections. This matches the requirement as written. Eradication can be valid in another context, but it is used for removal of malware, attacker persistence, compromised accounts, or root causes from the environment.
Incorrect Answers
Answer B is incorrect because Eradication refers to removal of malware, attacker persistence, compromised accounts, or root causes from the environment. The scenario instead requires proactive search for signs of attackers or compromise not already identified by routine detections, which is why Threat hunting is the better answer; this option serves the different function defined above.
Answer C is incorrect because Incident-response training refers to education that teaches responders and stakeholders their responsibilities and procedures. That concept can be valid in another scenario, but this question is testing proactive search for signs of attackers or compromise not already identified by routine detections; Threat hunting therefore fits the requirement more directly.
Answer D is incorrect because Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur. The concept is valid, but it does not match this stem. The required function is proactive search for signs of attackers or compromise not already identified by routine detections, which maps to Threat hunting.
Question 14
To return to production safely after eradication, which security approach should be selected?
- Recovery
- Tabletop exercise
- Legal hold
- Containment
Correct Answer: A
Correct Answer
Answer A is correct because Recovery means restoration of systems and business services to normal operation with appropriate validation and monitoring. The deciding point is functional fit: this option covers the stated need, while Containment addresses actions that limit spread or ongoing damage while preserving the ability to investigate.
Incorrect Answers
Answer B is incorrect because Tabletop exercise refers to discussion-based walkthrough of an incident scenario. The question is not asking for this function. It is testing restoration of systems and business services to normal operation with appropriate validation and monitoring, so Recovery is the stronger fit.
Answer C is incorrect because Legal hold refers to instruction to preserve relevant information because of litigation, investigation, or legal obligation. That concept can be valid in another scenario, but this question is testing restoration of systems and business services to normal operation with appropriate validation and monitoring; Recovery therefore fits the requirement more directly.
Answer D is incorrect because Containment refers to actions that limit spread or ongoing damage while preserving the ability to investigate. That concept can be valid in another scenario, but this question is testing restoration of systems and business services to normal operation with appropriate validation and monitoring; Recovery therefore fits the requirement more directly.
Question 15
To analyze evidence without unnecessarily modifying the source, which security approach should be selected?
- Root cause analysis
- E-discovery
- Incident-response training
- Forensic acquisition
Correct Answer: D
Correct Answer
Answer D is correct because Forensic acquisition means creation of a defensible copy of digital evidence using methods that preserve original data. That makes it the best answer here; Root cause analysis addresses structured effort to identify the underlying condition that allowed an incident to occur, not the function requested in the stem.
Incorrect Answers
Answer A is incorrect because Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur. The key mismatch is functional: Forensic acquisition addresses creation of a defensible copy of digital evidence using methods that preserve original data, the need stated by the question.
Answer B is incorrect because E-discovery refers to identification, preservation, collection, and production of electronically stored information for legal proceedings. The concept is valid, but it does not match this stem. The required function is creation of a defensible copy of digital evidence using methods that preserve original data, which maps to Forensic acquisition.
Answer C is incorrect because Incident-response training refers to education that teaches responders and stakeholders their responsibilities and procedures. The question is not asking for this function. It is testing creation of a defensible copy of digital evidence using methods that preserve original data, so Forensic acquisition is the stronger fit.
Question 16
A review during an incident-response exercise identifies two gaps. One requires structured effort to identify the underlying condition that allowed an incident to occur. The other requires proactive search for signs of attackers or compromise not already identified by routine detections. Which TWO options should be included in the remediation plan? Choose TWO.
- Threat hunting
- Tabletop exercise
- Forensic acquisition
- Recovery
- Root cause analysis
Correct Answers: A, E
Correct Answers
Answer A is correct because Threat hunting means proactive search for signs of attackers or compromise not already identified by routine detections. One required function is exactly what this option provides. Forensic acquisition may be useful elsewhere, but it is used for creation of a defensible copy of digital evidence using methods that preserve original data.
Answer E is correct because Root cause analysis means structured effort to identify the underlying condition that allowed an incident to occur. This option satisfies a specific requirement in the stem; Tabletop exercise serves discussion-based walkthrough of an incident scenario and therefore is not interchangeable with it.
Incorrect Answers
Answer B is incorrect because Tabletop exercise means discussion-based walkthrough of an incident scenario. The fixed-count answer set is Threat hunting, Root cause analysis; this option does not fill one of those named functions. For example, Root cause analysis is required for structured effort to identify the underlying condition that allowed an incident to occur.
Answer C is incorrect because Forensic acquisition means creation of a defensible copy of digital evidence using methods that preserve original data. Every answer slot must map to a stated requirement. The correct set is Threat hunting, Root cause analysis, so this option cannot replace one of those selections.
Answer D is incorrect because Recovery means restoration of systems and business services to normal operation with appropriate validation and monitoring. The question requires exactly 2 selections: Threat hunting, Root cause analysis. This option falls outside that required set.
Question 17
Which term describes creation of a defensible copy of digital evidence using methods that preserve original data?
- Lessons learned
- Incident-response training
- Forensic acquisition
- Preparation
Correct Answer: C
Correct Answer
Answer C is correct because Forensic acquisition means creation of a defensible copy of digital evidence using methods that preserve original data. That is the function the question is testing. Preparation would instead be used for the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs.
Incorrect Answers
Answer A is incorrect because Lessons learned refers to post-incident review of what happened, what worked, what failed, and what should change. The concept is valid, but it does not match this stem. The required function is creation of a defensible copy of digital evidence using methods that preserve original data, which maps to Forensic acquisition.
Answer B is incorrect because Incident-response training refers to education that teaches responders and stakeholders their responsibilities and procedures. The scenario instead requires creation of a defensible copy of digital evidence using methods that preserve original data, which is why Forensic acquisition is the better answer; this option serves the different function defined above.
Answer D is incorrect because Preparation refers to the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs. The question is not asking for this function. It is testing creation of a defensible copy of digital evidence using methods that preserve original data, so Forensic acquisition is the stronger fit.
Question 18
Two requirements remain open in an incident-response exercise: removal of malware, attacker persistence, compromised accounts, or root causes from the environment; practice activity that imitates a more realistic incident and response environment. Which TWO options close those specific gaps? Choose TWO.
- Evidence preservation
- Tabletop exercise
- Containment
- Simulation exercise
- Eradication
Correct Answers: D, E
Correct Answers
Answer D is correct because Simulation exercise means practice activity that imitates a more realistic incident and response environment. This option satisfies a specific requirement in the stem; Tabletop exercise serves discussion-based walkthrough of an incident scenario and therefore is not interchangeable with it.
Answer E is correct because Eradication means removal of malware, attacker persistence, compromised accounts, or root causes from the environment. It belongs in the fixed-count answer set because it covers one of the stated requirements. Containment instead serves actions that limit spread or ongoing damage while preserving the ability to investigate and cannot replace this function.
Incorrect Answers
Answer A is incorrect because Evidence preservation means protection of evidence from alteration, loss, or unauthorized access. Every answer slot must map to a stated requirement. The correct set is Simulation exercise, Eradication, so this option cannot replace one of those selections.
Answer B is incorrect because Tabletop exercise means discussion-based walkthrough of an incident scenario. The scenario calls for Simulation exercise, Eradication. Selecting this option would leave one of those required functions uncovered. For example, Simulation exercise is required for practice activity that imitates a more realistic incident and response environment.
Answer C is incorrect because Containment means actions that limit spread or ongoing damage while preserving the ability to investigate. The fixed-count answer set is Simulation exercise, Eradication; this option does not fill one of those named functions. For example, Eradication is required for removal of malware, attacker persistence, compromised accounts, or root causes from the environment.
Question 19
To demonstrate integrity and accountability for evidence handling, which security approach should be selected?
- Forensic acquisition
- Evidence preservation
- Root cause analysis
- Chain of custody
Correct Answer: D
Correct Answer
Answer D is correct because Chain of custody means documentation showing who collected, handled, transferred, stored, and examined evidence. The requirement maps directly to this function, whereas Evidence preservation is aimed at protection of evidence from alteration, loss, or unauthorized access.
Incorrect Answers
Answer A is incorrect because Forensic acquisition refers to creation of a defensible copy of digital evidence using methods that preserve original data. That concept can be valid in another scenario, but this question is testing documentation showing who collected, handled, transferred, stored, and examined evidence; Chain of custody therefore fits the requirement more directly.
Answer B is incorrect because Evidence preservation refers to protection of evidence from alteration, loss, or unauthorized access. That concept can be valid in another scenario, but this question is testing documentation showing who collected, handled, transferred, stored, and examined evidence; Chain of custody therefore fits the requirement more directly.
Answer C is incorrect because Root cause analysis refers to structured effort to identify the underlying condition that allowed an incident to occur. The concept is valid, but it does not match this stem. The required function is documentation showing who collected, handled, transferred, stored, and examined evidence, which maps to Chain of custody.
Question 20
An architect working on an incident-response exercise needs one capability that provides disciplined collection, preservation, examination, and reporting of digital evidence and another that provides instruction to preserve relevant information because of litigation, investigation, or legal obligation. Which TWO selections are the best match? Choose TWO.
- Digital forensics
- Evidence preservation
- E-discovery
- Preparation
- Legal hold
Correct Answers: A, E
Correct Answers
Answer A is correct because Digital forensics means disciplined collection, preservation, examination, and reporting of digital evidence. This option satisfies a specific requirement in the stem; Preparation serves the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs and therefore is not interchangeable with it.
Answer E is correct because Legal hold means instruction to preserve relevant information because of litigation, investigation, or legal obligation. It belongs in the fixed-count answer set because it covers one of the stated requirements. Evidence preservation instead serves protection of evidence from alteration, loss, or unauthorized access and cannot replace this function.
Incorrect Answers
Answer B is incorrect because Evidence preservation means protection of evidence from alteration, loss, or unauthorized access. The question requires exactly 2 selections: Digital forensics, Legal hold. This option falls outside that required set. For example, Digital forensics is required for disciplined collection, preservation, examination, and reporting of digital evidence.
Answer C is incorrect because E-discovery means identification, preservation, collection, and production of electronically stored information for legal proceedings. The scenario calls for Digital forensics, Legal hold. Selecting this option would leave one of those required functions uncovered. For example, Digital forensics is required for disciplined collection, preservation, examination, and reporting of digital evidence.
Answer D is incorrect because Preparation means the incident-response phase focused on plans, tools, access, roles, communications, and readiness before an incident occurs. The required choices are Digital forensics, Legal hold. Although this option is security-relevant, it does not satisfy one of the functions named in the stem.