CompTIA CySA+ (CS0-003) — Question 190
Which of the following in the digital forensics process is considered a critical activity that often includes a graphical representation of process and operating system events?
Answer options
- A. Registry editing
- B. Network mapping
- C. Timeline analysis
- D. Write blocking
Correct answer: C
Explanation
The correct answer is C, as timeline analysis is crucial for visualizing the sequence of events and activities in digital forensics. Options A and B do not focus on the chronological representation of events, while D refers to a method of protecting data integrity rather than analyzing events.