Certified Information Systems Auditor (CISA) — Question 818

Which of the following BEST protects evidence in a forensic investigation?

Answer options

Correct answer: C

Explanation

Creating an image of the affected system is the best way to preserve evidence, as it allows for a complete and exact copy of the data to be analyzed without altering the original information. Protecting hardware, powering down, or rebooting the system can result in data loss or corruption, making it harder to conduct a thorough investigation.