exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 312 discussion

Actual exam question from ISC's CISSP
Question #: 312
Topic #: 1
[All CISSP Questions]

Which of the following activities should a forensic examiner perform FIRST when determining the priority of digital evidence collection at a crime scene?

  • A. Gather physical evidence.
  • B. Assign responsibilities to personnel on the scene.
  • C. Establish a list of files to examine.
  • D. Establish order of volatility.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Loveguitar
Highly Voted 1 year, 4 months ago
Order of volatility is the first thing to consider
upvoted 12 times
jackdryan
8 months ago
D is correct
upvoted 1 times
...
...
stickerbush1970
Highly Voted 1 year, 3 months ago
Selected Answer: D
Agree with D.
upvoted 11 times
...
a_kto_to
Most Recent 2 months, 2 weeks ago
Selected Answer: D
In digital forensics, order of volatility refers to the sequence in which data should be collected based on how quickly it can change or disappear. Volatile data (e.g., RAM, running processes, network connections) must be captured first, as it may be lost when the system is powered down or altered. Establishing this order is critical to prioritizing evidence collection and preserving the integrity of the investigation.
upvoted 1 times
...
user009
9 months, 3 weeks ago
The correct answer is D. Establish order of volatility. Explanation: When determining the priority of digital evidence collection at a crime scene, a forensic examiner should first establish the order of volatility. The order of volatility refers to the sequence in which different types of digital evidence should be collected based on how easily they might be lost or altered. By establishing the order of volatility, the forensic examiner can prioritize the collection of the most volatile evidence, such as data stored in memory or cache, before it is lost or modified. Incorrect answers: B. Assign responsibilities to personnel on the scene: Assigning responsibilities to personnel is important for maintaining the integrity of the crime scene and ensuring a thorough investigation, but it is not the first step in prioritizing digital evidence collection.
upvoted 4 times
...
Ivanchun
1 year ago
Selected Answer: D
Vote D
upvoted 2 times
...
rdy4u
1 year, 2 months ago
Selected Answer: D
The idea is that you gather the most volatile data first– the data that has the potential for disappearing the most is what you want to gather very first thing. The data that could be around for a longer period of time, you at least have a little bit of time that you could wait before you have to gather that data before it disappears. So this order of volatility becomes very important.
upvoted 6 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...