While an employee is on vacation, suspicion arises that the employee has been involved in malicious activity on the network. The security engineer is concerned the investigation may need to continue after the employee returns to work. Given this concern, which of the following should the security engineer recommend to maintain the integrity of the investigation?
A) Create archival copies of all documents and communications related to the employee
B) Create a forensic image of network infrastructure devices
C) Create an image file of the employee's network drives and store it with hashes
D) Install a keylogger to capture the employee's communications and contacts
Correct Answer:
Verified
Q415: A Chief Information Security Officer (CISO) is
Q416: A network service on a production system
Q417: Staff members are reporting an unusual number
Q418: During a security event investigation, a junior
Q419: An organization is currently working with a
Q421: When implementing a penetration testing program, the
Q422: A security manager needed to protect a
Q423: A company is migrating systems from an
Q424: After investigating virus outbreaks that have cost
Q425: A penetration test is being scoped for
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents