Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingEasy

During an incident, a security analyst needs to ensure that all evidence collected from a compromised system is preserved in an unalterable state for forensic analysis and potential legal proceedings. Which of the following incident response tools is specifically designed for this purpose?

  1. AVulnerability Scanner
  2. BForensic Toolkit (FTK)
  3. CIntrusion Detection System (IDS)
  4. DSecurity Information and Event Management (SIEM)
Show answer & explanation

Correct answer: B. Forensic Toolkit (FTK)

A Forensic Toolkit (FTK) is a specialized software suite used to acquire, analyze, and preserve digital evidence in a forensically sound manner, ensuring its integrity for investigations and legal use. It creates bit-for-bit copies and verifies their authenticity.

Why the other options are wrong

  • A. A vulnerability scanner identifies weaknesses but does not collect or preserve incident evidence.
  • C. An IDS detects malicious activity but does not preserve evidence.
  • D. A SIEM aggregates and correlates security logs but isn't primarily for evidence acquisition.

Forensic Toolkit (FTK)

A software suite used for digital forensics, providing tools to acquire, process, and analyze digital evidence while maintaining its integrity.

  • Ensures evidence integrity through hashing and write-blocking.
  • Used for data recovery, password cracking, and email analysis.
  • Critical for legal and investigative purposes.

Memory trick: Tools for Incidents: Detect, Analyze, Preserve.

More Incident Handling questions