Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingEasy
During an incident, a security analyst needs to ensure that all evidence collected from a compromised system is preserved in an unalterable state for forensic analysis and potential legal proceedings. Which of the following incident response tools is specifically designed for this purpose?
- AVulnerability Scanner
- BForensic Toolkit (FTK)
- CIntrusion Detection System (IDS)
- DSecurity Information and Event Management (SIEM)
Show answer & explanationAnswer & explanation
Correct answer: B. Forensic Toolkit (FTK)
A Forensic Toolkit (FTK) is a specialized software suite used to acquire, analyze, and preserve digital evidence in a forensically sound manner, ensuring its integrity for investigations and legal use. It creates bit-for-bit copies and verifies their authenticity.
Why the other options are wrong
- A. A vulnerability scanner identifies weaknesses but does not collect or preserve incident evidence.
- C. An IDS detects malicious activity but does not preserve evidence.
- D. A SIEM aggregates and correlates security logs but isn't primarily for evidence acquisition.
Forensic Toolkit (FTK)
A software suite used for digital forensics, providing tools to acquire, process, and analyze digital evidence while maintaining its integrity.
- Ensures evidence integrity through hashing and write-blocking.
- Used for data recovery, password cracking, and email analysis.
- Critical for legal and investigative purposes.
Memory trick: Tools for Incidents: Detect, Analyze, Preserve.