Which of the following digital forensics activities would a security team perform when responding to legal requests in a pending investigation?
E-discovery
In a pending investigation, a security team would conduct e-discovery as part of the digital forensics activities to comply with legal requests. E-discovery involves identifying, preserving, collecting, reviewing, and producing electronically stored information (ESI) that may be relevant to the investigation or legal proceedings.
User provisioning is the process of setting up user accounts and granting access permissions to systems and resources. While important for managing user access within an organization, it is not directly related to digital forensics activities in response to legal requests during an investigation.
Exporting firewall logs involves retrieving and saving records of network traffic and security events logged by the firewall. While firewall logs can be valuable for investigating security incidents, exporting them is typically not a primary digital forensics activity specifically carried out to respond to legal requests in a pending investigation.
Root cause analysis is a methodical process used to identify the underlying cause of an issue or incident. While it is crucial for understanding and addressing security incidents, it is not a typical digital forensics activity specifically performed in response to legal requests during an investigation.
In the context of a pending investigation and legal requests, the digital forensics activity that a security team would primarily engage in is e-discovery. This process ensures that relevant electronic evidence is properly identified, preserved, and presented in compliance with legal requirements, aiding in the investigation and potential legal proceedings.
Related Questions
View allWhich of the following risks can be mitigated by HTTP headers?
A forensic engineer determines that the root cause of a compromise is...
An organization experiences data loss after several employees traveled...
Which of the following is a common data removal option for companies t...
A university employee has logged on to an academic server and attempte...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA CySA+ Cybersecurity Analyst Certification all in One Exam Guide
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus Example Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations