Which of the following digital forensics activities would a security team perform when responding to legal requests in a pending investigation?
E-discovery
In a pending investigation, a security team would conduct e-discovery as part of the digital forensics activities to comply with legal requests. E-discovery involves identifying, preserving, collecting, reviewing, and producing electronically stored information (ESI) that may be relevant to the investigation or legal proceedings.
User provisioning is the process of setting up user accounts and granting access permissions to systems and resources. While important for managing user access within an organization, it is not directly related to digital forensics activities in response to legal requests during an investigation.
Exporting firewall logs involves retrieving and saving records of network traffic and security events logged by the firewall. While firewall logs can be valuable for investigating security incidents, exporting them is typically not a primary digital forensics activity specifically carried out to respond to legal requests in a pending investigation.
Root cause analysis is a methodical process used to identify the underlying cause of an issue or incident. While it is crucial for understanding and addressing security incidents, it is not a typical digital forensics activity specifically performed in response to legal requests during an investigation.
In the context of a pending investigation and legal requests, the digital forensics activity that a security team would primarily engage in is e-discovery. This process ensures that relevant electronic evidence is properly identified, preserved, and presented in compliance with legal requirements, aiding in the investigation and potential legal proceedings.
Related Questions
View allA company hired a security consultant to suggest a device that will pr...
Which of the following should an organization use to ensure that it ca...
Which of the following outlines the configuration, maintenance, and se...
Which of the following can automate vulnerability management?
An engineer needs to ensure that a script has not been modified before...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA CySA+ Cybersecurity Analyst Certification all in One Exam Guide
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus Example Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations