When an organization lacks internal expertise to conduct highly technical forensics investigations, what is the BEST way to ensure effective and timely investigations following an information security incident?
A.
Purchase forensic standard operating procedures.
B.
Retain a forensics firm prior to experiencing an incident.
C.
Ensure the incident response policy allows hiring a forensics firm.
D.
Provide forensics training to the information security team.
Whilst I agree it's B. That's a very expensive thing to do that may never be needed and a lot of organizations wouldn't approve the spend. C is the more likely option
B. Retain a forensics firm prior to experiencing an incident.
upvoted 2 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
WibbleMyFins
1 month agoAlexJacobson
5 months, 2 weeks agorichck102
8 months, 3 weeks ago