Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

EC-Council 112-57 Exam - Topic 4 Question 9 Discussion

Jennifer, a forensics investigation team member, was inspecting a compromised system. After gathering all the evidence related to the compromised system, she disconnected the system from the network to stop the spread of the incident to other systems.Identify the role played by Jennifer in the forensics investigation.
A) Incident responder
B) Incident analyzer
C) Evidence manager
D) Expert witness

EC-Council 112-57 Exam - Topic 4 Question 9 Discussion

Actual exam question for EC-Council's 112-57 exam
Question #: 9
Topic #: 4
[All 112-57 Questions]

Jennifer, a forensics investigation team member, was inspecting a compromised system. After gathering all the evidence related to the compromised system, she disconnected the system from the network to stop the spread of the incident to other systems.

Identify the role played by Jennifer in the forensics investigation.

Show Suggested Answer Hide Answer
Suggested Answer: A

Jennifer's actions match the responsibilities of an incident responder, whose job spans immediate containment, preservation, and stabilization activities during an active or recently active security incident. In standard digital forensics and incident response (DFIR) procedures, responders first take steps to preserve evidence (e.g., documenting the scene, capturing volatile data when appropriate, and collecting relevant system artifacts) and then execute containment measures to prevent further harm. Disconnecting a compromised host from the network is a classic containment control used to stop malware propagation, block command-and-control communications, and prevent lateral movement to other systems.

An incident analyzer typically focuses on deeper technical analysis---timeline reconstruction, root cause determination, and correlating artifacts across hosts and logs---rather than performing immediate containment. An evidence manager is primarily responsible for maintaining evidence integrity, chain of custody, storage, labeling, and access control, not operational containment. An expert witness provides formal testimony and interpretation in legal or disciplinary proceedings and is not usually involved in live containment actions. Since Jennifer both gathered evidence and then isolated the system to stop spread, the role most consistent with documented DFIR responsibilities is Incident responder (A).


Contribute your Thoughts:

0/2000 characters
Nieves
5 days ago
True, but the main role here is responding to the incident.
upvoted 0 times
...
Genevieve
10 days ago
But she also gathers evidence. Could be an evidence manager too.
upvoted 0 times
...
Rene
15 days ago
Agreed! Stopping the spread is key.
upvoted 0 times
...
Felix
20 days ago
I think Jennifer is an incident responder. She took immediate action.
upvoted 0 times
...
Lashawna
25 days ago
I’m with you all. Responding is her primary role here.
upvoted 0 times
...
Christoper
1 month ago
Incident responder fits best. She disconnected to prevent further damage.
upvoted 0 times
...
Jesusa
1 month ago
I see the evidence manager point, but the response was urgent.
upvoted 0 times
...
Jess
1 month ago
Definitely an incident responder. Quick decisions are key in forensics.
upvoted 0 times
...
Carrol
2 months ago
But she acted quickly to contain the issue. That’s a responder's role.
upvoted 0 times
...
Felicia
2 months ago
I lean towards evidence manager. She gathered and secured evidence first.
upvoted 0 times
...
Maddie
2 months ago
Agreed, incident responder makes sense. Stopping the spread is crucial.
upvoted 0 times
...
Kirk
2 months ago
I think Jennifer is an incident responder. She took immediate action.
upvoted 0 times
...
Haydee
2 months ago
Disconnected the system? Seems a bit extreme, right?
upvoted 0 times
...
Queenie
2 months ago
Wait, are we sure she’s not an incident analyzer?
upvoted 0 times
...
Casie
3 months ago
I agree, incident responder makes sense here.
upvoted 0 times
...
Merissa
3 months ago
I think she’s more of an evidence manager.
upvoted 0 times
...
Vincent
3 months ago
She's definitely an incident responder.
upvoted 0 times
...
Ulysses
3 months ago
I could see her being an evidence manager too, but the immediate action of disconnecting the system feels more like an incident responder role.
upvoted 0 times
...
Shaun
5 months ago
This reminds me of a practice question where the responder was also the one to contain the incident. I feel like that's what Jennifer is doing here.
upvoted 0 times
...
Thurman
5 months ago
I'm not entirely sure, but I remember something about incident analyzers focusing more on the analysis phase rather than immediate response.
upvoted 0 times
...
Rosendo
5 months ago
I think Jennifer is acting as an incident responder since she disconnected the system to prevent further damage. That seems to fit the role.
upvoted 0 times
...

Save Cancel