Following a security alert, the incident response team at a legal consulting firm suspects that an employee used a USB storage device to exfiltrate confidential client data. To confirm which USB device was connected and gather timestamps and identifiers, which method is most effective?
ECIH forensic readiness guidance identifies the Windows Registry as a primary source for USB device artifacts. The Enum\USB registry key stores vendor IDs, product IDs, serial numbers, and connection history.
Option A is correct because it provides direct evidence of which USB devices were connected, when they were installed, and on which system---critical for insider investigations.
Option B cannot reliably identify physical USB usage. Option C contains driver installation data but is less comprehensive. Option D is irrelevant.
Registry analysis is a foundational forensic technique in ECIH, making Option A correct.
A cybersecurity team at a financial services firm detects abnormal behavior on several endpoints, suggesting a possible breach. The anomalies include unexpected data transfers and processes running with unusual permissions. Given the potential impact, the team needs to quickly validate whether these are indicators of a security incident or benign anomalies. What method should the team prioritize to detect and validate the incident effectively?
Explanation (aligned to IH&R lifecycle):
This question is about triage/validation---determining whether what you see is truly an incident and establishing priority. The most appropriate first move is to use endpoint telemetry and behavioral analytics (A) to validate maliciousness (e.g., suspicious parent/child process chains, token manipulation, credential dumping patterns, anomalous privilege escalation, and data transfer behaviors). This supports fast, evidence-based classification and reduces unnecessary disruption. Option (C) is containment and may be required after validation or for clearly high-confidence cases, but immediately disconnecting multiple endpoints can destroy volatile evidence, break business operations, and reduce your ability to trace lateral movement patterns across hosts. Option (B) is a broad preventive change that can create outage risk and is not a validation method. Option (D) can be helpful, but it is slower and not the primary ''detect and validate'' action for an internal team facing active anomalies.
A disciplined approach is: validate via behavioral tooling + logs, scope affected endpoints, determine severity, then execute containment proportional to confirmed risk. That sequencing mirrors standard incident handling flow (identify validate/triage contain eradicate recover lessons learned). When time matters, the highest-value action is the one that converts ambiguous signals into confident incident classification quickly---behavioral validation does that best.
Bob, an incident responder at CyberTech Solutions, is investigating a cybercrime attack occurred in the client company. He acquired the evidence data, preserved it, and started
performing analysis on acquired evidentiary data to identify the source of the crime and the culprit behind the incident.
Identify the forensic investigation phase in which Bob is currently in.
Bob is in the Investigation phase of the forensic investigation process. This phase involves the detailed examination and analysis of the collected evidence to identify the source of the crime and the perpetrator behind the incident. It is a crucial step that follows the acquisition and preservation of evidence, where the incident responder applies various techniques and methodologies to analyze the evidentiary data. This analysis aims to uncover how the cybercrime was committed, trace the activities of the culprit, and gather actionable intelligence to support legal actions and prevent future incidents.
Identify Sarbanes--Oxley Act (SOX) Title, which consists of only one section, that includes measures designed to help restore investor confidence in the reporting of
securities analysts.
The Sarbanes--Oxley Act (SOX) Title V, titled 'Analyst Conflicts of Interest,' contains measures specifically designed to restore investor confidence in the reporting of securities analysts. It addresses the issue of potential conflicts of interest for securities analysts who recommend stocks and other securities by requiring disclosure of certain relationships and financial interests between analysts and the companies they cover. This part of the SOX Act aims to ensure that investors receive unbiased and accurate information from analysts, thereby helping to restore trust in financial markets. Title V consists of only one section, making it unique compared to other titles within the Act that may encompass multiple sections or provisions.
Logan, an incident handler, ensures the chain of custody is documented while handling backup media post-attack. The goal is to preserve evidence integrity while restoring critical systems. Which recovery principle is Logan adhering to?
The EC-Council Incident Handler (ECIH) curriculum stresses the importance of maintaining evidence integrity during recovery operations. Documenting the chain of custody ensures that evidence remains admissible in legal proceedings and maintains forensic validity.
Chain of custody documentation tracks who handled the evidence, when it was accessed, how it was stored, and what actions were performed. This aligns directly with forensic compliance principles, which require proper evidence preservation, documentation, and controlled handling procedures.
While restoring systems, responders must ensure that backup media and affected systems are handled in a way that does not compromise evidence. ECIH emphasizes that recovery should not destroy or contaminate forensic artifacts that may be required for legal, regulatory, or disciplinary action.
Option B (Network segmentation) relates to containment strategies. Option C (Immutable infrastructure) refers to architectural resilience models. Option D (Enhanced authentication) concerns access control, not evidence handling.
Therefore, Logan is adhering to forensic compliance principles during recovery.
Sandra Johnson
7 days agoMaria Murphy
21 days agoLaura Jones
1 month agoJustin Cook
2 months agoHeather Wright
2 months agoSteven Parker
3 months agoEdward Miller
3 months agoDonna Miller
4 months agoRyan Rodriguez
4 months agoSharon Stewart
4 months agoMaria Taylor
4 months agoDorothy Roberts
4 months agoAdam Cook
4 months agoJason Williams
4 months agoCurtis
5 months agoPage
5 months agoAileen
5 months agoShalon
6 months agoFrankie
6 months agoJulianna
6 months agoLuisa
6 months agoElza
7 months agoChau
7 months agoElly
7 months agoSanjuana
7 months agoJanna
8 months agoMartina
8 months agoSabra
8 months agoHuey
8 months agoArgelia
9 months agoEdelmira
9 months agoMariann
9 months agoLindsey
9 months agoEmiko
10 months agoDaron
10 months agoKaty
10 months agoViva
10 months agoCherry
11 months agoKaran
11 months agoFrancisca
11 months agoGeorgiann
11 months agoTula
11 months agoChauncey
12 months agoLajuana
12 months agoPercy
1 year agoElmira
1 year agojalolag
1 year agoMari
1 year agoJaime
1 year agoBeckie
1 year agoCurtis
1 year agoDorothy
2 years agoDesirae
2 years agoAndree
2 years agoRosio
2 years agoArletta
2 years agoTeri
2 years agoAugustine
2 years agoQuiana
2 years agoTori
2 years agoKallie
2 years agoAlise
2 years agoMike
2 years agoStaci
2 years agoJulio
2 years agoAnnice
2 years agoAnnabelle
2 years agoElli
2 years agoCarisa
2 years agoEugene
2 years agoAdelina
2 years agoReed
2 years agoCecil
2 years agoPeggie
2 years agoMi
2 years agoLashonda
2 years agoCletus
2 years agoCharlesetta
2 years agoLanie
2 years agoAmos
2 years agoWilford
2 years agoBeckie
2 years agoAleta
2 years agoDaniel
2 years ago