Organizations or incident response teams need to protect the evidence for any future legal actions that may be taken against perpetrators that intentionally attacked the computer system. EVIDENCE PROTECTION is also required to meet legal compliance issues. Which of the following documents helps in protecting evidence from physical or logical damage: A. Network and host log records B. Chain-of-Custody C. Forensic analysis report D. Chain-of-Precedence  Suggested Answer: B This question is in 212-89 EC-Council Certified Incident Handler Exam For getting EC-Council Certified Incident Handler (ECIH) Disclaimers: The website is not related to, affiliated with, endorsed or authorized by EC-Council. Trademarks, certification & product names are used for reference only and belong to EC-Council. The website does not contain actual questions and answers from EC-Council's Certification Exams.
Please login or Register to submit your answer