CISSP Practice Question – Investigations & Forensics
During an internal investigation of suspected data theft, the incident response team collects a laptop from an employee’s desk. To preserve admissibility of evidence, which of the following is the MOST important step to take FIRST? A. Create a forensic image of the laptop using a write blocker. B. Power down the laptop to prevent further tampering. C. Document the time, date, and individuals involved in seizing the device. D. Secure the laptop in a locked evidence cabinet.