The correct answer is to create a detailed initial report. This is the first and most crucial step in documenting an incident. It establishes the foundation for the entire incident response process and helps maintain the integrity of the investigation. The initial report should include the date, time, and nature of the incident, as well as any immediate observations or actions taken. This document becomes the starting point for the chain of custody, which is essential for potential legal proceedings.
While contacting law enforcement is important, it's not the first step in documentation. Similarly, creating a final report comes after the investigation is complete, not at the beginning. Deleting log files is never a correct action, as it destroys valuable evidence and violates proper incident response procedures.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What should be included in a detailed initial report?
Open an interactive chat with Bash
What is the chain of custody and why is it important?
Open an interactive chat with Bash
Why is deleting log files considered a bad practice during an incident?