In incident handling, which activity gathers facts?

Study for the Valley Fair iROC Test. Enhance your skills with our comprehensive exam that includes multiple choice questions and clear explanations. Prepare confidently and ace your test!

Multiple Choice

In incident handling, which activity gathers facts?

Explanation:
Gaining factual information during an incident is the investigation phase. This step focuses on collecting evidence from systems, logs, and people, asking what happened, when it happened, how it occurred, and who was involved. It includes interviewing staff, preserving the chain of custody for any evidence, and documenting observations to build a solid factual basis for decisions and further analysis. Containment aims to stop the incident and limit damage, not to gather facts. Documentation records what happened and what actions were taken, but its purpose is to capture information rather than actively discover root facts. Analysis then uses the collected facts to interpret and determine root causes and impact. So, the activity that gathers facts is investigation.

Gaining factual information during an incident is the investigation phase. This step focuses on collecting evidence from systems, logs, and people, asking what happened, when it happened, how it occurred, and who was involved. It includes interviewing staff, preserving the chain of custody for any evidence, and documenting observations to build a solid factual basis for decisions and further analysis. Containment aims to stop the incident and limit damage, not to gather facts. Documentation records what happened and what actions were taken, but its purpose is to capture information rather than actively discover root facts. Analysis then uses the collected facts to interpret and determine root causes and impact. So, the activity that gathers facts is investigation.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy