Best Method to Determine System Activities During a Cyber Incident
Which of the following BEST enables an organization to determine what activities and changes have occurred on a system during a cybersecurity incident?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the distinction between proactive visibility tools and reactive investigative disciplines, with the common trap being choosing live monitoring over comprehensive evidentiary reconstruction.
Computer forensics is the authoritative method for reconstructing system activities and changes during a cybersecurity incident, though many candidates mistakenly select continuous log monitoring due to its real-time alerting capabilities.
Candidates frequently choose continuous log monitoring (C) because it sounds actionable, but it only captures live data streams without the deep correlation and preservation required to definitively determine past system changes and attacker actions.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Computer forensics provides the structured methodology required to collect, preserve, and analyze digital evidence to accurately reconstruct the timeline of a cyber incident. Unlike simple monitoring, forensics correlates logs, file system artifacts, registry entries, and memory dumps to determine exactly what activities and changes occurred. This aligns with ISACA’s emphasis on systematic investigation to establish root causes, scope, and attacker tactics.Why the Other Options Are Wrong
Penetration testing (A) is a proactive vulnerability assessment tool used before incidents occur, not an investigative technique. Root cause analysis (B) focuses on identifying underlying systemic failures after the fact, rather than tracking specific system activities or changes. Continuous log monitoring (C) offers real-time alerts but lacks the comprehensive evidentiary depth needed to fully determine historical modifications and compromise impact.Community Comment Notes
While the majority voted for option C, experienced practitioners correctly highlight that log monitoring only tracks current states or live streams. As noted in helpful feedback, forensics is specifically designed to reconstruct sequences of events and identify the full impact of an attacker’s actions, making it the definitive choice for determining what has already occurred on a compromised system.Official Reference
Exam Strategy
Always distinguish between real-time detection mechanisms and post-incident investigative disciplines when reviewing CISM questions. When a prompt asks to "determine what occurred" or "reconstruct events," prioritize forensic analysis over monitoring tools, as forensics encompasses the full evidentiary lifecycle required for accurate incident reporting.
Frequently Asked Questions
Why isn't continuous log monitoring the best choice for incident investigation?
Log monitoring provides real-time alerts but lacks the deep evidentiary correlation needed to reconstruct past system changes and attacker actions.
How does computer forensics differ from root cause analysis in CISM?
Forensics focuses on reconstructing the sequence of events and identifying specific system changes, while root cause analysis targets underlying systemic vulnerabilities after investigation.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →