Best Method to Determine System Activities During a Cyber Incident

Incident Management & Digital Forensics
Answer Correct answer: D — Computer forensics systematically collects, preserves, and analyzes digital evidence to reconstruct system activities and changes during a cybersecurity incident.

Which of the following BEST enables an organization to determine what activities and changes have occurred on a system during a cybersecurity incident?

  1. Penetration testing
  2. Root cause analysis
  3. Continuous log monitoring
  4. Computer forensics Correct Answer

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the distinction between proactive visibility tools and reactive investigative disciplines, with the common trap being choosing live monitoring over comprehensive evidentiary reconstruction.

Computer forensics is the authoritative method for reconstructing system activities and changes during a cybersecurity incident, though many candidates mistakenly select continuous log monitoring due to its real-time alerting capabilities.

Candidates frequently choose continuous log monitoring (C) because it sounds actionable, but it only captures live data streams without the deep correlation and preservation required to definitively determine past system changes and attacker actions.

Community Discussion (3 comments)

yottabyte 👍 6 Selected: C
Computer forensics is required but tracking the activities is through log monitoring.
mb141 👍 1 Selected: D
Computer forensics is the BEST approach to determine what activities and changes have occurred on a system during a cybersecurity incident. It involves the systematic collection, analysis, and preservation of digital evidence to: Understand the scope of the incident. Reconstruct the sequence of events. Identify the attacker’s activities and the impact of their actions. Computer forensics is specifically designed to analyze systems post-incident, making it the most appropriate choice for investigating and understanding cybersecurity incidents.
shootnot 👍 1
D- for changes that have occurred and already in the systems can only be found through forensics. C- would enable only current state monitoring

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Computer forensics provides the structured methodology required to collect, preserve, and analyze digital evidence to accurately reconstruct the timeline of a cyber incident. Unlike simple monitoring, forensics correlates logs, file system artifacts, registry entries, and memory dumps to determine exactly what activities and changes occurred. This aligns with ISACA’s emphasis on systematic investigation to establish root causes, scope, and attacker tactics.

Why the Other Options Are Wrong

Penetration testing (A) is a proactive vulnerability assessment tool used before incidents occur, not an investigative technique. Root cause analysis (B) focuses on identifying underlying systemic failures after the fact, rather than tracking specific system activities or changes. Continuous log monitoring (C) offers real-time alerts but lacks the comprehensive evidentiary depth needed to fully determine historical modifications and compromise impact.

Community Comment Notes

While the majority voted for option C, experienced practitioners correctly highlight that log monitoring only tracks current states or live streams. As noted in helpful feedback, forensics is specifically designed to reconstruct sequences of events and identify the full impact of an attacker’s actions, making it the definitive choice for determining what has already occurred on a compromised system.

Official Reference

Exam Strategy

Always distinguish between real-time detection mechanisms and post-incident investigative disciplines when reviewing CISM questions. When a prompt asks to "determine what occurred" or "reconstruct events," prioritize forensic analysis over monitoring tools, as forensics encompasses the full evidentiary lifecycle required for accurate incident reporting.

Frequently Asked Questions

Why isn't continuous log monitoring the best choice for incident investigation?

Log monitoring provides real-time alerts but lacks the deep evidentiary correlation needed to reconstruct past system changes and attacker actions.

How does computer forensics differ from root cause analysis in CISM?

Forensics focuses on reconstructing the sequence of events and identifying specific system changes, while root cause analysis targets underlying systemic vulnerabilities after investigation.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide