Sovi.AI - AI Math Tutor

Scan to solve math questions

QUESTION IMAGE

at what phase of a security incident response should evidence be collec…

Question

at what phase of a security incident response should evidence be collected? preparation detection and analysis containment and eradication post - incident recovery

Explanation:

Brief Explanations

In security incident response, during the Detection and Analysis phase, the incident is identified, and evidence related to the incident (like logs, system states) is collected to understand the nature of the incident. Preparation is about getting ready, Containment and Eradication is about stopping the incident, and Post - incident Recovery is about restoring systems. So evidence collection happens in Detection and Analysis.

Answer:

Detection and Analysis