Certified Information Systems Security Professional – CISSP – Question149

What is the MOST important step during forensic analysis when trying to learn the purpose of an unknown application?

A.
Disable all unnecessary services
B. Ensure chain of custody
C. Prepare another backup of the system
D. Isolate the system from the network

Correct Answer: D