🔥 3-day streak
Cisco CCNA Cybersecurity (200-201 CCNACBR)79 / 145
Question 79 of 145

A CyberOps analyst is establishing a digital forensics workflow based on NIST SP 800-86. After legally acquiring a suspect's hard drive image, the analyst needs to identify and extract relevant items such as file timestamps and application data before drawing conclusions for the incident report. According to the four-phase forensic process in NIST SP 800-86, which phase is the analyst performing when identifying and extracting these relevant items from the acquired data?

Reviewed for accuracy · Report an issueNext question