Which statement most accurately captures the defining purpose of digital forensics as it supports the incident response process?
- ADigital forensics is the activity of patching exploited vulnerabilities on affected systems so that the same flaw cannot be re-used by the attacker once recovery is complete.
- BDigital forensics is the rapid blocking of known malicious indicators at firewalls and proxies during an active incident so that command and control traffic stops reaching infected hosts.
- CDigital forensics is the structured collection, preservation, and analysis of digital evidence using a defensible chain of custody so that findings stand up to internal, regulatory, or legal scrutiny. Correct
- DDigital forensics is the periodic review of security policies and standards by an internal audit team to confirm that the organisation is complying with its own documented control set.
Why A is wrong: Patching exploited vulnerabilities is part of eradication or longer-term remediation; digital forensics is concerned with collecting and analysing evidence, not with applying fixes to the underlying flaws.
Why B is wrong: Rapid blocking of indicators at the perimeter is a containment action driven by threat intelligence; digital forensics may inform such blocks but is itself the evidence-handling discipline rather than the blocking action.
Why C is correct: Digital forensics is defined by sound evidence handling: acquiring data in a repeatable way, preserving its integrity with hashes, maintaining a documented chain of custody, and analysing it so the results are defensible in internal reviews, regulatory action, or court.
Why D is wrong: Periodic policy and control reviews by internal audit are governance activities; digital forensics is the technical evidence discipline that supports incident response and any subsequent investigations, not a compliance review function.