ACE Risk Management & Mitigation 3 — Questions and Answers
Question 1: A forensic examiner is called to respond to a ransomware incident. Which immediate action best mitigates further data loss risk?
- Pay the ransom to restore files quickly
- Isolate affected systems from the network to prevent spread (Correct answer)
- Delete all encrypted files to stop the malware
- Reboot all infected systems simultaneously
Correct answer: Isolate affected systems from the network to prevent spread
Network isolation prevents ransomware from propagating to additional systems while preserving the existing state for forensic analysis.
Question 2: Which framework is most commonly referenced for IT risk management and aligns closely with digital forensics operational risk controls?
- PCI DSS
- NIST SP 800-30 (Correct answer)
- ISO 9001
- OWASP Top 10
Correct answer: NIST SP 800-30
NIST SP 800-30 provides a comprehensive guide to risk assessment that is widely applied to IT and digital forensics environments.
Question 3: An examiner's workstation is compromised by malware mid-investigation. Which risk was insufficiently mitigated?
- Evidence volatility risk
- Examiner workstation integrity risk (Correct answer)
- Witness credibility risk
- Legal admissibility risk
Correct answer: Examiner workstation integrity risk
Malware on the examiner's workstation represents a failure to mitigate workstation integrity risk, which can contaminate forensic analysis results.
Question 4: A risk assessment reveals that the probability of unauthorized physical access to evidence storage is 'high' but the impact is 'low.' How should this risk typically be prioritized?
- Treat as critical and address immediately
- Treat as medium priority and schedule remediation (Correct answer)
- Accept the risk without any action
- Transfer the risk to local law enforcement
Correct answer: Treat as medium priority and schedule remediation
High probability combined with low impact generally yields a medium overall risk rating, warranting planned remediation rather than immediate action.
Question 5: Which of the following best describes a 'threat' in the context of risk management for a forensic lab?
- A vulnerability in evidence handling procedures
- A potential cause of an unwanted incident that could harm assets (Correct answer)
- The likelihood that an attack will succeed
- A safeguard implemented to reduce exposure
Correct answer: A potential cause of an unwanted incident that could harm assets
A threat is any potential cause of an unwanted incident, such as a malicious actor, natural disaster, or human error, that could exploit vulnerabilities.
Question 6: What is the purpose of a Business Impact Analysis (BIA) in a forensic lab's risk management program?
- To identify the financial cost of all hardware
- To determine the criticality of lab functions and acceptable downtime (Correct answer)
- To evaluate examiner performance metrics
- To audit chain of custody documentation
Correct answer: To determine the criticality of lab functions and acceptable downtime
A BIA identifies which lab functions are most critical, their recovery time objectives, and the business impact if those functions are disrupted.
Question 7: An ACE examiner receives a hard drive that shows signs of physical damage. Which risk mitigation step should be taken before attempting logical acquisition?
- Run FTK Imager immediately to capture all data
- Send the drive to a clean room for physical recovery assessment (Correct answer)
- Delete suspect files to prevent further damage
- Hash the drive without mounting it
Correct answer: Send the drive to a clean room for physical recovery assessment
Physically damaged drives risk further data loss if operated without assessment; a clean room specialist can evaluate and stabilize the drive before acquisition.
A forensic examiner is called to respond to a ransomware incident.
Which immediate action best mitigates further data loss risk?