CySA+ v4 · Objective 3.3
Evidence and response techniques
Execute a response with clear authority, a defensible timeline, preserved evidence, and verified restoration.
What you will be able to do
- Create a response task sequence with owners, escalation triggers, and verification steps.
- Correlate and enrich records without losing their original context.
- Document evidence acquisition, integrity checks, custody, and preservation requirements.
- Define release and restoration criteria linked to the incident cause.
Learn the concepts
- Lesson 1
Coordinate the first response actions
Practical response combines technical work with decisions about authority, priority, and communication. A short, well-owned task list is more useful than many uncoordinated actions that change the same system.
Open lesson → - Lesson 2
Preserve evidence that another analyst can trust
Evidence must remain interpretable after the person who collected it leaves the incident. Good handling preserves the artifact, explains how it was obtained, and records every meaningful change in custody.
Open lesson →
Apply your judgement · Synthetic scenario
The audit export changes hands
A fictional membership service is investigating unauthorised profile access. Two analysts have overlapping exports, one of which has been filtered. The next shift must continue containment while preserving a reliable evidence record.
- Original acquisition
- E-31: audit export acquired at 14:20 UTC by analyst Mina; original source, query, and SHA-256 recorded.
- Working file
- membership-filtered.csv arrived at 14:42 UTC from analyst Theo; no transformation notes attached.
- Time discrepancy
- Application events are recorded in local time; the identity export explicitly uses UTC.
- Response state
- Account suspension requested at 14:35 UTC; a new session event appears at 14:39 UTC.
Your task
- Separate trusted originals from derivatives and identify the missing handling information.
- Explain how to reconcile the timeline without altering raw evidence.
- Define the next containment verification and escalation.
Compare your response
Preserve E-31 with its acquisition record and restrict access. Preserve the received filtered file separately, record its receipt, and ask Theo for its parent artifact and transformation method. Do not replace the original with the filtered file or claim they are equivalent.
Retain original timestamps and document the application time zone and any known clock offset. Build a normalised timeline that records conversion assumptions and flags uncertain orderings. Correlate using account and session identifiers as well as times.
Check whether the new session was created after effective suspension or merely recorded later. Verify account state and session revocation, notify the incident lead of the unresolved access, and use the approved alternative containment path if access continues.
Put it into practice
Use these labs alongside this module.
Check your understanding
Source reading: supplied book, chapters 9, 10, 11. Lessons, scenarios, and questions are original CyberCorps course material.