CySA+ v4 · Objective 3.3

Evidence and response techniques

Execute a response with clear authority, a defensible timeline, preserved evidence, and verified restoration.

What you will be able to do

  • Create a response task sequence with owners, escalation triggers, and verification steps.
  • Correlate and enrich records without losing their original context.
  • Document evidence acquisition, integrity checks, custody, and preservation requirements.
  • Define release and restoration criteria linked to the incident cause.

Learn the concepts

  1. Lesson 1

    Coordinate the first response actions

    Practical response combines technical work with decisions about authority, priority, and communication. A short, well-owned task list is more useful than many uncoordinated actions that change the same system.

    Open lesson →
  2. Lesson 2

    Preserve evidence that another analyst can trust

    Evidence must remain interpretable after the person who collected it leaves the incident. Good handling preserves the artifact, explains how it was obtained, and records every meaningful change in custody.

    Open lesson →

Apply your judgement · Synthetic scenario

The audit export changes hands

A fictional membership service is investigating unauthorised profile access. Two analysts have overlapping exports, one of which has been filtered. The next shift must continue containment while preserving a reliable evidence record.

Original acquisition
E-31: audit export acquired at 14:20 UTC by analyst Mina; original source, query, and SHA-256 recorded.
Working file
membership-filtered.csv arrived at 14:42 UTC from analyst Theo; no transformation notes attached.
Time discrepancy
Application events are recorded in local time; the identity export explicitly uses UTC.
Response state
Account suspension requested at 14:35 UTC; a new session event appears at 14:39 UTC.

Your task

  1. Separate trusted originals from derivatives and identify the missing handling information.
  2. Explain how to reconcile the timeline without altering raw evidence.
  3. Define the next containment verification and escalation.
Compare your response

Preserve E-31 with its acquisition record and restrict access. Preserve the received filtered file separately, record its receipt, and ask Theo for its parent artifact and transformation method. Do not replace the original with the filtered file or claim they are equivalent.

Retain original timestamps and document the application time zone and any known clock offset. Build a normalised timeline that records conversion assumptions and flags uncertain orderings. Correlate using account and session identifiers as well as times.

Check whether the new session was created after effective suspension or merely recorded later. Verify account state and session revocation, notify the incident lead of the unresolved access, and use the approved alternative containment path if access continues.

Put it into practice

Use these labs alongside this module.

Check your understanding

Choose the best response to each scenario, then check your reasoning. These are course practice questions.

1. A copied packet capture has the same SHA-256 value as the acquired capture. Which statement is justified?
2. A response timeline mixes UTC identity records with local-time application records. Two events appear one hour apart. What should the analyst do before inferring their order?
3. The service is restored, but an adviser issues preservation instructions while a dispute is assessed. Storage is nearly full. What is the best response?

0 of 3 answered

Source reading: supplied book, chapters 9, 10, 11. Lessons, scenarios, and questions are original CyberCorps course material.