TRUE/FALSE
1. Incident responseis strictly an information security operation.
2. Large organizationstypically have the resources to protect everything against allthreats.
3. Detecting that asecurity event is occurring or has occurred is an easy matter.
4. Recovery is thereturning of the asset into the business function.
5. All data is equallyimportant, and it is equally damaging in the event of loss.
6. When performingforensics on a computer system you should use the utilitiesprovided by that system.
7. When analyzingcomputer storage components, the original system should beanalyzed.
8. Relevant evidencemust be convincing or measure up without question.
9. Oral testimony thatproves
OR
OR