medium
Single Answer
0

Denis suspects that a hacker has penetrated a system belonging to his company. The system does not contain any regulated information, and Denis wants to conduct an investigation on behalf of his company. He has permission from his supervisor to conduct the investigation. Which of the following statements is true?

Answer Options

A

Denis is legally required to contact law enforcement before beginning the investigation.

B

Denis may not conduct his own investigation.

C

Denis's investigation may include examining the contents of hard disks, network traffic, and any other systems or information belonging to the company.

D

Denis may ethically perform "hack back" activities after identifying the perpetrator.

Correct Answer: C

Explanation

Denis may conduct his investigation as he wants and use any information that is legally available to him, including information and systems belonging to his employer. There is no obligation to contact law enforcement. However, Denis may not perform "hack back" activities because those may constitute violations of the law and/or the ISC2 Code of Ethics.