Computer forensics (D) best enables an organization to determine what activities occurred and what changes were made to a system during a cybersecurity incident. In CISM incident management, computer forensics focuses on the systematic collection, preservation, analysis, and reconstruction of digital evidence to establish a detailed timeline of events, attacker actions, data access, and system modifications. This capability is essential for understanding the scope and impact of an incident, supporting legal or regulatory requirements, and preventing recurrence.
Continuous log monitoring (B) supports detection and early awareness of suspicious activity, but logs alone may be incomplete, altered, or insufficient to fully reconstruct attacker behavior. Root cause analysis (A) is performed after facts are established and focuses on why an incident occurred, not what exactly happened. Penetration testing (C) is a proactive security testing activity and is unrelated to incident investigation.
CISM emphasizes that once an incident has occurred, forensic analysis is critical to ensure accurate incident handling, evidence integrity, accountability, and informed remediation decisions.
[References:, ISACA CISM Review Manual, Information Security Incident Management — incident investigation and forensics, ISACA CISM Exam Content Outline, Domain 4: Information Security Incident Management, , , ]