Problem Statement
During containment, why is preserving forensic evidence critical?
Explanation
Forensic evidence helps investigators trace the origin and scope of an attack.
Preserving logs, memory dumps, and network captures ensures that later analysis and legal teams have valid, untampered data to work with.