CISSP PRACTICE QUESTIONS – 20210519

Effective CISSP Questions

As part of the e-discovery in a legal proceeding on salary controversy, an unfriendly ex-employee submitted a legal request for the printout of audit trails in question stored on the SIEM server to your company. Which of the following least affects the admissibility of the printout as evidence? (Wentz QOTD)
A. The best evidence rule
B. Exceptions to the rule against hearsay
C. The beyond a reasonable doubt standard
D. The preponderance of the evidence standard

Kindly be reminded that the suggested answer is for your reference only. It doesn’t matter whether you have the right or wrong answer. What really matters is your reasoning process and justifications.

My suggested answer is C. The beyond a reasonable doubt standard.

The question is talking about a civil case between an ex-employee and your company. The burden of proof does not follow the beyond a reasonable doubt standard which applies to criminal cases only. Instead, civil cases follow the preponderance of the evidence standard.

The best evidence rule and exceptions to the rule against hearsay are crucial factors that affect the relevance, materiality, and competency of evidence, that is, the evidence admissibility.

Exceptions to the Rule against Hearsay

Records of a Regularly Conducted Activity. A record of an act, event, condition, opinion, or diagnosis if:
(A) the record was made at or near the time by — or from information transmitted by — someone with knowledge;
(B) the record was kept in the course of a regularly conducted activity of a business, organization, occupation, or calling, whether or not for profit;
(C) making the record was a regular practice of that activity;
(D) all these conditions are shown by the testimony of the custodian or another qualified witness, or by a certification that complies with Rule 902(11) or (12) or with a statute permitting certification; and
(E) the opponent does not show that the source of information or the method or circumstances of preparation indicate a lack of trustworthiness.

Source: Federal Rules of Evidence

Beyond a Reasonable Doubt

Most criminal cases must meet the beyond a reasonable doubt standard of evidence. Following this standard, the prosecution must demonstrate that the defendant committed the crime by presenting facts from which there are no other logical conclusions. For this reason, criminal investigations must follow very strict evidence collection and preservation processes.

Preponderance of the Evidence

Most civil cases do not follow the beyond a reasonable doubt standard of proof. Instead, they use the weaker preponderance of the evidence standard. Meeting this standard simply requires that the evidence demonstrate that the outcome of the case is more likely than not. For this reason, evidence collection standards for civil investigations are not as rigorous as those used in criminal investigations.

The Best Evidence Rule

The best evidence rule states that, when a document is used as evidence in a court proceeding, the original document must be introduced. Copies or descriptions of original evidence (known as secondary evidence) will not be accepted as evidence unless certain exceptions to the rule apply.

Source: Stewart, James M.; Chapple, Mike; Gibson, Darril. CISSP ISC2 Certified Information Systems Security Professional Official Study Guide. Wiley.

Reference

A BLUEPRINT FOR YOUR SUCCESS IN CISSP

My new book, The Effective CISSP: Security and Risk Management, helps CISSP aspirants build a solid conceptual security model. It is not only a tutorial for information security but also a study guide for the CISSP exam and an informative reference for security professionals.

作為有關工資爭議的法律程序中電子發現(e-discovery)的一部分,一位不友好的前僱員向您的公司提交了一份法律要求,要求將存儲在SIEM服務器上的特定稽核軌跡打印出來。 以下哪項對該文件被採納作為法庭證據的影響最小?(Wentz QOTD)
A. The best evidence rule
B. Exceptions to the rule against hearsay
C. The beyond a reasonable doubt standard
D. The preponderance of the evidence standard

Leave a Reply