Which of these is not an appropriate incident response procedure?
  1. Examining Network traffic and logs
  2. Tracking man hours and expenses
  3. Getting a capture of the System Image
  4. Collecting data on machines unaffected by incident
Answer: D- Collecting data from machines that have nothing to do with the incident is inappropriate

Key Takeaway: Collecting data on machines unrelated to the incident will be of little use and generally a waste of time. It is better to concentrate your energy on the systems infected, and log man-hours and expenses so that a cost can better be put to this incident.
