正解:B
Comprehensive and Detailed Step-by-Step Explanation:
Forensic evidence must be legally admissible, unaltered, and properly collected to support prosecution.
* Option A (Incorrect):While an IDS helpsdetectcybercrime, it does not ensure evidence collection or legal admissibility.
* Option B (Correct):Theprofessional collection of unaltered evidencefollows forensic standards, includingchain of custody, ensuring that the evidence is admissible in court. This is the most critical factor in prosecuting cybercriminals.
* Option C (Incorrect):Internal legal reporting is necessary but does not directly impactevidence preservation, which is key for legal action.
* Option D (Incorrect):Law enforcement involvement is important, but withoutproperly collected evidence, prosecution is unlikely to succeed.
Reference:ISACA CISA Review Manual -Domain 5: Protection of Information Assets- Covers forensic investigation, evidence collection, and chain of custody principles.