ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 100 - ECSS discussion

Report
Export

Sarah, a forensic investigator, is working on a criminal case. She was provided with all the suspect devices. Sarah employs an imaging software tool for duplicating the original data from the suspect devices. However, the tool she employed failed to image the data as the suspect version of the drive was very old and incompatible with imaging software. Hence, Sarah used an alternative data acquisition technique and succeeded in imaging the data.

Which of the following types of data acquisition techniques did Sarah employ in the above scenario?

A.

Bit-stream disk-to-disk

Answers
A.

Bit-stream disk-to-disk

B.

Bit-stream disk-to-image file

Answers
B.

Bit-stream disk-to-image file

C.

Sparse acquisition

Answers
C.

Sparse acquisition

D.

Logical acquisition

Answers
D.

Logical acquisition

Suggested answer: D

Explanation:

Sarah employed theLogical acquisitiontechnique in the given scenario. Logical acquisition involves selectively extracting specific files, folders, or data from a device, bypassing the need for a full disk image.It is useful when traditional imaging methods fail due to compatibility issues or other constraints1. In this case, Sarah successfully imaged the data using an alternative approach, focusing on specific data rather than creating a bit-stream image of the entire drive.The logical acquisition method allowed her to work around the limitations posed by the outdated suspect drive version1.

EC-Council Certified Security Specialist (E|CSS) documents and study guide.

EC-Council Certified Security Specialist (E|CSS) course materials.

1:How to Handle Data Acquisition in Digital Forensics

asked 24/10/2024
Benjamin Colart
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first