ExamGecko
Home Home / ISC / CISSP
Question list
Search
Search

Question 146 - CISSP discussion

Report
Export

How can a forensic specialist exclude from examination a large percentage of operating system files residing on a copy of the target system?

A.
Take another backup of the media in question then delete all irrelevant operating system files.
Answers
A.
Take another backup of the media in question then delete all irrelevant operating system files.
B.
Create a comparison database of cryptographic hashes of the files from a system with the same operating system and patch level.
Answers
B.
Create a comparison database of cryptographic hashes of the files from a system with the same operating system and patch level.
C.
Generate a message digest (MD) or secure hash on the drive image to detect tampering of the media being examined.
Answers
C.
Generate a message digest (MD) or secure hash on the drive image to detect tampering of the media being examined.
D.
Discard harmless files for the operating system, and known installed programs.
Answers
D.
Discard harmless files for the operating system, and known installed programs.
Suggested answer: B
asked 18/09/2024
Bruno Soriano
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first