ExamGecko
Question list
Search
Search

Question 387 - CISM discussion

Report
Export

A forensic examination of a PC is required, but the PC has been switched off. Which of the following should be done FIRST?

A.
Perform a backup of the hard drive using backup utilities.
Answers
A.
Perform a backup of the hard drive using backup utilities.
B.
Perform a bit-by-bit backup of the hard disk using a write-blocking device
Answers
B.
Perform a bit-by-bit backup of the hard disk using a write-blocking device
C.
Perform a backup of the computer using the network
Answers
C.
Perform a backup of the computer using the network
D.
Reboot the system using third-party forensic software in the CD-ROM drive
Answers
D.
Reboot the system using third-party forensic software in the CD-ROM drive
Suggested answer: B

Explanation:

Performing a bit-by-bit backup of the hard disk using a write-blocking device is the first step to do when a forensic examination of a PC is required, but the PC has been switched off because it helps to create a forensically sound copy of the original evidence without altering or damaging it. A bit-by-bit backup, also known as a physical or raw image, is a complete copy of every bit on the hard disk, including the unallocated or deleted data. A write-blocking device is a hardware or software tool that prevents any write operations to the hard disk, such as updating timestamps or changing file attributes. Performing a bit-by-bit backup of the hard disk using a write-blocking device ensures the integrity and authenticity of the evidence and allows the forensic analysis to be conducted on the duplicate image rather than the original source. Therefore, performing a bit-by-bit backup of the hard disk using a write-blocking device is the correct answer.

https://en.wikipedia.org/wiki/Computer_forensics

https://resources.infosecinstitute.com/topic/computer-forensics-forensic-analysis-examination-planning/

https://www.computer-forensics-recruiter.com/topics/examination_steps/

asked 01/10/2024
EDUARDO VIDAL
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first