ExamGecko
Question list
Search
Search

Question 443 - CISM discussion

Report
Export

The GREATEST challenge when attempting data recovery of a specific file during forensic analysis is when:

A.
the partition table on the disk has been deleted.
Answers
A.
the partition table on the disk has been deleted.
B.
the tile has been overwritten.
Answers
B.
the tile has been overwritten.
C.
all files in the directory have been deleted.
Answers
C.
all files in the directory have been deleted.
D.
high-level disk formatting has been performed.
Answers
D.
high-level disk formatting has been performed.
Suggested answer: B

Explanation:

Data recovery is the process of restoring data that has been lost, corrupted, or deleted. When a file is deleted, it is usually not physically erased from the disk, but only marked as free space by the operating system. Therefore, it may be possible to recover the file by using specialized tools that scan the disk for the file's data. However, if the file has been overwritten by another file or data, then the original file's data is lost and cannot be recovered. The other options are not as challenging as overwriting, because they only affect the logical structure of the disk, not the physical data. For example, the partition table, the directory, and the formatting information can be reconstructed or bypassed by using forensic tools.Reference= CISM Review Manual, 16th Edition, Chapter 5, Section 5.4.1.2

asked 01/10/2024
Kristi Riddick
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first