ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 436 - CAS-004 discussion

Report
Export

A forensic investigator started the process of gathering evidence on a laptop in response to an incident The investigator took a snapshof of the hard drive, copied relevant log files and then performed a memory dump Which of the following steps in the process should have occurred first?

A.
Preserve secure storage
Answers
A.
Preserve secure storage
B.
Clone the disk.
Answers
B.
Clone the disk.
C.
Collect the most volatile data
Answers
C.
Collect the most volatile data
D.
Copy the relevant log files
Answers
D.
Copy the relevant log files
Suggested answer: C

Explanation:

The first step in forensic analysis is to collect the most volatile data, which is the information that would be lost when the power is turned off or the system is rebooted. This includes the contents of memory (RAM) and other temporary data that are stored in caches or buffers. A memory dump captures this data and should be done before other less volatile data is collected, like hard drive images or log files, to ensure the most accurate and comprehensive capture of the system's state at the time of the incident.

asked 02/10/2024
Bouchtig, Yassine
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first