ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 102 - CS0-003 discussion

Report
Export

A security analyst must preserve a system hard drive that was involved in a litigation request Which of the following is the best method to ensure the data on the device is not modified?

A.
Generate a hash value and make a backup image.
Answers
A.
Generate a hash value and make a backup image.
B.
Encrypt the device to ensure confidentiality of the data.
Answers
B.
Encrypt the device to ensure confidentiality of the data.
C.
Protect the device with a complex password.
Answers
C.
Protect the device with a complex password.
D.
Perform a memory scan dump to collect residual data.
Answers
D.
Perform a memory scan dump to collect residual data.
Suggested answer: A

Explanation:

Generating a hash value and making a backup image is the best method to ensure the data on the device is not modified, as it creates a verifiable copy of the original data that can be used for forensic analysis. Encrypting the device, protecting it with a password, or performing a memory scan dump do not prevent the data from being altered or deleted. Verified

Reference:CompTIA CySA+ CS0-002 Certification Study Guide, page 3291

asked 02/10/2024
George Mabry
51 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first