220-801 · Question #39
Which of the following is NOT a best practice when prohibited activity is suspected?
The correct answer is B. Turn off the computer. Turning off the computer is NOT a best practice because it destroys volatile evidence. Data held in RAM-such as running processes, open network connections, encryption keys, and temporary files-is permanently lost when power is removed. This can compromise a forensic…
Question
Which of the following is NOT a best practice when prohibited activity is suspected?
Options
- ABack up the hard drive
- BTurn off the computer
- CDocument the incident
- DIdentify the content
How the community answered
(25 responses)- A16% (4)
- B72% (18)
- C4% (1)
- D8% (2)
Explanation
Turning off the computer is NOT a best practice because it destroys volatile evidence. Data held in RAM-such as running processes, open network connections, encryption keys, and temporary files-is permanently lost when power is removed. This can compromise a forensic investigation. The correct practices are to document the incident (C), identify the content (D), and back up the hard drive (A) to preserve non-volatile evidence, while leaving the system running to allow forensic capture of volatile data by trained personnel.
Topics
Community Discussion
No community discussion yet for this question.