312-49 · Question #211
Why should you never power on a computer that you need to acquire digital evidence from?
The correct answer is A. When the computer boots up, files are written to the computer rendering the data nclean?When. When a computer boots up, the operating system immediately begins writing to the hard drive: it updates log files, writes to the registry, creates or modifies temporary files, updates file access timestamps, and may even run startup programs that write additional data. All of…
Question
Why should you never power on a computer that you need to acquire digital evidence from?
Options
- AWhen the computer boots up, files are written to the computer rendering the data nclean?When
- BWhen the computer boots up, the system cache is cleared which could destroy evidence
- CWhen the computer boots up, data in the memory buffer is cleared which could destroy
- DPowering on a computer has no affect when needing to acquire digital evidence from it
How the community answered
(55 responses)- A93% (51)
- B4% (2)
- C2% (1)
- D2% (1)
Explanation
When a computer boots up, the operating system immediately begins writing to the hard drive: it updates log files, writes to the registry, creates or modifies temporary files, updates file access timestamps, and may even run startup programs that write additional data. All of these writes alter the state of the disk from what it was at the time of the incident, effectively contaminating the evidence. Overwritten sectors may contain deleted files that were potential evidence. This is why forensic best practice requires acquiring a bit-for-bit image of the drive using a hardware or software write-blocker before the system is ever powered on, preserving the original state of all data.
Topics
Community Discussion
No community discussion yet for this question.