312-49 · Question #290
Chris has been called upon to investigate a hacking incident reported by one of his clients. The company suspects the involvement of an insider accomplice in the attack. Upon reaching the incident…
The correct answer is B. Prepare the system for acquisition; Connect the target media; Copy the media; Secure the. After physically securing the scene, powering down, and labeling all connectors, the correct forensic acquisition sequence is: (1) Prepare the system for acquisition - configure the forensic workstation, attach a hardware write-blocker to prevent accidental writes to the…
Question
Chris has been called upon to investigate a hacking incident reported by one of his clients. The company suspects the involvement of an insider accomplice in the attack. Upon reaching the incident scene, Chris secures the physical area, records the scene using visual media. He shuts the system down by pulling the power plug so that he does not disturb the system in any way. He labels all cables and connectors prior to disconnecting any. What do you think would be the next sequence of events?
Options
- AConnect the target media; Prepare the system for acquisition; Secure the evidence; Copy the
- BPrepare the system for acquisition; Connect the target media; Copy the media; Secure the
- CConnect the target media; Delete the system for acquisition; Secure the evidence; Copy the
- DSecure the evidence; Prepare the system for acquisition; Connect the target media; Copy the
How the community answered
(70 responses)- A13% (9)
- B77% (54)
- C3% (2)
- D7% (5)
Explanation
After physically securing the scene, powering down, and labeling all connectors, the correct forensic acquisition sequence is: (1) Prepare the system for acquisition - configure the forensic workstation, attach a hardware write-blocker to prevent accidental writes to the evidence drive, and prepare forensic imaging software. (2) Connect the target media - attach the evidence hard drive (through the write-blocker) and a clean destination drive to receive the forensic image. (3) Copy the media - perform a bit-for-bit forensic image (e.g., using dd or FTK Imager), verifying integrity with hash values. (4) Secure the evidence - seal, tag, and store both the original drive and the image in a secure, documented location to maintain chain of custody. This order ensures evidence integrity is never compromised before imaging is complete.
Topics
Community Discussion
No community discussion yet for this question.