nerdexam
EC-Council

312-49 · Question #290

Chris has been called upon to investigate a hacking incident reported by one of his clients. The company suspects the involvement of an insider accomplice in the attack. Upon reaching the incident…

The correct answer is B. Prepare the system for acquisition; Connect the target media; Copy the media; Secure the. After physically securing the scene, powering down, and labeling all connectors, the correct forensic acquisition sequence is: (1) Prepare the system for acquisition - configure the forensic workstation, attach a hardware write-blocker to prevent accidental writes to the…

Submitted by ahmad_uae· Apr 18, 2026Computer Forensics Investigation Process

Question

Chris has been called upon to investigate a hacking incident reported by one of his clients. The company suspects the involvement of an insider accomplice in the attack. Upon reaching the incident scene, Chris secures the physical area, records the scene using visual media. He shuts the system down by pulling the power plug so that he does not disturb the system in any way. He labels all cables and connectors prior to disconnecting any. What do you think would be the next sequence of events?

Options

  • AConnect the target media; Prepare the system for acquisition; Secure the evidence; Copy the
  • BPrepare the system for acquisition; Connect the target media; Copy the media; Secure the
  • CConnect the target media; Delete the system for acquisition; Secure the evidence; Copy the
  • DSecure the evidence; Prepare the system for acquisition; Connect the target media; Copy the

How the community answered

(70 responses)
  • A
    13% (9)
  • B
    77% (54)
  • C
    3% (2)
  • D
    7% (5)

Explanation

After physically securing the scene, powering down, and labeling all connectors, the correct forensic acquisition sequence is: (1) Prepare the system for acquisition - configure the forensic workstation, attach a hardware write-blocker to prevent accidental writes to the evidence drive, and prepare forensic imaging software. (2) Connect the target media - attach the evidence hard drive (through the write-blocker) and a clean destination drive to receive the forensic image. (3) Copy the media - perform a bit-for-bit forensic image (e.g., using dd or FTK Imager), verifying integrity with hash values. (4) Secure the evidence - seal, tag, and store both the original drive and the image in a secure, documented location to maintain chain of custody. This order ensures evidence integrity is never compromised before imaging is complete.

Topics

#Digital Forensics Process#Evidence Acquisition#Forensic Imaging#Incident Scene Procedures

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice