nerdexam
EC-Council

312-49 · Question #443

A state department site was recently attacked and all the servers had their disks erased. The incident response team sealed the area and commenced investigation. During evidence collection they came…

The correct answer is C. They tampered with evidence by using it. The incident response team made a critical forensic error by running the zip disk on an isolated system to examine its contents. Proper digital forensics requires that evidence never be used or executed directly. Instead, investigators must first create a verified forensic…

Submitted by kim_seoul· Apr 18, 2026Computer Forensics Investigation Process

Question

A state department site was recently attacked and all the servers had their disks erased. The incident response team sealed the area and commenced investigation. During evidence collection they came across a zip disks that did not have the standard labeling on it. The incident team ran the disk on an isolated system and found that the system disk was accidentally erased. They decided to call in the FBI for further investigation. Meanwhile, they short listed possible suspects including three summer interns. Where did the incident team go wrong?

Options

  • AThey examined the actual evidence on an unrelated system
  • BThey attempted to implicate personnel without proof
  • CThey tampered with evidence by using it
  • DThey called in the FBI without correlating with the fingerprint data

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    7% (2)
  • C
    77% (23)
  • D
    13% (4)

Explanation

The incident response team made a critical forensic error by running the zip disk on an isolated system to examine its contents. Proper digital forensics requires that evidence never be used or executed directly. Instead, investigators must first create a verified forensic image (bit-for-bit copy) of the media and work only from that copy. By booting/running the actual disk, they inadvertently caused the system disk to be erased - an irreversible alteration of the original evidence. This constitutes tampering with evidence, which can invalidate the integrity of the entire investigation and make evidence inadmissible in court. The correct procedure is to write-block the media, image it using tools like FTK Imager or dd, verify the hash, and then analyze only the copy.

Topics

#Evidence Handling#Forensic Best Practices#Evidence Integrity

Community Discussion

No community discussion yet for this question.

Full 312-49 Practice