nerdexam
EC-Council

312-49V11 · Question #115

A cybersecurity forensics investigator is tasked with acquiring data from a suspect's drive for a civil litigation case. The suspect drive is 1TB, and due to time constraints, the investigator…

The correct answer is D. Use a reliable data acquisition tool to make a copy of the original drive. Since the original drive cannot be retained, the investigator must create a defensible copy using a trusted acquisition tool that supports integrity verification (e.g., hashing) and proper logging. This ensures the evidence remains admissible and repeatable. Logical acquisition…

Digital Evidence Collection and Acquisition

Question

A cybersecurity forensics investigator is tasked with acquiring data from a suspect's drive for a civil litigation case. The suspect drive is 1TB, and due to time constraints, the investigator decides to prioritize and acquire only data of evidentiary value. The original drive cannot be retained. In this context, which of the following steps should the investigator prioritize?

Options

  • AOpt for disk-to-image copying for the large suspect drive
  • BExecute logical acquisition considering the one-time opportunity to capture data
  • CUtilize DriveSpace or DoubleSpace to reduce the data size
  • DUse a reliable data acquisition tool to make a copy of the original drive

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    14% (4)
  • C
    7% (2)
  • D
    75% (21)

Explanation

Since the original drive cannot be retained, the investigator must create a defensible copy using a trusted acquisition tool that supports integrity verification (e.g., hashing) and proper logging. This ensures the evidence remains admissible and repeatable. Logical acquisition (B) may miss critical metadata or artifacts, and compression tools (C) are not acquisition methods.

Topics

#data acquisition#forensic imaging#evidence preservation#civil litigation

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice