nerdexam
EC-Council

312-49V11 · Question #116

An organization has suffered a significant data breach and called in a Computer Hacking Forensics Investigator (CHFI) to gather evidence. The investigator has decided to use the dead acquisition…

The correct answer is C. Active network connections. Dead acquisition is performed when the system is powered off (or storage is acquired offline). It captures non-volatile data from disk such as browser cache, unallocated space, and boot sectors. Active network connections are volatile/live-state artifacts and cannot be captured…

Digital Evidence Collection and Acquisition

Question

An organization has suffered a significant data breach and called in a Computer Hacking Forensics Investigator (CHFI) to gather evidence. The investigator has decided to use the dead acquisition technique to gather nonvolatile data from the compromised system. Which of the following would NOT typically be acquired during this type of forensic data acquisition process?

Options

  • AWeb browser cache
  • BUnallocated drive space
  • CActive network connections
  • DBoot sectors

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    9% (2)
  • C
    86% (19)

Explanation

Dead acquisition is performed when the system is powered off (or storage is acquired offline). It captures non-volatile data from disk such as browser cache, unallocated space, and boot sectors. Active network connections are volatile/live-state artifacts and cannot be captured via dead

Topics

#dead acquisition#nonvolatile data#volatile data#forensic acquisition

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice