312-49V11 · Question #116
An organization has suffered a significant data breach and called in a Computer Hacking Forensics Investigator (CHFI) to gather evidence. The investigator has decided to use the dead acquisition…
The correct answer is C. Active network connections. Dead acquisition is performed when the system is powered off (or storage is acquired offline). It captures non-volatile data from disk such as browser cache, unallocated space, and boot sectors. Active network connections are volatile/live-state artifacts and cannot be captured…
Question
An organization has suffered a significant data breach and called in a Computer Hacking Forensics Investigator (CHFI) to gather evidence. The investigator has decided to use the dead acquisition technique to gather nonvolatile data from the compromised system. Which of the following would NOT typically be acquired during this type of forensic data acquisition process?
Options
- AWeb browser cache
- BUnallocated drive space
- CActive network connections
- DBoot sectors
How the community answered
(22 responses)- A5% (1)
- B9% (2)
- C86% (19)
Explanation
Dead acquisition is performed when the system is powered off (or storage is acquired offline). It captures non-volatile data from disk such as browser cache, unallocated space, and boot sectors. Active network connections are volatile/live-state artifacts and cannot be captured via dead
Topics
Community Discussion
No community discussion yet for this question.