nerdexam
EC-Council

312-49V11 · Question #18

As part of a digital investigation, a forensic expert needs to analyze a server suspected of hosting illicit content. The server has multiple volumes and partitions. To proceed with the analysis…

The correct answer is D. Non-volatile storage retains data even when powered off. This question aligns with CHFI v11 objectives under Computer Forensics Fundamentals and Digital Evidence and Storage Media. In forensic investigations involving servers suspected of hosting illicit content, investigators must focus on storage locations that reliably preserve…

Data Acquisition and Duplication

Question

As part of a digital investigation, a forensic expert needs to analyze a server suspected of hosting illicit content. The server has multiple volumes and partitions. To proceed with the analysis, the investigator needs to gather evidence from a location on the server where user files, documents, and system metadata are typically stored. Which of the following storage locations should the investigator primarily focus on for this purpose?

Options

  • AVolatile memory stores temporary data.
  • BExternal backup devices store data but may not always contain relevant information.
  • CNetwork storage systems may require additional access controls.
  • DNon-volatile storage retains data even when powered off.

How the community answered

(36 responses)
  • A
    17% (6)
  • B
    3% (1)
  • C
    8% (3)
  • D
    72% (26)

Explanation

This question aligns with CHFI v11 objectives under Computer Forensics Fundamentals and Digital Evidence and Storage Media. In forensic investigations involving servers suspected of hosting illicit content, investigators must focus on storage locations that reliably preserve data over time. CHFI v11 emphasizes that non-volatile storage--such as hard disk drives (HDDs), solid-state drives (SSDs), RAID arrays, and other persistent storage media--is the primary repository for user files, documents, system files, logs, and file system metadata. Non-volatile storage retains data even when the system is powered off, making it essential for post-incident forensic analysis. This includes directory structures, timestamps, access control lists, deleted file remnants, and application data, all of which are critical for reconstructing user activity and determining the presence and origin of illicit content. Volatile memory (RAM) contains temporary data such as running processes and network connections, which is useful during live analysis but does not store long-term user files. External backups and network storage may contain copies of data but are secondary sources and may not reflect the system's current state. Therefore, consistent with CHFI v11 forensic principles, the investigator should primarily focus on non-volatile storage, as it is the most reliable and comprehensive source of persistent digital evidence.

Topics

#non-volatile storage#digital evidence#storage types#forensic targets

Community Discussion

No community discussion yet for this question.

Full 312-49V11 Practice