312-49V11 · Question #19
Madison, a forensic investigator, has been assigned to investigate a case of email fraud, where the suspect allegedly used a compromised email account to send phishing emails to several victims. As…
The correct answer is A. Seizing the computer and email accounts. This question aligns with CHFI v11 objectives under Regulations, Policies, and Ethics and Search and Seizure of Digital Evidence. Before any forensic examination can legally take place-- especially an on-site examination involving computers and email servers--the investigator…
Question
Madison, a forensic investigator, has been assigned to investigate a case of email fraud, where the suspect allegedly used a compromised email account to send phishing emails to several victims. As part of the investigation, Madison must first obtain permission to conduct an on-site examination of the suspect's machine and the email server used for the fraudulent emails. What is the initial step that Madison must take before proceeding with the forensic examination?
Options
- ASeizing the computer and email accounts
- BRetrieving email headers
- CRecovering deleted email messages
- DAnalyzing email headers
How the community answered
(32 responses)- A84% (27)
- B3% (1)
- C3% (1)
- D9% (3)
Explanation
This question aligns with CHFI v11 objectives under Regulations, Policies, and Ethics and Search and Seizure of Digital Evidence. Before any forensic examination can legally take place-- especially an on-site examination involving computers and email servers--the investigator must obtain proper legal authorization. In practice, this authorization is enforced through the lawful seizure of systems and accounts, either via a search warrant, court order, or explicit consent from the system owner. CHFI v11 emphasizes that digital forensic investigations must strictly follow legal procedures to ensure evidence admissibility and avoid violations of privacy or due process. Seizing the computer systems and email accounts establishes lawful control over the evidence, enables proper chain of custody documentation, and prevents further tampering or destruction of data. Only after seizure and authorization can investigators safely proceed with technical tasks such as retrieving email headers, recovering deleted messages, or analyzing email content.
Topics
Community Discussion
No community discussion yet for this question.