nerdexam
EC-Council

312-49V11 · Question #2

312-49V11 Question #2: Real Exam Question with Answer & Explanation

Sign in or unlock 312-49V11 to reveal the answer and full explanation for question #2. The question stem and answer options stay visible for context.

Question

Following a cybercrime incident, a forensic investigator is conducting a detailed examination of a suspect's digital device. The investigator needs to preserve and analyze the disk images without being restricted by various image file formats tied to commercial software, which may limit the investigator's ability to work with a range of analysis platforms. The investigator chooses a simple, straightforward, and uncompressed format that can be easily accessed and analyzed using a wide range of forensic tools and platforms, without the need for specialized software. Which data acquisition format should the investigator use in this case?

Options

  • AAdopt the raw format that is commonly used in digital evidence investigations.
  • BChoose the AFF4 format, which offers advanced features for comprehensive analysis.
  • CEmploy the advanced forensics format for storing metadata and disk images.
  • DUse a proprietary format that is compatible with specific commercial software.

Unlock 312-49V11 to see the answer

You've previewed enough free 312-49V11 questions. Unlock 312-49V11 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full 312-49V11 Practice