nerdexam
Access_Data

A30-327 · Question #58

When previewing a physical drive on a local machine with FTK Imager, which statement is true?

The correct answer is D. FTK Imager should always be used in conjunction with a hardware write protect device to prevent writes to suspect media. D is correct because FTK Imager does not contain built-in write-blocking capabilities that meet forensic standards - it can read a physical drive, but nothing in the software itself prevents writes from occurring to that suspect media. Hardware write blockers (e.g., Tableau…

Forensic Process and Best Practices

Question

When previewing a physical drive on a local machine with FTK Imager, which statement is true?

Options

  • AFTK Imager can block calls to interrupt 13h and prevent writes to suspect media.
  • BFTK Imager can operate from a USB drive, thus preventing writes to suspect media.
  • CFTK Imager can operate via a DOS boot disk, thus preventing writes to suspect media.
  • DFTK Imager should always be used in conjunction with a hardware write protect device to prevent writes to suspect media.

How the community answered

(26 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    4% (1)
  • D
    85% (22)

Explanation

D is correct because FTK Imager does not contain built-in write-blocking capabilities that meet forensic standards - it can read a physical drive, but nothing in the software itself prevents writes from occurring to that suspect media. Hardware write blockers (e.g., Tableau, WiebeTech) operate at the physical layer and are the forensically accepted standard for evidence integrity.

A is wrong because FTK Imager does not intercept INT 13h BIOS calls, and even tools that historically did this were considered unreliable because modern operating systems and direct I/O paths can bypass INT 13h entirely.

B and C are wrong for the same reason: where FTK Imager runs from (USB drive or DOS boot disk) has no bearing on whether writes are blocked to a separate suspect drive - running from a different medium doesn't protect the evidence disk.

Memory tip: Think "hardware blocks hardware." A software tool running on the same OS that controls the evidence drive can never fully guarantee write protection - only a physical hardware write blocker sitting between the drive and the machine can do that reliably.

Topics

#hardware write blockers#evidence integrity#FTK Imager#write protection

Community Discussion

No community discussion yet for this question.

Full A30-327 Practice