GCFA · Question #249
Which of the following steps are generally followed in computer forensic examinations? Each correct answer represents a complete solution. Choose three.
The correct answer is B. Acquire C. Authenticate D. Analyze. Computer forensic examinations follow a structured process of acquiring evidence, authenticating it, and analyzing it - not encrypting it.
Question
Which of the following steps are generally followed in computer forensic examinations? Each correct answer represents a complete solution. Choose three.
Options
- AEncrypt
- BAcquire
- CAuthenticate
- DAnalyze
How the community answered
(66 responses)- A27% (18)
- B73% (48)
Why each option
Computer forensic examinations follow a structured process of acquiring evidence, authenticating it, and analyzing it - not encrypting it.
Encryption is a data protection technique, not a step in the forensic examination process - applying encryption to evidence would alter it and compromise forensic integrity.
Acquisition is the first critical forensic step where evidence is collected using forensically sound methods to preserve its original state and maintain chain of custody.
Authentication verifies the integrity of collected evidence, typically using hash values (MD5, SHA-256) to confirm the copy is identical to the original and has not been altered.
Analysis involves systematically examining the authenticated evidence using forensic tools to extract relevant artifacts, timelines, and findings that support the investigation.
Concept tested: Computer forensic examination process steps
Source: https://www.nist.gov/system/files/documents/2017/05/09/SP800-101Rev1.pdf
Topics
Community Discussion
No community discussion yet for this question.