nerdexam
GIAC

GCFA · Question #249

Which of the following steps are generally followed in computer forensic examinations? Each correct answer represents a complete solution. Choose three.

The correct answer is B. Acquire C. Authenticate D. Analyze. Computer forensic examinations follow a structured process of acquiring evidence, authenticating it, and analyzing it - not encrypting it.

Advanced Incident Response & Digital Forensics Fundamentals

Question

Which of the following steps are generally followed in computer forensic examinations? Each correct answer represents a complete solution. Choose three.

Options

  • AEncrypt
  • BAcquire
  • CAuthenticate
  • DAnalyze

How the community answered

(66 responses)
  • A
    27% (18)
  • B
    73% (48)

Why each option

Computer forensic examinations follow a structured process of acquiring evidence, authenticating it, and analyzing it - not encrypting it.

AEncrypt

Encryption is a data protection technique, not a step in the forensic examination process - applying encryption to evidence would alter it and compromise forensic integrity.

BAcquireCorrect

Acquisition is the first critical forensic step where evidence is collected using forensically sound methods to preserve its original state and maintain chain of custody.

CAuthenticateCorrect

Authentication verifies the integrity of collected evidence, typically using hash values (MD5, SHA-256) to confirm the copy is identical to the original and has not been altered.

DAnalyzeCorrect

Analysis involves systematically examining the authenticated evidence using forensic tools to extract relevant artifacts, timelines, and findings that support the investigation.

Concept tested: Computer forensic examination process steps

Source: https://www.nist.gov/system/files/documents/2017/05/09/SP800-101Rev1.pdf

Topics

#forensic examination steps#evidence acquisition#authentication#forensic analysis

Community Discussion

No community discussion yet for this question.

Full GCFA Practice