nerdexam
GIAC

GCFA · Question #88

Adam works as a professional Computer Hacking Forensic Investigator. He has been called by the FBI to examine data of the hard disk, which is seized from the house of a suspected terrorist. Adam decid

The correct answer is C. ImageMASSter Solo-3. The ImageMASSter Solo-3 is a portable forensic hardware imaging device that supports IDE, SATA, SCSI, and flash card interfaces while generating MD5 and CRC32 hashes during acquisition.

Advanced Incident Response & Digital Forensics Fundamentals

Question

Adam works as a professional Computer Hacking Forensic Investigator. He has been called by the FBI to examine data of the hard disk, which is seized from the house of a suspected terrorist. Adam decided to acquire an image of the suspected hard drive. He uses a forensic hardware tool, which is capable of capturing data from IDE, Serial ATA, SCSI devices, and flash cards. This tool can also produce MD5 and CRC32 hash while capturing the data. Which of the following tools is Adam using?

Options

  • AWipe MASSter
  • BImageMASSter 4002i
  • CImageMASSter Solo-3
  • DFireWire DriveDock

How the community answered

(41 responses)
  • A
    12% (5)
  • B
    2% (1)
  • C
    78% (32)
  • D
    7% (3)

Why each option

The ImageMASSter Solo-3 is a portable forensic hardware imaging device that supports IDE, SATA, SCSI, and flash card interfaces while generating MD5 and CRC32 hashes during acquisition.

AWipe MASSter

Wipe MASSter is an ICS hardware tool designed for sanitizing and destroying data on storage media, not for forensic imaging or evidence acquisition.

BImageMASSter 4002i

The ImageMASSter 4002i is a different ICS model with a distinct feature set and interface configuration that does not match all the specific capabilities described in the question.

CImageMASSter Solo-3Correct

The ImageMASSter Solo-3, manufactured by Intelligent Computer Solutions (ICS), is a standalone forensic hardware duplicator designed to acquire forensic images from IDE, Serial ATA, SCSI, and flash card storage devices - exactly matching the question description. It produces MD5 and CRC32 hash values during the capture process to cryptographically verify data integrity, a critical chain-of-custody requirement in forensic investigations. Its multi-interface support combined with built-in hash generation makes it a comprehensive tool used by law enforcement agencies for field evidence collection.

DFireWire DriveDock

FireWire DriveDock is a drive enclosure and connectivity adapter that provides FireWire interface access to hard drives but is not a forensic imaging tool and lacks native hash generation or SCSI and flash card support.

Concept tested: Forensic hardware imaging tool identification and multi-interface capabilities

Topics

#forensic imaging#ImageMASSter#disk acquisition#hash verification

Community Discussion

No community discussion yet for this question.

Full GCFA Practice