CompTIA
JK0-018 · Question #456
JK0-018 Question #456: Real Exam Question with Answer & Explanation
Sign in or unlock JK0-018 to reveal the answer and full explanation for question #456. The question stem and answer options stay visible for context.
Question
An incident response team member needs to perform a forensics examination but does not have the required hardware. Which of the following will allow the team member to perform the examination with minimal impact to the potential evidence?
Options
- AUsing a software file recovery disc
- BMounting the drive in read-only mode
- CImaging based on order of volatility
- DHashing the image after capture
Unlock JK0-018 to see the answer
You've previewed enough free JK0-018 questions. Unlock JK0-018 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.