SSCP · Question #953
In the process of gathering evidence from a computer attack, a system administrator took a series of actions which are listed below. Can you identify which one of these actions has compromised the who
The correct answer is D. Displayed the contents of a folder. Displaying the directory contents of a folder can alter the last access time on each listed file. Using a write blocker is wrong because using a write blocker ensure that you cannot modify the data on the host and it prevent the host from writing to its hard drives. Made a full-d
Question
In the process of gathering evidence from a computer attack, a system administrator took a series of actions which are listed below. Can you identify which one of these actions has compromised the whole evidence collection process?
Options
- AUsing a write blocker
- BMade a full-disk image
- CCreated a message digest for log files
- DDisplayed the contents of a folder
How the community answered
(36 responses)- A8% (3)
- B3% (1)
- C6% (2)
- D83% (30)
Explanation
Displaying the directory contents of a folder can alter the last access time on each listed file. Using a write blocker is wrong because using a write blocker ensure that you cannot modify the data on the host and it prevent the host from writing to its hard drives. Made a full-disk image is wrong because making a full-disk image can preserve all data on a hard disk, including deleted files and file fragments. Created a message digest for log files is wrong because creating a message digest for log files. A message digest is a cryptographic checksum that can demonstrate that the integrity of a file has not been compromised (e.g. changes to the content of a log file) Domain: LEGAL, REGULATIONS, COMPLIANCE AND INVESTIGATIONS
Topics
Community Discussion
No community discussion yet for this question.