nerdexam
(ISC)2

SSCP · Question #953

In the process of gathering evidence from a computer attack, a system administrator took a series of actions which are listed below. Can you identify which one of these actions has compromised the who

The correct answer is D. Displayed the contents of a folder. Displaying the directory contents of a folder can alter the last access time on each listed file. Using a write blocker is wrong because using a write blocker ensure that you cannot modify the data on the host and it prevent the host from writing to its hard drives. Made a full-d

Submitted by fatema_kw· Apr 18, 2026Incident Response and Recovery

Question

In the process of gathering evidence from a computer attack, a system administrator took a series of actions which are listed below. Can you identify which one of these actions has compromised the whole evidence collection process?

Options

  • AUsing a write blocker
  • BMade a full-disk image
  • CCreated a message digest for log files
  • DDisplayed the contents of a folder

How the community answered

(36 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    6% (2)
  • D
    83% (30)

Explanation

Displaying the directory contents of a folder can alter the last access time on each listed file. Using a write blocker is wrong because using a write blocker ensure that you cannot modify the data on the host and it prevent the host from writing to its hard drives. Made a full-disk image is wrong because making a full-disk image can preserve all data on a hard disk, including deleted files and file fragments. Created a message digest for log files is wrong because creating a message digest for log files. A message digest is a cryptographic checksum that can demonstrate that the integrity of a file has not been compromised (e.g. changes to the content of a log file) Domain: LEGAL, REGULATIONS, COMPLIANCE AND INVESTIGATIONS

Topics

#Digital Forensics#Evidence Collection#Incident Response#Evidence Integrity

Community Discussion

No community discussion yet for this question.

Full SSCP Practice