nerdexam
CompTIA

SY0-301 · Question #456

An incident response team member needs to perform a forensics examination but does not have the required hardware. Which of the following will allow the team member to perform the examination with…

The correct answer is B. Mounting the drive in read-only mode. In digital forensics, preserving evidence integrity is paramount. Mounting a drive in read-only mode ensures that no writes occur to the original media during examination, preventing any alteration of potential evidence. Using a software file recovery disc (A) risks writing to…

Security operations

Question

An incident response team member needs to perform a forensics examination but does not have the required hardware. Which of the following will allow the team member to perform the examination with minimal impact to the potential evidence?

Options

  • AUsing a software file recovery disc
  • BMounting the drive in read-only mode
  • CImaging based on order of volatility
  • DHashing the image after capture

How the community answered

(46 responses)
  • A
    9% (4)
  • B
    74% (34)
  • C
    4% (2)
  • D
    13% (6)

Explanation

In digital forensics, preserving evidence integrity is paramount. Mounting a drive in read-only mode ensures that no writes occur to the original media during examination, preventing any alteration of potential evidence. Using a software file recovery disc (A) risks writing to the drive. Imaging based on order of volatility (C) is a best practice for capturing volatile data but does not directly address the hardware limitation or evidence preservation during examination. Hashing after capture (D) verifies integrity post-acquisition but does not prevent evidence modification during examination. Read-only mounting is the quickest way to protect evidence with minimal hardware requirements.

Topics

#digital forensics#evidence preservation#read-only mount#incident response

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice