CompTIA
SY0-301 · Question #456
SY0-301 Question #456: Real Exam Question with Answer & Explanation
Sign in or unlock SY0-301 to reveal the answer and full explanation for question #456. The question stem and answer options stay visible for context.
Question
An incident response team member needs to perform a forensics examination but does not have the required hardware. Which of the following will allow the team member to perform the examination with minimal impact to the potential evidence?
Options
- AUsing a software file recovery disc
- BMounting the drive in read-only mode
- CImaging based on order of volatility
- DHashing the image after capture
Unlock SY0-301 to see the answer
You've previewed enough free SY0-301 questions. Unlock SY0-301 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.