QuestionQ39
Data Collection and Sources of Threat IntelligenceSarah, a forensic investigator, is handling a criminal case. She was provided with all of the suspect devices. Sarah uses imaging software to duplicate the original data from the suspect devices. However, the tool she used could not image the data because the suspect version of the drive was very old and incompatible with the imaging software. Therefore, Sarah used an alternative data-acquisition technique and successfully imaged the data.
Which of the following data-acquisition techniques did Sarah use in this scenario?
- A Sparse acquisition
- B Bit-stream disk-to-disk
- C Bit-stream disk-to-image-file
- D Logical acquisition
Community Discussion