QuestionQ46

Threat Intelligence in Incident Response

John, a forensic officer, was working on a criminal case. He used imaging software to create a copy of data from the suspect device onto a storage medium for further investigation. To create an image of the original data, John used a software application that prevents an unauthorized user from altering the image content on the storage media, thus preserving an unchanged image copy.

Identify the data-acquisition step John performed in this scenario.

  • A Sanitized the target media
  • B Planned for contingency
  • C Validated data acquisition
  • D Enabled write protection on the evidence media
Explanation

Write protection prevents changes to the evidence media or its forensic image, preserving the acquired data as an unaltered copy for forensic integrity.

Community Discussion

No comments yet. Be the first to start the discussion!