QuestionQ46
Threat Intelligence in Incident ResponseJohn, a forensic officer, was working on a criminal case. He used imaging software to create a copy of data from the suspect device onto a storage medium for further investigation. To create an image of the original data, John used a software application that prevents an unauthorized user from altering the image content on the storage media, thus preserving an unchanged image copy.
Identify the data-acquisition step John performed in this scenario.
- A Sanitized the target media
- B Planned for contingency
- C Validated data acquisition
- D Enabled write protection on the evidence media
Community Discussion