QuestionQ199
Procedures and MethodologyYou are a forensic analyst at a prominent technology company that suspects one of its software developers has been selling proprietary source code. The suspect’s secured computer is a macOS machine and is awaiting examination. You have been assigned to obtain a forensically sound copy of the suspect’s system data. Given the circumstances and the possibility of macOS-specific malware on the suspect’s computer, which method is the best approach for obtaining a forensically sound copy of the data?
- A Disconnect the suspect’s hard drive and connect it to a forensic workstation.
- B Conduct a live acquisition using a software write-blocker.
- C Remotely acquire the data via network-based acquisition.
- D Use a forensic boot disk to bypass the macOS and directly access the disk for acquisition.
Community Discussion