QuestionQ199

Procedures and Methodology

You are a forensic analyst at a prominent technology company that suspects one of its software developers has been selling proprietary source code. The suspect’s secured computer is a macOS machine and is awaiting examination. You have been assigned to obtain a forensically sound copy of the suspect’s system data. Given the circumstances and the possibility of macOS-specific malware on the suspect’s computer, which method is the best approach for obtaining a forensically sound copy of the data?

  • A Disconnect the suspect’s hard drive and connect it to a forensic workstation.
  • B Conduct a live acquisition using a software write-blocker.
  • C Remotely acquire the data via network-based acquisition.
  • D Use a forensic boot disk to bypass the macOS and directly access the disk for acquisition.
Explanation

Booting from a forensic disk permits an offline, controlled acquisition that bypasses the potentially compromised installed macOS, preventing macOS-specific malware from running during collection and allowing direct disk imaging. SWGDE guidance recognizes booting an evidence computer with a forensic operating-system environment as an acquisition method and requires appropriate data-protection measures for a forensically sound examination.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!