QuestionQ11

Incident Response Concepts and Application

What type of media should the IR team handle while seeking to understand an incident’s root cause?

  • A Restored media from full backup of the infected host
  • B Media from the infected host, copied to the dedicated IR host
  • C Original media from the infected host
  • D Bit-for-bit image from the infected host
Explanation

A bit-for-bit forensic image preserves the full contents of the infected host, including unallocated and slack space, while allowing analysis without modifying the original evidence. NIST recommends performing subsequent analysis on copied media and preserving the original securely.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!