QuestionQ24

Enterprise Environment Incident Response

Adam is a professional Computer Hacking Forensic Investigator. The FBI has called him to examine data from a hard disk seized at the home of a suspected terrorist. Adam decides to acquire an image of the suspect hard drive. He uses a forensic hardware tool capable of capturing data from IDE, Serial ATA, SCSI devices, and flash cards. The tool can also generate MD5 and CRC32 hashes while it captures the data. Which of the following tools is Adam using?

  • A Wipe MASSter
  • B ImageMASSter 4002i
  • C ImageMASSter Solo-3
  • D FireWire DriveDock
Explanation

ImageMASSter Solo-3 Forensic is a portable forensic data-acquisition device for IDE, SATA, and SCSI media, with support for flash-media acquisition through adapters. Its hashing functions include MD5 and CRC32, allowing an examiner to verify the integrity of captured evidence.

Community Discussion

No comments yet. Be the first to start the discussion!