Chapter 9 Questions and answers by subject area
Evidence collection
- Q: When evidence is processed in the lab, do we work on the evidence or on a copy of the evidence?
- A: Only on a copy of the evidence.
- Q: Before booting a computer with a diskette, what critical item should be checked?
- A: CMOS settings to ensure the diskette boots first. If you boot from the hard drive, you will corrupt or lose evidence. And yes, some areas of the world are still using diskettes so I’m keeping such items in this newer version of the book.
- Q: Who should be the first person sitting with you at the victim’s machine?
- A: A system administrator who is an expert on that system type.
- Q: What do you want to obtain from a dot matrix or ...
Get Cyber Crime Investigator's Field Guide, 3rd Edition now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.