CHAPTER 3 ASSESSMENT
1. To preserve digital evidence, an investigator should ________.
make two copies of each evidence item using a single imaging tool
make a single copy of each evidence item using an approved imaging tool
make two copies of each evidence item using different imaging tools
store only the original evidence item
2. Bob was asked to make a copy of all the evidence from the compromised system. Melanie did a DOS copy of all the files on the system. What would be the primary reason for you to recommend for or against using a disk-imaging tool?
A disk-imaging tool would check for internal self-checking and validation and have an MD5 checksum.
The evidence file format will contain case data entered by the examiner and encrypted ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access