During a corporate security incident investigation, a security analyst needs to create an exact duplicate of a suspect's hard drive for forensic analysis. Which of the following approaches is the BEST choice for maintaining evidence admissibility?
Taking screenshots of active processes and file directories
Running a virus scan on the original drive to identify malware
Copying visible files to an external drive for analysis
The correct answer is creating a bit-by-bit image using write blockers. When performing digital forensics, maintaining evidence integrity is paramount. A bit-by-bit image (also called a forensic image or bitstream copy) creates an exact duplicate of the original media at the binary level, including deleted files, slack space, and unallocated space. Write blockers are hardware or software tools that prevent any modifications to the original evidence during the imaging process, ensuring that the original data remains unchanged and maintaining the chain of custody. This approach preserves the integrity of the evidence and follows proper forensic procedures.
Hashing the original and the copy ensures that they are identical, which is part of the verification process but not the primary imaging method. Taking screenshots provides only visual evidence of visible data but doesn't capture hidden or deleted data. Running a virus scan on the original drive would potentially modify file access times and could destroy evidence, violating a fundamental principle of digital forensics: do not alter the original evidence.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a bit-by-bit image in digital forensics?
Open an interactive chat with Bash
What are write blockers and why are they important?
Open an interactive chat with Bash
What is the chain of custody in a forensic investigation?
Open an interactive chat with Bash
ISC2 CISSP
Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
IT & Cybersecurity Package Join Premium for Full Access