An incident handler needs to preserve evidence for possible litigation. Which of the following will the incident handler MOST likely do to preserve the evidence?
I chose this answer because cloning the drives creates copies of the drive which preserves the data, encrypting the files will protect the data but cloning them preserves data in case the data is destroyed.
B
And as the first responder, you may be responsible for collecting any evidence and ensuring that no evidence is destroyed during this process. It’s very common when collecting this evidence to get a copy of any storage drives. When taking this evidence, we’re not simply copying the files, we’re copying every single bit of information from that storage drive. You’ll sometimes hear this referred to as a bit-for-bit copy or a byte-for-byte copy.
That means you’re not only collecting all of the files, you’re also collecting anything else that might be on that storage device. We’ll sometimes perform this drive copy by physically removing the drive from the device. We will then connect it to a hardware write blocker that would prevent anything from changing the data that’s on that storage drive. We can then make a copy of that drive by using a hardware copying device or by using software imaging tools that can create the copy for us
Professor ¨GOD¨ Messer
I stand corrected, after research on this question I believe A is the correct answer. That is because he is trying to preserve the files. How else would you preserve it? You can encrypt the file to protect anyone getting into the files. Maybe also provide a hash to to verify any changes of the file. I believe A is the correct option. B wouldn't make since because even if you clone the files you just made copies and those copies can easily be modified (not preserved). I would go with A.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
007madmonk
Highly Voted 1Â year, 6Â months agoPegi
1Â year agoHUSBULLA
Highly Voted 1Â year, 3Â months ago6e49f75
5Â months, 1Â week agoDoveta1ls
5Â months agojbeezy
Most Recent 2Â weeks, 3Â days agoChavozamiri
7Â months, 2Â weeks agomohdAj
8Â months agopaobro
1Â year, 3Â months agoCruzBruzzz
1Â year, 6Â months agoCruzBruzzz
1Â year, 6Â months agoParadox_Walnut
1Â year, 7Â months agoPaula77
9Â months, 4Â weeks agocmarks05
1Â year, 7Â months ago