exam questions

Exam 220-1102 All Questions

View all questions & answers for the 220-1102 exam

Exam 220-1102 topic 1 question 26 discussion

Actual exam question from CompTIA's 220-1102
Question #: 26
Topic #: 1
[All 220-1102 Questions]

An incident handler needs to preserve evidence for possible litigation. Which of the following will the incident handler MOST likely do to preserve the evidence?

  • A. Encrypt the files.
  • B. Clone any impacted hard drives.
  • C. Contact the cyber insurance company.
  • D. Inform law enforcement.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
007madmonk
Highly Voted 1 year, 6 months ago
Selected Answer: B
It's B https://www.professormesser.com/free-a-plus-training/220-1102/220-1102-video/privacy-licensing-and-policies-220-1102/
upvoted 14 times
Pegi
1 year ago
Thanks for the reference. B is absolutely the correct answer
upvoted 3 times
...
...
HUSBULLA
Highly Voted 1 year, 3 months ago
husbulla the goat
upvoted 8 times
6e49f75
5 months, 1 week ago
HUSBULLA! Hope everyone passes their core 1 and 2 exams! Passed my core 1 and currently studying for core 2. Going to take it tomorrow!!
upvoted 4 times
Doveta1ls
5 months ago
6e49f75 how did it go! I have mine in two days! (Also B)
upvoted 2 times
...
...
...
jbeezy
Most Recent 2 weeks, 3 days ago
Selected Answer: B
I chose this answer because cloning the drives creates copies of the drive which preserves the data, encrypting the files will protect the data but cloning them preserves data in case the data is destroyed.
upvoted 1 times
...
Chavozamiri
7 months, 2 weeks ago
Selected Answer: B
bit-for-bit copy or a byte-for-byte copy( CLONE) will preserve the evidence.
upvoted 1 times
...
mohdAj
8 months ago
Selected Answer: B
B. Clone any impacted hard drives
upvoted 1 times
...
paobro
1 year, 3 months ago
B And as the first responder, you may be responsible for collecting any evidence and ensuring that no evidence is destroyed during this process. It’s very common when collecting this evidence to get a copy of any storage drives. When taking this evidence, we’re not simply copying the files, we’re copying every single bit of information from that storage drive. You’ll sometimes hear this referred to as a bit-for-bit copy or a byte-for-byte copy. That means you’re not only collecting all of the files, you’re also collecting anything else that might be on that storage device. We’ll sometimes perform this drive copy by physically removing the drive from the device. We will then connect it to a hardware write blocker that would prevent anything from changing the data that’s on that storage drive. We can then make a copy of that drive by using a hardware copying device or by using software imaging tools that can create the copy for us Professor ¨GOD¨ Messer
upvoted 5 times
...
CruzBruzzz
1 year, 6 months ago
Selected Answer: B
B because you can't tamper with evidence. Cloning is the only option.
upvoted 4 times
CruzBruzzz
1 year, 6 months ago
I stand corrected, after research on this question I believe A is the correct answer. That is because he is trying to preserve the files. How else would you preserve it? You can encrypt the file to protect anyone getting into the files. Maybe also provide a hash to to verify any changes of the file. I believe A is the correct option. B wouldn't make since because even if you clone the files you just made copies and those copies can easily be modified (not preserved). I would go with A.
upvoted 4 times
...
...
Paradox_Walnut
1 year, 7 months ago
Selected Answer: A
Wouldn't the answer be "A"? Since the incident handler would want to "preserve the evidence"?
upvoted 4 times
Paula77
9 months, 4 weeks ago
By encrypting the files you are protecting not preserving the files. The question is asking what is the best way of ''preserving'' which is cloning.
upvoted 1 times
...
cmarks05
1 year, 7 months ago
By encrypting the files you altered the evidence
upvoted 10 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago