Soru

Zorluk: OrtaDigital Forensics and Chain of Custody

A digital forensics investigator is preparing to capture a bit-stream copy of a seized hard drive recovered from an employee's computer during an insider threat investigation. To ensure that the physical drive's original data remains unmodified and that the acquired evidence is legally admissible, which of the following procedures must the investigator implement prior to starting the imaging process?

  1. Connect the target hard drive through a hardware write-blocker and calculate an initial cryptographic hash value.Cevap
  2. B
    Boot the computer using its native operating system to verify system log timestamps before mounting the drive.
  3. C
    Encrypt the source drive using asymmetric encryption to guarantee non-repudiation during evidence transport.
  4. D
    Transfer the unsealed physical drive directly to an analyst's workstation and initiate file system recovery scripts.

Cevap

Connect the target hard drive through a hardware write-blocker and calculate an initial cryptographic hash value.
Connecting the evidence drive through a hardware write-blocker guarantees that no write commands reach the physical disk during acquisition. Computing an initial cryptographic hash (such as SHA-256) before and immediately after imaging proves that the image is a bit-for-bit identical duplicate of the original drive without modification.

Adım Adım Çözüm

1
Isolate the evidence disk
Prevents unauthorized access or network interaction.
Ensures the drive is handled in a controlled forensic environment.
2
Attach a hardware write-blocker to the drive controller interface
Blocks write signals from the forensic workstation controller.
Protects the evidence from accidental modifications, timestamp updates, or operating system writes.
3
Generate an initial cryptographic hash (e.g., SHA-256) of the original drive
Creates a baseline hash digest value.
Establishes a verifiable integrity baseline to compare against forensic disk images.

Anahtar Kavram

Digital Forensics Evidence Acquisition Integrity and Write Protection
Bu soruyu puanla