Soru

Zorluk: KolayDigital Forensics and Chain of Custody

An incident response team is preparing to collect evidence from a physical storage drive recovered during an investigation. To ensure that the drive's contents cannot be altered or modified by the operating system while creating a forensic bit-stream image, which of the following tools should the technician use to connect the drive to the workstation?

  1. A hardware write-blockerCevap
  2. B
    A cryptographic checksum generator
  3. C
    A hardware security module
  4. D
    A Faraday bag

Cevap

A hardware write-blocker should be used to intercept write commands and prevent modification of the target drive during evidence acquisition.
A hardware write-blocker is physically placed between the evidence drive and the forensic computer. It permits read requests (necessary to copy or image the drive) while dropping write requests, ensuring that the original evidence remains unchanged.

Adım Adım Çözüm

1
Identify the primary risk during physical drive analysis.
Connecting a suspect drive directly to a forensic workstation can cause the operating system to write metadata or system files to the drive.
Any modification to the original drive invalidates the evidence.
2
Select the appropriate forensic hardware control.
Deploying a hardware write-blocker between the drive and the workstation allows read operations for imaging while blocking all write operations.
Write-blockers guarantee read-only access to preserve forensic integrity.

Anahtar Kavram

Write-blocker usage during forensic acquisition
Bu soruyu puanla