A security analyst is initiating a digital forensics investigation on a compromised live application server. Which of the following actions should the analyst perform to adhere to proper evidence preservation and chain of custody procedures? (Select TWO.)
- Capture the active system RAM before shutting down or rebooting the server.Cevap
- Calculate and record SHA-256 cryptographic hashes for all disk images immediately upon acquisition.Cevap
- CPower off the server immediately before capturing volatile memory to prevent further malware execution.
- DRely solely on digital signature certificates rather than hashing to verify that evidence files have not been altered.
Cevap
The analyst should capture active system RAM before shutting down the server and calculate SHA-256 cryptographic hashes for disk images immediately upon acquisition.
Capturing active RAM prior to system shutdown preserves highly volatile evidence according to the order of volatility. Calculating and recording cryptographic hashes immediately upon image acquisition ensures evidence integrity and supports chain of custody proof in legal proceedings.
Adım Adım Çözüm
Anahtar Kavram
Digital Forensics Order of Volatility and Chain of Custody Integrity