Soru

Zorluk: KolayDigital Forensics and Chain of Custody

A security analyst is initiating a digital forensics investigation on a compromised live application server. Which of the following actions should the analyst perform to adhere to proper evidence preservation and chain of custody procedures? (Select TWO.)

  1. Capture the active system RAM before shutting down or rebooting the server.Cevap
  2. Calculate and record SHA-256 cryptographic hashes for all disk images immediately upon acquisition.Cevap
  3. C
    Power off the server immediately before capturing volatile memory to prevent further malware execution.
  4. D
    Rely solely on digital signature certificates rather than hashing to verify that evidence files have not been altered.

Cevap

The analyst should capture active system RAM before shutting down the server and calculate SHA-256 cryptographic hashes for disk images immediately upon acquisition.
Capturing active RAM prior to system shutdown preserves highly volatile evidence according to the order of volatility. Calculating and recording cryptographic hashes immediately upon image acquisition ensures evidence integrity and supports chain of custody proof in legal proceedings.

Adım Adım Çözüm

1
Identify the most volatile evidence components.
System RAM is identified as highly volatile and must be captured while the server remains powered on.
Shutting down the server clears RAM contents, resulting in permanent loss of volatile evidence.
2
Establish evidence integrity baseline upon collection.
Cryptographic hashes (e.g., SHA-256) are generated immediately after image acquisition.
Hashes provide proof that the forensic image was not modified during handling or analysis.

Anahtar Kavram

Digital Forensics Order of Volatility and Chain of Custody Integrity
Bu soruyu puanla