An incident handler is preparing a forensic image of a hard drive. Which of the following MUST be done to provide evidence that the image is an exact copy of the original?
Verifying file counts manually? That doesn't sound very efficient or reliable. Digital hashing is definitely the way to go to validate the forensic copy.
Using the same hardware seems like it could be important, but I'm not sure if that's an absolute requirement. The hashing is definitely the key piece to provide evidence of the forensic image.
Okay, I'm pretty confident that D is the right answer. Hashing the original and the image will give you a checksum to compare and prove they're identical.
I'm a bit confused - is encrypting and backing up the drive before copying really necessary? Seems like extra steps that aren't directly related to verifying the image.
Noel
9 hours agoClaudio
6 days agoCandra
11 days agoDonette
16 days agoArtie
21 days agoBarb
26 days agoKenny
1 month agoLacey
1 month agoCiara
1 month agoRaina
2 months agoTruman
2 months agoUlysses
2 months agoCarrol
2 months agoAshlyn
2 months agoLon
2 months agoCorinne
3 months agoMakeda
3 months agoGregg
3 months agoMitsue
3 months ago