An incident handler is preparing a forensic image of a hard drive. Which of the following MUST be done to provide evidence that the image is an exact copy of the original?
Verifying file counts manually? That doesn't sound very efficient or reliable. Digital hashing is definitely the way to go to validate the forensic copy.
Using the same hardware seems like it could be important, but I'm not sure if that's an absolute requirement. The hashing is definitely the key piece to provide evidence of the forensic image.
Okay, I'm pretty confident that D is the right answer. Hashing the original and the image will give you a checksum to compare and prove they're identical.
I'm a bit confused - is encrypting and backing up the drive before copying really necessary? Seems like extra steps that aren't directly related to verifying the image.
Lavera
1 month agoMichell
2 months agoBerry
2 months agoDanica
2 months agoMarti
2 months agoMelita
2 months agoTambra
2 months agoNoel
3 months agoClaudio
3 months agoCandra
3 months agoDonette
4 months agoArtie
4 months agoBarb
4 months agoKenny
4 months agoLacey
4 months agoCiara
4 months agoRaina
5 months agoTruman
5 months agoUlysses
5 months agoCarrol
5 months agoAshlyn
5 months agoLon
5 months agoCorinne
6 months agoMakeda
6 months agoGregg
6 months agoAnnita
20 days agoKasandra
26 days agoCiara
1 month agoMindy
1 month agoMitsue
6 months ago