An incident handler is preparing a forensic image of a hard drive. Which of the following MUST be done to provide evidence that the image is an exact copy of the original?
Verifying file counts manually? That doesn't sound very efficient or reliable. Digital hashing is definitely the way to go to validate the forensic copy.
Using the same hardware seems like it could be important, but I'm not sure if that's an absolute requirement. The hashing is definitely the key piece to provide evidence of the forensic image.
Okay, I'm pretty confident that D is the right answer. Hashing the original and the image will give you a checksum to compare and prove they're identical.
I'm a bit confused - is encrypting and backing up the drive before copying really necessary? Seems like extra steps that aren't directly related to verifying the image.
Michell
1 day agoBerry
6 days agoDanica
11 days agoMarti
17 days agoMelita
22 days agoTambra
27 days agoNoel
2 months agoClaudio
2 months agoCandra
2 months agoDonette
2 months agoArtie
2 months agoBarb
2 months agoKenny
3 months agoLacey
3 months agoCiara
3 months agoRaina
3 months agoTruman
3 months agoUlysses
3 months agoCarrol
4 months agoAshlyn
4 months agoLon
4 months agoCorinne
4 months agoMakeda
5 months agoGregg
5 months agoMitsue
4 months ago