New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 ISSMP Exam - Topic 1 Question 38 Discussion

Actual exam question for ISC2's ISSMP exam
Question #: 38
Topic #: 1
[All ISSMP Questions]

Which of the following is used to back up forensic evidences or data folders from the network or locally attached hard disk drives?

Show Suggested Answer Hide Answer
Suggested Answer: D

FAR systems are used in the forensic process to back up evidence or data folders from the network or locally attached hard disk drives. It automatically spans the content over a series of discs in a variety of media. Backups are encrypted with the MD5 algorithm for verification and full chain of evidence reporting. The restore feature is used to load discs automatically, to any local or network storage location.

Answer option C is incorrect. Device Seizure is a software, which is used in forensic analysis and recovery of mobile phone and PDA data. It is used for data recovery, full data dumps of certain cell phone models, logical and physical acquisitions of PDAs, data cable access, and advanced reporting. Device Seizure also provides feature of GSM SIM card acquisition and deleted data recovery using SIMCon technology.

Answer option B is incorrect. Vedit is a commercial text editor for Microsoft Windows and MS-DOS. Vedit was one of the pioneers in visual editing. Today, it is a powerful and feature-rich general-purpose text editor. Vedit can edit any file, including binary files and huge multi-gigabyte files. Still it is compact and extremely fast, perhaps because it is written mostly in Assembly language.

Answer option A is incorrect. WinHex is a famous hexadecimal editor tool that is used to examine files that have been collected for analysis and examination. This includes file fragments, recovered deleted files, or other data that have been corrupted or destroyed. WinHex can also examine the contents of a file retrieved from a hard disk whose application software, which open the particular file, is not available. We can also view data captured from a network to identify passwords and other data. WinHex also provides a feature that allows cloning of a hard disk and thus making a duplicate of the data to work with. It can also provide a RAM editor feature that allows access to the physical RAM and

any processes running in virtual memory. WinHex is also set to run in a write-protected mode, which open any file in a read-only mode to prevent any modification in the original data.


Contribute your Thoughts:

0/2000 characters
Rosalyn
4 months ago
I thought WinHex was just for hex editing, not backups!
upvoted 0 times
...
Wayne
4 months ago
Wait, are we sure Vedit is even used for backups?
upvoted 0 times
...
Melissa
4 months ago
FAR system is pretty reliable too, but not as popular.
upvoted 0 times
...
Laine
4 months ago
I think Device Seizure is more commonly used in forensic cases.
upvoted 0 times
...
Lazaro
5 months ago
WinHex is definitely a solid choice for data recovery.
upvoted 0 times
...
Ezekiel
5 months ago
I believe Vedit is more for editing files rather than backing up, so I’m leaning towards Device Seizure for this question.
upvoted 0 times
...
Shannon
5 months ago
I’m a bit confused about FAR system; I feel like I’ve seen it mentioned in similar questions, but I can’t recall its exact purpose.
upvoted 0 times
...
Antonio
5 months ago
I remember practicing with Device Seizure in class; it seemed like a solid choice for backing up data from devices.
upvoted 0 times
...
Karon
5 months ago
I think WinHex is used for data recovery, but I'm not sure if it's specifically for backing up forensic evidence.
upvoted 0 times
...
Elin
5 months ago
Okay, the key here is to identify the correct namespace prefix and element names based on the YANG model. I think I can figure this out if I take my time.
upvoted 0 times
...
Willard
5 months ago
Hmm, this seems straightforward. The question is asking if the underlined text is correct, and it's telling me to use Device Manager to investigate the network adapter driver. I think the answer is "No change is needed" since the underlined text matches the instructions.
upvoted 0 times
...
Odette
5 months ago
Okay, let me re-read the question and options. I want to make sure I fully understand the default behavior before selecting an answer.
upvoted 0 times
...

Save Cancel