Q: 10
[Introduction to Incident Handling and Response]
Farheen is an incident responder at reputed IT Firm based in Florid
a. Farheen was asked to investigate a recent cybercrime faced by the organization. As part of this
process, she collected static data from a victim system. She used DD tool command to perform
forensic duplication to obtain an NTFS image of the original disk. She created a sector-by-sector
mirror imaging of the disk and saved the output image file as image.dd.
Identify the static data collection process step performed by Farheen while collecting static data.
Options
Discussion
I think C fits here.
Option A
It’s C here. Making a bit-for-bit image with dd is all about system preservation, since you need an unchanged copy for forensics. Not really about comparison or administrative stuff. Pretty sure this lines up with ECIH study material.
Be respectful. No spam.