CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security
A company secretary is asked to preserve a suspect laptop for a possible internal fraud investigation. Which first step best protects the evidential value of the data on the laptop?
The best first step is to make a bit-by-bit forensic image of the drive using a write blocker and analyse only the copy. This preserves the original unaltered, including deleted data, and protects the integrity and admissibility of the evidence.
- ARun an antivirus scan to remove any malware before examination
- BCreate a forensic bit-by-bit image of the drive using a write blocker and work on the copyCorrect
- CBrowse the files to identify relevant documents and copy them to a pen drive
- DReinstall the operating system to restore normal working
Explanation
A forensic image taken through a write blocker captures all data, including deleted and slack-space content, without altering the original. Scanning, browsing or reinstalling changes timestamps or overwrites data, which damages integrity and admissibility.
Did you get it right without looking?
One question tells you little. A timed set on Cyber Security shows your real accuracy, how long you take and where you lose marks.
More Cyber Security questions
- Which of the following best describes 'two-factor authentication' as a cyber security control?
- In the standard incident response lifecycle followed in cyber security practice, which phase comes immediately after 'Detection and Analysis…
- Rohit, an employee of a Pune firm, uses a colleague's login credentials without permission and downloads confidential client files from the …
- Meera receives an email that appears to come from her bank and asks her to enter her net-banking password on a look-alike website. She does …
- A Mumbai-based fintech company discovers that an attacker has gained unauthorised access to its customer database through a compromised serv…
- As part of cyber security governance, a listed company's board wants a single accountable executive to design the information security progr…