Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security

A company secretary is asked to preserve a suspect laptop for a possible internal fraud investigation. Which first step best protects the evidential value of the data on the laptop?

The best first step is to make a bit-by-bit forensic image of the drive using a write blocker and analyse only the copy. This preserves the original unaltered, including deleted data, and protects the integrity and admissibility of the evidence.

  1. ARun an antivirus scan to remove any malware before examination
  2. BCreate a forensic bit-by-bit image of the drive using a write blocker and work on the copyCorrect
  3. CBrowse the files to identify relevant documents and copy them to a pen drive
  4. DReinstall the operating system to restore normal working

Explanation

A forensic image taken through a write blocker captures all data, including deleted and slack-space content, without altering the original. Scanning, browsing or reinstalling changes timestamps or overwrites data, which damages integrity and admissibility.

Did you get it right without looking?

One question tells you little. A timed set on Cyber Security shows your real accuracy, how long you take and where you lose marks.

More Cyber Security questions