COMPLETE QUESTIONS AND100% CORRECT
DETAILED ANSWERS FOR GUARANTEED PASS
[ALREADY GRADED A+]
VERSION!!Which computer forensics tools can connect to
suspect's remote computer and run surreptitiously? -
ANSWER-EnCase Enterprise, ProDiscover Investigator,
and ProDiscover Incident Response
EnCase, FTK, SMART, and ILook treat an image file as
though it were the original disk. - ANSWER-True
When possible, you should make two copies of evidences.
- ANSWER-True
, FTK Imager can acquire data in a drive's host protected
area. - ANSWER-False
What is the primary goal of static acquisition? - ANSWER-
to preserve the digital evidence.
Name the three formats for computer forensics data
acquisitions - ANSWER-Raw Format, Proprietary Formats,
Advance Forensic Format
What are two advantages and disadvantages of the raw
format? - ANSWER-fast data transfers and capability to
ignore minor data read errors on the source drive,
Requires as much storage space as the original disk or
that it might not collect marginal (bad) sectors on the
source drive.