CompTIA Security+ (SY0-701)Security OperationsEasy
A security analyst is conducting a forensic investigation after a suspected intrusion. To ensure the integrity of the collected evidence, the analyst must create a mathematically verifiable copy of a hard drive before performing any analysis. Which of the following tools or techniques is essential for this step?
- AMemory dump utility
- BForensic write blocker
- CPacket sniffer
- DLive acquisition tool
Show answer & explanationAnswer & explanation
Correct answer: B. Forensic write blocker
A forensic write blocker is a hardware or software device that prevents any write operations to the source evidence drive. This ensures that the original data remains unaltered during the imaging process, preserving its integrity for legal and investigative purposes, which is crucial for digital forensics.
Why the other options are wrong
- A. A memory dump utility captures the contents of RAM, not a hard drive image.
- C. A packet sniffer captures network traffic and is unrelated to creating disk images.
- D. A live acquisition tool collects data from a running system, which is different from creating an unaltered image of a hard drive.
Forensic Write Blocker
A device or software that physically or logically prevents data from being written to a storage device, ensuring the integrity of original evidence during forensic imaging.
- Protects original evidence from alteration.
- Essential for maintaining chain of custody.
- Can be hardware or software-based.
Memory trick: To keep the EVIDENCE pure, you must BLOCK any changes to the ORIGINAL.