EC-Council: Computer Hacking Forensic Investigator(CHFI-V10)
Module 2 : Computer Forensics Investigation Process
         
Questions available : 60 You are not logged in.
Please Login for track your learning progress
   
 
Q. No: 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 |
Go to Question No.



Question No 0


If you want to share the link of this question, please click here to "Copy Question Link" and share that generated link. Link from URL may change in future.
 

   
Bookmark this Question
QID: 585  
   
Melanie was newly assigned to an investigation and asked to make a copy of all the evidence from the compromised system. Melanie did a DOS copy of all the files on the system. What would be the primary reason for you to recommend a disk imaging tool?


 
A:    A disk imaging tool would check for CRC32s for internal self-checking and validation and have MD5 checksum
 
B:    Evidence file format will contain case data entered by the examiner and encrypted at the beginning of the evidence file
C:    A simple DOS copy will not include deleted files, file slack and other information
 
D:    There is no case for an imaging tool as it will use a closed, proprietary format that if compared to the original will not match up sector for sector
 
         

 
 

Diffence opinion in Correct Answer or any comment?
Vote / Comment for correct Answer




















WELCOME TO ONLINE EXAM PREPARATION SYSTEM

Certification Examinations