0
3.5kviews
Explain the pros and cons of performing a live response evidence collection versus a forensic disk image. Why is a live response the most common method of evidence preservation during an IR?

Subject: Digital Forensics

Topic: Initial response and forensic duplication

Difficulty: High

1 Answer
0
254views

A live response is typically used for two purposes, to gather volatile evidence before a system is shut down for imaging, and as a ‘first look’ at a system to determine whether it requires additional attention.

In large enterprise investigations, you may find that most of your investigation is accomplished …

Create a free account to keep reading this post.

and 3 others joined a min ago.

Please log in to add an answer.