0
5.9kviews
Explain the pros and cons of performing a live response evidence collection versus a forensic disk image.

Subject: Digital Forensics

Topic: Initial response and forensic duplication

Difficulty: Medium

1 Answer
0
383views

A live response is typically used for two purposes, to gather volatile evidence before a system is shut down for imaging, and as a ‘first look’ at a system to determine whether it requires additional attention.

In large enterprise investigations, you may find that most of your investigation is accomplished …

Create a free account to keep reading this post.

and 3 others joined a min ago.

Please log in to add an answer.