A first responder arrives at a crime scene where a computer is running. According to standard forensic procedure, what should the responder do FIRST?
Trap 1: Connect a write blocker and create a forensic image immediately
Imaging should occur after documentation and securing the scene.
Trap 2: Immediately shut down the computer to prevent data alteration
Shutting down may cause loss of volatile data and is not the first step.
Trap 3: Pull the power cord to ensure the system does not shut down normally
Pulling the plug may cause data corruption; proper shutdown or memory capture should be considered.
- A
Photograph the scene and secure the area
Securing and photographing the scene ensures preservation of the original state.
- B
Connect a write blocker and create a forensic image immediately
Why wrong: Imaging should occur after documentation and securing the scene.
- C
Immediately shut down the computer to prevent data alteration
Why wrong: Shutting down may cause loss of volatile data and is not the first step.
- D
Pull the power cord to ensure the system does not shut down normally
Why wrong: Pulling the plug may cause data corruption; proper shutdown or memory capture should be considered.