Courseiva

CCNA Evidence Acquisition Questions

11 questions · Evidence Acquisition topic · All types, answers revealed

1
MCQeasy

A forensic investigator is preparing to acquire a USB flash drive that is suspected to contain evidence of intellectual property theft. The investigator needs to ensure that the acquisition process does not alter any data on the flash drive. Which of the following should the investigator use?

A.A software write blocker
B.A hardware write blocker
C.The 'dd' command with the 'if' and 'of' parameters
D.A USB hub with power management
AnswerB

A hardware write blocker prevents any write commands from reaching the USB flash drive, ensuring that the data remains unaltered. It is a physical device that intercepts and blocks writes at the hardware level, providing strong protection against accidental modification. This is the standard tool for forensic acquisition to maintain evidential integrity.

Why this answer

A hardware write blocker is the most reliable way to prevent any writes to the USB flash drive during acquisition. It physically intercepts write commands, ensuring the drive remains unaltered. Software write blockers and 'dd' do not offer the same level of guaranteed protection, and a USB hub has no write-blocking capability.

Therefore, a hardware write blocker is the correct choice.

Exam trap

The trap here is assuming that a software write blocker or 'dd' command provides the same level of protection as a hardware write blocker, but only a hardware blocker physically prevents writes.

2
MCQeasy

A forensic examiner needs to acquire a hard drive that is part of a RAID 5 array. The RAID controller is unavailable. What is the best approach to acquire the data?

A.Acquire each disk individually, then reconstruct the array using software
B.Acquire only one disk because RAID 5 can be reconstructed from a single disk
C.Use a hardware write blocker that supports RAID
D.Connect the RAID array to a similar controller and acquire as a single drive
AnswerA

Each physical disk must be imaged independently using a proper write blocker to preserve the raw device contents, including RAID metadata, superblocks, and any data sitting outside the array's logical volume. After all disks are imaged, a forensic RAID reconstruction tool (or mdadm with the correct parameters) can reassemble the logical volume by using the known stripe size, parity rotation, and disk order without needing the original controller. This preserves the exact state of the array and avoids the risk of the controller writing configuration changes during acquisition.

Why this answer

When the RAID controller is unavailable, the only reliable method to acquire the data is to image each physical disk individually using a forensic write blocker, then reconstruct the logical RAID 5 volume in a forensic software tool (e.g., FTK Imager, X-Ways Forensics, or EnCase). This preserves the original evidence on each disk and allows the examiner to rebuild the array by specifying the stripe size, parity rotation, and disk order, which is essential because RAID 5 distributes data and parity across all disks and can tolerate a single disk failure.

Exam trap

EC-Council often tests the misconception that a hardware RAID controller is required for forensic acquisition, or that a single disk from a RAID 5 array contains enough data to reconstruct the volume, when in fact individual disk imaging and software reconstruction is the only forensically sound approach when the controller is unavailable.

How to eliminate wrong answers

Option B is wrong because RAID 5 requires at least three disks and uses distributed parity; a single disk contains only stripes and parity blocks, not the complete data, so reconstruction from one disk is impossible. Option C is wrong because a hardware write blocker that supports RAID would still require the RAID controller to present the logical volume; without the controller, the write blocker cannot access the array as a single drive. Option D is wrong because connecting the disks to a similar controller may cause the controller to attempt an automatic rebuild or initialization, altering the evidence, and the controller's configuration (e.g., stripe size, disk order) may not match the original, leading to data corruption or loss.

3
MCQmedium

During a forensic acquisition, you notice that the target drive has bad sectors. What is the best approach to acquire the drive?

A.Use dd with a higher block size to skip bad sectors
B.Use ddrescue to recover as much data as possible
C.Use FTK Imager and ignore the errors
D.Perform a physical acquisition by removing platters
AnswerB

ddrescue is purpose-built for imaging failing or damaged storage devices. It reads the drive in a single pass, records errors in a logfile, and then retries difficult sectors with increasingly fine-grained reads, recovering the maximum amount of data while preserving a documented map of the damage. Because it can be re-run and continues from the logfile, it is the forensically sound choice when the target drive exhibits read errors.

Why this answer

B is correct because ddrescue is specifically designed to handle media with bad sectors by using a sophisticated read-retry algorithm that logs errors and attempts recovery from multiple angles, including reverse reads and splitting the drive into good and bad regions. Unlike dd, which will abort or produce corrupted output on encountering a bad sector, ddrescue maximizes data recovery while preserving a map of unrecoverable areas.

Exam trap

EC-Council often tests the misconception that dd can handle bad sectors by adjusting block size, but the trap is that dd lacks any error recovery algorithm and will simply fail or produce incomplete data, whereas ddrescue is the proper tool for forensic acquisition of damaged media.

How to eliminate wrong answers

Option A is wrong because increasing the block size in dd does not skip bad sectors; it only changes the read granularity, and a bad sector within a larger block will still cause an I/O error, potentially aborting the entire acquisition. Option C is wrong because FTK Imager, while capable of ignoring read errors, does not actively attempt to recover data from bad sectors; it simply skips them and logs the error, resulting in data loss without the advanced retry and mapping capabilities of ddrescue. Option D is wrong because physically removing platters is an extreme, destructive method reserved for drives with severe mechanical failure or when the drive cannot be powered on; it is not the best approach for a drive with only bad sectors, as it risks total data loss and is unnecessary when software tools like ddrescue can recover most data.

4
MCQhard

You are a forensic investigator responding to a data breach at a financial institution. The compromised server is a Windows Server 2019 running a custom trading application. The server is still powered on and connected to the production network. The incident response team has instructed you to acquire forensic evidence while minimizing downtime. The server has 2 TB of storage with 500 GB used. You have a forensic workstation with a write-blocker and an empty 2 TB external drive. The server's RAM is 64 GB. You need to acquire both volatile data (RAM) and a forensic image of the disk. However, the legal team requires a verified bit-for-bit copy with cryptographic hash verification. Additionally, the server's performance is critical; acquiring RAM via network is not feasible due to bandwidth constraints. Which of the following is the best course of action?

A.Shut down the server, remove the disk, connect it to a write-blocker, and acquire the disk image using FTK Imager; RAM is lost but disk acquisition is verified.
B.Use FTK Imager over the network to acquire RAM first, then use dd to image the disk to the external drive via write-blocker.
C.Run win32dd locally to capture RAM to the external drive, then use FTK Imager over the network to create a physical disk image with verification.
D.Use dd over netcat to acquire RAM and disk simultaneously, then compute hashes separately.
AnswerC

This is the correct order of volatility. Running win32dd locally captures RAM quickly to an external device, minimizing the time that volatile data is at risk, and it preserves a raw memory image for later analysis. After that, FTK Imager can acquire a physical disk image over the network and automatically generate hash values (e.g., MD5/SHA1) to verify the integrity of the image at acquisition time. This combines fast volatile capture with network-acquired disk imaging that includes built-in verification.

Why this answer

It prioritizes capturing volatile RAM first using win32dd (a memory acquisition tool) locally to the external drive, which preserves the most volatile evidence before any shutdown or network transfer. After RAM capture, FTK Imager over the network creates a verified physical disk image, satisfying the legal requirement for cryptographic hash verification while minimizing downtime. This approach avoids the risk of losing RAM data (as in shutdown) and avoids bandwidth constraints (as in network RAM acquisition).

Exam trap

EC-Council often tests the misconception that network-based RAM acquisition is always feasible or that shutting down the server is acceptable, but the trap here is that candidates overlook the bandwidth constraint and the critical need to preserve volatile data before disk imaging.

How to eliminate wrong answers

Option A is wrong because shutting down the server destroys volatile data (RAM), which is critical for investigating the breach, and the legal team requires a verified bit-for-bit copy, but RAM is lost entirely. Option B is wrong because acquiring RAM over the network is explicitly stated as not feasible due to bandwidth constraints, and using dd to image the disk to the external drive via write-blocker is not described correctly (dd is a Linux tool, not native to Windows Server 2019, and FTK Imager over the network for RAM would be slow and unreliable). Option D is wrong because using dd over netcat for RAM acquisition is not a standard Windows memory acquisition method, and simultaneous acquisition of RAM and disk is impractical without proper write-blocking and verification; netcat does not provide cryptographic hash verification natively.

5
MCQhard

You are a forensic investigator responding to a suspected data breach at a financial institution. The incident response team has isolated a Windows 10 workstation used by a former employee. The system is still powered on, and the login screen is displayed. Your task is to acquire forensic evidence in a defensible manner. The following actions are available: A. Immediately pull the power cord to perform a cold acquisition of the hard drive. B. Capture volatile data (RAM, network connections, running processes) using a trusted tool on a USB drive, then shut down normally and remove the hard drive for imaging. C. Boot the system from a forensic live CD and create a forensic image of the hard drive while the system is running. D. Use the built-in Windows backup to create a system image to an external drive. Which action is the most appropriate first step in this scenario?

A.Use the built-in Windows backup to create a system image to an external drive
B.Capture volatile data using a trusted tool on a USB drive, then shut down normally and remove the hard drive for imaging
C.Boot the system from a forensic live CD and create a forensic image of the hard drive while the system is running
D.Immediately pull the power cord to perform a cold acquisition of the hard drive
AnswerB

This is the correct order because volatile data (RAM, running processes, network connections, open files) is lost the instant the system loses power. Using a trusted, write-protected USB tool to capture this data first ensures the most transient evidence is preserved. A graceful shutdown, unlike a hard power-off, allows the OS to flush and close file structures cleanly, reducing the risk of filesystem corruption, and then removing the drive for a forensic imaging workstation yields a defensible disk image without altering the original.

Why this answer

The system is still powered on with the login screen displayed, meaning volatile data (RAM, network connections, running processes) is present and will be lost if the system is powered off. Capturing this data first using a trusted forensic tool (e.g., FTK Imager or DumpIt) from a write-blocked USB drive preserves critical evidence such as encryption keys, active network connections, and malware in memory. Only after volatile data is secured should the system be shut down normally and the hard drive removed for forensic imaging, ensuring a defensible chain of custody.

Exam trap

EC-Council often tests the misconception that pulling the power cord is the safest method to preserve disk evidence, but the trap here is that it destroys volatile data and can cause filesystem corruption, making it inappropriate when the system is still powered on and volatile data is present.

How to eliminate wrong answers

Option A is wrong because using the built-in Windows backup to create a system image modifies the system (e.g., writes backup metadata, changes registry timestamps) and does not capture volatile data, violating forensic integrity principles. Option C is wrong because booting from a forensic live CD while the system is running can overwrite portions of RAM and disk (e.g., pagefile, unallocated space) and may trigger anti-forensic mechanisms, plus it does not capture the current volatile state before the system is altered. Option D is wrong because immediately pulling the power cord (cold acquisition) destroys all volatile data (RAM, network connections, running processes) that may contain critical evidence like encryption keys or active malware, and can cause filesystem corruption if the disk was in a write state.

6
MCQhard

You are imaging a suspect's hard drive using a write blocker and dd command. After imaging, you verify the hash of the original drive and the image file. The original drive hash is SHA1: A1B2C3D4E5..., and the image hash is SHA1: F6G7H8I9J0... What is the most likely cause of the mismatch?

A.The dd command used a different block size
B.The write blocker malfunctioned and allowed writes to the original drive
C.The dd command compressed the output
D.The image file was corrupted during transfer
AnswerB

A write blocker is a dedicated hardware or software mechanism that intercepts and blocks all write commands from the host system to the suspect drive during acquisition. If it malfunctions, the operating system or the acquisition tool may write temporary files, filesystem metadata, or other data onto the original evidence drive. Any such unintended write changes the drive's contents, so when the examiner later computes a hash of the original drive, it will no longer match the hash of the forensic image taken earlier. This is the only option that directly explains how the source itself could be altered, making it the correct cause of the hash discrepancy.

Why this answer

The hash mismatch indicates that the data on the original drive and the image file are not identical. A write blocker malfunction that allowed writes to the original drive during the imaging process would alter the source data after the initial hash was computed, causing the final hash of the original drive to differ from the hash of the image file taken at a different point in time. This is the most direct cause of a hash mismatch because the write blocker's primary purpose is to prevent any modification to the evidence.

Exam trap

EC-Council often tests the misconception that dd's block size or compression affects the hash, but the trap here is that candidates overlook the write blocker's role in preserving evidence integrity and instead focus on technical details of the dd command that do not alter the data content.

How to eliminate wrong answers

Option A is wrong because the dd command's block size affects read/write performance and the number of blocks, but it does not change the underlying data; the hash of the output will match the input regardless of block size as long as the entire drive is read. Option C is wrong because dd does not compress output by default; it performs a bit-for-bit copy, and even if compression were applied (e.g., via piping to gzip), the hash would be computed on the compressed file, not the raw image, but the question states the image file hash is compared, so compression would not cause a mismatch between the original drive hash and the image hash if the image is decompressed correctly. Option D is wrong because corruption during transfer would affect the image file's integrity, but the hash of the original drive would remain unchanged; the mismatch described is between the original drive hash and the image hash, and transfer corruption would only alter the image hash, not the original drive hash.

7
MCQmedium

The command used to acquire a disk image resulted in an I/O error. What is the most likely cause?

A.The source disk has bad sectors
B.The output file already exists and is being overwritten
C.The target directory does not have write permissions
D.The target drive is full
AnswerA

The source disk has bad sectors. When the imaging tool issues a raw read to a region containing a physically damaged or unreliable sector, the disk controller cannot return valid data and raises a hardware-level error. The operating system exposes this as an I/O error (EIO) on the read operation, causing the acquisition command to terminate or skip the sector. This is the classic cause of I/O errors during forensic imaging and requires error-handling flags such as 'conv=noerror,sync' in dd to continue.

Why this answer

When a disk imaging tool (e.g., dd, FTK Imager, EnCase) encounters an I/O error during acquisition, the most common cause is physical damage or degradation of the source media, specifically bad sectors. Bad sectors prevent the read head from reliably retrieving data, triggering an I/O error at the operating system or device driver level. This is distinct from logical errors like file system corruption, which typically produce different error messages.

Exam trap

The trap here is that candidates confuse an I/O error (a hardware-level read failure) with logical or permission-based errors, mistakenly attributing the error to the output destination rather than the source media.

How to eliminate wrong answers

Option B is wrong because overwriting an existing output file does not cause an I/O error; it may produce a warning or prompt for confirmation, but the read operation from the source disk proceeds normally. Option C is wrong because a lack of write permissions on the target directory results in a permission denied error, not an I/O error, and the acquisition tool would fail before attempting to read the source. Option D is wrong because a full target drive causes a 'disk full' or 'no space left on device' error, which is a write failure, not a read-related I/O error from the source disk.

8
MCQeasy

Which of the following is the primary purpose of using a hardware write blocker during disk acquisition?

A.To decrypt the drive during acquisition
B.To prevent any writes to the original evidence drive
C.To compress the acquired image
D.To increase the speed of the acquisition
AnswerB

The primary purpose of a write blocker is to guarantee the integrity of the original evidence by creating a read-only interface between the drive and the forensic workstation. It intercepts and blocks all write commands issued by the operating system, including those that might occur from normal mounting, file system metadata updates, or malware, ensuring the source drive remains bit-for-bit unchanged. This preservation is essential for maintaining a legally defensible chain of custody and allowing a subsequent hash verification to prove evidence authenticity.

Why this answer

A hardware write blocker is a device placed between the suspect drive and the forensic workstation that intercepts and blocks any write commands from the host operating system, ensuring that the original evidence drive remains unaltered. This is critical for maintaining the integrity of digital evidence, as any modification to the source drive could render it inadmissible in court. The primary purpose is therefore to prevent any writes to the original evidence drive, preserving its exact state for forensic analysis.

Exam trap

EC-Council often tests the misconception that a write blocker performs active functions like decryption or compression, when in reality it is a passive hardware filter that only enforces read-only access at the bus level.

How to eliminate wrong answers

Option A is wrong because a hardware write blocker does not perform decryption; decryption requires separate tools or keys and is not a function of write-blocking hardware. Option C is wrong because compression of the acquired image is handled by imaging software (e.g., FTK Imager, dd with gzip) after the write blocker has ensured read-only access, not by the write blocker itself. Option D is wrong because a write blocker does not increase acquisition speed; in fact, it may introduce a slight latency due to the hardware bridge, and speed is determined by the interface (e.g., SATA, USB) and the imaging tool, not the blocker.

9
MCQmedium

An investigator must acquire a 2 TB USB 3.0 external hard drive as evidence in a fraud case. The drive contains a single NTFS volume with 500 GB of allocated data. The investigator needs to create a forensic image that captures all allocated and unallocated space, and the acquisition must be completed as quickly as possible while maintaining evidential integrity. Which acquisition method should the investigator use?

A.Perform a sparse acquisition that only copies allocated clusters
B.Create a logical image of the NTFS volume using EnCase Logical Evidence File (LEF)
C.Use the dd command with a software write blocker to create a raw image
D.Create a physical image using a hardware write blocker and FTK Imager in E01 format
AnswerD

A physical image captures every sector, including allocated and unallocated space, preserving all potential evidence. Using a hardware write blocker prevents any writes to the source drive, maintaining integrity. FTK Imager with E01 compression reduces file size and is a standard forensic format, making this the correct choice for speed and completeness.

Why this answer

A physical image captures every sector, including unallocated space, which is essential for recovering deleted evidence in a fraud case. A hardware write blocker ensures the source drive is not altered, preserving evidential integrity. E01 compression reduces storage and transfer time compared to raw formats, addressing the speed requirement.

Logical or sparse acquisitions would omit critical areas, making them unsuitable.

Exam trap

The trap here is assuming that a logical image or sparse acquisition is sufficient because it captures the visible files, but it misses unallocated space where deleted evidence often resides.

10
MCQhard

Based on the acquisition log, what can be concluded about the integrity of the acquired image?

A.The image is not forensically sound because the verification passed
B.The source and image have different data
C.The image is corrupted because only one hash algorithm was used
D.The image is an exact copy of the source
AnswerD

The acquisition log documents that the hash of the source and the hash of the acquired image are identical, and the subsequent verification step confirms these values still match. Identical hash digests plus a verified match provide strong cryptographic proof that the image is a precise, bit-for-bit duplicate of the source, which is the definition of a forensically sound copy.

Why this answer

The acquisition log shows that the hash values computed for the source drive and the acquired image match exactly. A matching hash (e.g., MD5 or SHA-1) verifies that the image is a bit-for-bit identical copy of the original evidence, confirming forensic soundness. Therefore, the image is an exact copy of the source, making option D correct.

Exam trap

EC-Council often tests the misconception that a passed verification indicates the image is not forensically sound, or that using only one hash algorithm implies corruption, when in fact a matching hash confirms integrity regardless of the number of algorithms used.

How to eliminate wrong answers

Option A is wrong because a verification that passes (hash match) confirms forensic soundness, not the opposite; a failed verification would indicate the image is not forensically sound. Option B is wrong because matching hash values prove the source and image have identical data, not different data. Option C is wrong because using a single hash algorithm (e.g., MD5 or SHA-1) is standard practice and does not indicate corruption; corruption would cause a hash mismatch, not be caused by the number of algorithms used.

11
Multi-Selecthard

A forensic examiner is acquiring a running Linux server that is part of a live incident response. The server hosts a critical database and cannot be taken offline. The examiner needs to capture volatile data in a forensically sound manner. Which TWO of the following actions should the examiner perform? (Choose two.)

Select 2 answers
A.Delete temporary files to free up space for acquisition
B.Use the 'dd' command to create a full disk image of the server's primary drive
C.Capture network connections using the 'netstat' command
D.Run 'fsck' on the primary drive to check for file system inconsistencies
E.Collect the output of the 'ps' command to capture running processes
AnswersC, E

The 'netstat' command displays active network connections, listening ports, and associated processes. This volatile data is crucial for identifying command-and-control channels or data exfiltration. It can be collected quickly without impacting the server's operation, making it a correct action for live volatile data acquisition.

Why this answer

Capturing running processes with 'ps' and network connections with 'netstat' are standard volatile data collection steps that do not disrupt the server. They provide critical information about active threats and can be performed quickly. Full disk imaging and file system checks are either disruptive or irrelevant to volatile data, and deleting files destroys evidence.

Exam trap

The trap here is confusing volatile data acquisition with full disk imaging, or thinking that system maintenance commands like fsck are part of live response.

Ready to test yourself?

Try a timed practice session using only Evidence Acquisition questions.