An incident responder needs to create a forensic image of a suspect hard drive. Which of the following steps is ESSENTIAL to ensure the integrity of the evidence?
A hardware write blocker intercepts write commands at the interface level, allowing reads while preventing any modification to the suspect drive. This preserves the original evidence's integrity, ensuring the forensic image is an admissible, verifiable copy.
Why this answer
Using a write blocker is essential because it ensures that no data can be written to the suspect hard drive during the imaging process, preserving the original evidence in a forensically sound state. Without a write blocker, any operating system or imaging tool could inadvertently modify metadata (e.g., access timestamps) or the file system, which would compromise the integrity and admissibility of the evidence in legal proceedings.
Exam trap
A common trap in SSCP is the misconception that booting the system or running software-based checks is acceptable. However, any interaction with the original drive that could alter its state—even a read-only mount without a write blocker—can change metadata and break the chain of custody.
How to eliminate wrong answers
Option A is wrong because running an antivirus scan on the drive before imaging could modify the drive's contents (e.g., by quarantining or deleting files), which violates forensic integrity principles. Option C is wrong because booting the suspect system can alter the system state, including writing to the drive (e.g., log files, temporary files), and may trigger anti-forensic mechanisms. Option D is wrong because performing imaging over the network introduces risks of data corruption, packet loss, or interception, and does not inherently prevent writes to the original drive; a write blocker is still required for forensic soundness.