Question

Computer imaging is the process of duplicating the data of an entire hard drive. Imaging has...

Computer imaging is the process of duplicating the data of an entire hard drive. Imaging has many uses. For example, many network and systems administrators use imaging to deploy a consistent operating system installation across a series of computer with the same hardware. This saves the administrator time and effort by not having to load each computer by hand.

However, in the realm of computer forensics, disk imaging is used to make an exact copy of a drive so to not “tamper” or “damage” the original evidence.

In computer forensics what are the steps to creating an image of a disk?

What security checks should be performed to ensure an exact copy is made?

What are some reasons disk imaging is useful in computer forensics?

0 0
Add a comment Improve this question Transcribed image text
Answer #1

Solution:

The steps to creating an image of a disk

  • The data inside the disk should no tamper while taking the image of the disks.
  • In computer forensics never work on the original evidence else it will tamper the data and leads to rejection of those evidences in the court.
  • First preserve the evidence as such don’t even turn off/on the system.
  • Use a special computer that is designed only for disk imaging, that computer should not have any other software rather than dedicated for the imaging.
  • Connect the system to the target computer through the communication ports of the system.
  • Through that communication port the complete copy of the disk will be copied to the other disk.
  • The exact copy of disk will be made by preserving pattern of sectors and holes, etc.
  • Once produce the forensically sound copy preserve the original disk in its current state.

Security checks should be performed to ensure an exact copy is made:

  • Test the size and pattern of free spaces in the copy to ensure the correctness of the copy.
  • Check for the logs of the files inside the copy it should preserve the original time.
  • The file modified time should not be the copied time but the same as on the original disk.

Reasons disk imaging is useful in computer forensics

  • To submit the original evidence without any modification disk imaging is very useful.
  • It allows to do any test on the copy since do not worry much about the loss of data or tamper of data in the copy.
Add a comment
Know the answer?
Add Answer to:
Computer imaging is the process of duplicating the data of an entire hard drive. Imaging has...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around...

    Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around risk and threat management, fostering an environment in which objectives seem clear: manage risk, manage threat, stop attacks, identify attackers. These objectives aren't wrong, but they are fundamentally misleading.In this session we'll examine the state of the information security industry in order to understand how the current climate fails to address the true needs of the business. We'll use those lessons as a foundation...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT