a disk that contains ReFS

Computer Networking: A Top-Down Approach (7th Edition)
7th Edition
ISBN:9780133594140
Author:James Kurose, Keith Ross
Publisher:James Kurose, Keith Ross
Chapter1: Computer Networks And The Internet
Section: Chapter Questions
Problem R1RQ: What is the difference between a host and an end system? List several different types of end...
icon
Related questions
Question
Question 17
You are provided with a disk that contains ReFS and need to analyze the contents.
How do you BEST go about this?
O Write protect the drive, capture an AD1 of the files and separately carve a physical disk
image.
O It is not possible to forensically examine an ReFS disk.
O Browse the physical disk with FTK Imager and export files of interest.
Create a physical disk image with FTK Imager and then process in FTK.
Transcribed Image Text:Question 17 You are provided with a disk that contains ReFS and need to analyze the contents. How do you BEST go about this? O Write protect the drive, capture an AD1 of the files and separately carve a physical disk image. O It is not possible to forensically examine an ReFS disk. O Browse the physical disk with FTK Imager and export files of interest. Create a physical disk image with FTK Imager and then process in FTK.
Question 12
You must acquire a virtual machine as evidence from the host computer. The virtual
machine is running on your local machine, but the virtual disk file and other files are
on a computer at another address not covered by your warrant. What should you
do?
O Save the state by snapshot, or other method, then copy the appliance or disk over to
your media.
O Save the state by snapshot, or other method, then start a boot media image in the VM
and make a forensic image to media you have passed to the guest.
O It is difficult to know the legal status of this acquisition. You call a prosecuting attorney
and your agency's attorney for advice.
Pass a USB disk through to the live VM and use FTK Imager from that disk to make an
e01.
Transcribed Image Text:Question 12 You must acquire a virtual machine as evidence from the host computer. The virtual machine is running on your local machine, but the virtual disk file and other files are on a computer at another address not covered by your warrant. What should you do? O Save the state by snapshot, or other method, then copy the appliance or disk over to your media. O Save the state by snapshot, or other method, then start a boot media image in the VM and make a forensic image to media you have passed to the guest. O It is difficult to know the legal status of this acquisition. You call a prosecuting attorney and your agency's attorney for advice. Pass a USB disk through to the live VM and use FTK Imager from that disk to make an e01.
Expert Solution
steps

Step by step

Solved in 2 steps

Blurred answer
Recommended textbooks for you
Computer Networking: A Top-Down Approach (7th Edi…
Computer Networking: A Top-Down Approach (7th Edi…
Computer Engineering
ISBN:
9780133594140
Author:
James Kurose, Keith Ross
Publisher:
PEARSON
Computer Organization and Design MIPS Edition, Fi…
Computer Organization and Design MIPS Edition, Fi…
Computer Engineering
ISBN:
9780124077263
Author:
David A. Patterson, John L. Hennessy
Publisher:
Elsevier Science
Network+ Guide to Networks (MindTap Course List)
Network+ Guide to Networks (MindTap Course List)
Computer Engineering
ISBN:
9781337569330
Author:
Jill West, Tamara Dean, Jean Andrews
Publisher:
Cengage Learning
Concepts of Database Management
Concepts of Database Management
Computer Engineering
ISBN:
9781337093422
Author:
Joy L. Starks, Philip J. Pratt, Mary Z. Last
Publisher:
Cengage Learning
Prelude to Programming
Prelude to Programming
Computer Engineering
ISBN:
9780133750423
Author:
VENIT, Stewart
Publisher:
Pearson Education
Sc Business Data Communications and Networking, T…
Sc Business Data Communications and Networking, T…
Computer Engineering
ISBN:
9781119368830
Author:
FITZGERALD
Publisher:
WILEY