Bird
0
0

How can you combine disk imaging with timeline analysis to investigate a security incident?

hard🚀 Application Q9 of 15
Cybersecurity - Digital Forensics
How can you combine disk imaging with timeline analysis to investigate a security incident?
ADelete temporary files before imaging to reduce size
BCreate a disk image, then extract timestamps to build an event timeline
CRun antivirus on the live system before imaging
DOnly image the system partition to save time
Step-by-Step Solution
Solution:
  1. Step 1: Understand disk imaging and timeline analysis

    Disk imaging captures all data; timeline analysis uses timestamps from files to reconstruct events.
  2. Step 2: Combine steps for investigation

    Creating a disk image preserves data, then extracting timestamps helps build a timeline of actions during the incident.
  3. Final Answer:

    Create a disk image, then extract timestamps to build an event timeline -> Option B
  4. Quick Check:

    Image + timestamps = timeline analysis [OK]
Quick Trick: Image first, then analyze timestamps for timeline [OK]
Common Mistakes:
MISTAKES
  • Running antivirus before imaging can alter evidence
  • Deleting files loses potential evidence
  • Imaging only one partition may miss data

Want More Practice?

15+ quiz questions · All difficulty levels · Free

Free Signup - Practice All Questions
More Cybersecurity Quizzes