Question: discuss why you need to use a write blocker (either hardware or software) in your examinations, whether for a criminal case or a corporate case.
discuss why you need to use a write blocker (either hardware or software) in your examinations, whether for a criminal case or a corporate case.
Also, imagine you are a computer forensic examiner receiving a suspect hard disk drive from a detective in your department. The drive was seized properly during a legally executed search warrant. The detective signs the chain of custody log and hands you the drive. Your job is to accept the drive, conduct an analysis, and maintain the drive until trial. Please explain the steps you would take, from receipt until testimony, including the reasons why you would take each step. For example, what would you check for when you sign for the drive on the chain of custody?
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
