Professional Documents
Culture Documents
SCI 4201 Practicals: Bethel Chaka N0161068D May 13, 2020
SCI 4201 Practicals: Bethel Chaka N0161068D May 13, 2020
SCI 4201 Practicals: Bethel Chaka N0161068D May 13, 2020
1
1. You’re investigating a case involving a 2 GB drive that you need
to copy at the scene. Write one to two pages describing three op-
tions you have to copy the drive accurately. Be sure to include your
software and media choices.
• Solution
Acquiring the data primarily requires making a copy of the hard drive
bit by bit. Acquisition of data requires collecting data to solve the case
from the location of the crime. Evidences are stored as image file in one
of three formats in the computer forensics tool. Two are open source and
the third is proprietary. Proprietary format is different, as each vendor has
different unique features. The data collection is carried out in four ways:
Disk Imaging
The stand-alone drive imaging software ”Forensic Imager” is included in
the Recover My Files Installation tab. Forensic Imager is a program based
on Windows that acquires a sectoral copy (”image”) of a drive in one of
the following common forensic file formats:
2
3. E01 (EnCase) [Version 6.xx format]