PC のフォレンジック調査が必要ですが、PC の電源がオフになっています。最初に行うべきことはどれですか?
正解:B
Performing a bit-by-bit backup of the hard disk using a write-blocking device is the first step to do when a forensic examination of a PC is required, but the PC has been switched off because it helps to create a forensically sound copy of the original evidence without altering or damaging it. A bit-by-bit backup, also known as a physical or raw image, is a complete copy of every bit on the hard disk, including the unallocated or deleted data. A write-blocking device is a hardware or software tool that prevents any write operations to the hard disk, such as updating timestamps or changing file attributes. Performing a bit-by-bit backup of the hard disk using a write-blocking device ensures the integrity and authenticity of the evidence and allows the forensic analysis to be conducted on the duplicate image rather than the original source. Therefore, performing a bit-by-bit backup of the hard disk using a write-blocking device is the correct answer. References: * https://en.wikipedia.org/wiki/Computer_forensics * https://resources.infosecinstitute.com/topic/computer-forensics-forensic-analysis-examination-planning/ * https://www.computer-forensics-recruiter.com/topics/examination_steps/