Chapter 3 Solutions
Review Questions
1. What’s the main goal of a static acquisition?
2. Name the three formats for digital forensics data acquisitions.
3. What are two advantages and disadvantages of the raw format?
Advantages: faster data transfer speeds, ignores minor data errors, and most forensics analysis
4. List two features common with proprietary format acquisition files.
Can compress or not compress the acquisition data; can segment acquisition output files into
5. Of all the proprietary formats, which one is the unofficial standard?
6. Name two commercial tools that can make a forensic sector-by-sector duplicate of a
drive to a larger drive.
7. What does a logical acquisition collect for an investigation?
8. What does a sparse acquisition collect for an investigation?
9. What should you consider when determining which data acquisition method to use?
10. Why is it a good practice to make two images of a suspect drive in a critical
investigation?
11. When you perform an acquisition at a remote location, what should you consider to
prepare for this task?
12. With newer Linux kernel distributions, what happens if you connect a hot-swappable
device, such a USB thumb drive, containing evidence?