Data Acquisition and Recovery C8 Flashcards
1
Q
Two Types of Data Acquisition
A
- Static Acquisition
- Live Acquisition
2
Q
Bit-stream copy and Bit-stream image
A
Bit-stream copy = mirror image backup
Bit-stream image = Sector-by-sector copy of a physical or logical drive
3
Q
Three Formats
A
- Raw Format
- Proprietary format
- Advanced forensics
4
Q
Raw Format pros and cons
A
Pros:
- fast data transfers
- can ignore minor data errors
Cons:
- require as much storage as original disk
- tools might not collect marginal sectors
5
Q
Proprietary Formats pros and cons
A
Pros:
- option to compress or not image files
- can split an image into smaller segments
Cons:
- Inability to share an image between different tools
- file size limitation
6
Q
Advanced Forensics Format
A
- simple design with extensibility
- open source for multiple platforms
7
Q
4 methods of data acquisitions
A
- bit-stream disk-to-image file
- bit-stream disk-to-disk
- logical
- sparse