Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil Exam 212-89 Topic 4 Question 72 Discussion

Actual exam question for Eccouncil's 212-89 exam
Question #: 72
Topic #: 4
[All 212-89 Questions]

Patrick is doing a cyber forensic investigation. He is in the process of collecting physical

evidence at the crime scene.

Which of the following elements he must consider while collecting physical evidence?

Show Suggested Answer Hide Answer
Suggested Answer: D

In the context of collecting physical evidence during a cyber forensic investigation, Patrick must consider items like removable media, cables, and publications. These items can contain crucial information related to the crime, such as data storage devices (USB drives, external hard drives), cables connected to potentially relevant devices, and any printed materials that might have information or clues about the incident. Open ports, services, and OS vulnerabilities, DNS information, and published name servers and web application source code, while important in digital forensics, do not constitute physical evidence in the traditional sense. Reference: Incident Handler (ECIH v3) study guides and courses detail the process of evidence collection in cyber forensic investigations, emphasizing the importance of securing physical evidence that could support digital forensic analysis.


Contribute your Thoughts:

Delmy
23 hours ago
I believe option A) Open ports, services, and operating system (OS) vulnerabilities is also important to consider.
upvoted 0 times
...
Olen
5 days ago
Hmm, I don't know. D seems a bit too simple. Maybe I should consider the other options as well.
upvoted 0 times
...
Deonna
8 days ago
I'm going with D too. Those publications might have some juicy details about the crime scene.
upvoted 0 times
...
Dominga
18 days ago
D seems like the obvious choice here. Gotta collect that physical evidence like removable media and cables, right?
upvoted 0 times
Nobuko
23 hours ago
User 2: Yeah, collecting removable media and cables is crucial for physical evidence.
upvoted 0 times
...
Regenia
7 days ago
User 1: D seems like the obvious choice here.
upvoted 0 times
...
...
Esteban
22 days ago
I agree with Chau. Those items could contain valuable evidence for the investigation.
upvoted 0 times
...
Chau
24 days ago
I think Patrick should consider option D) Removable media, cable, and publications.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77