CompTIA CySA+ CS0-003 Practice Question
During an incident response, a security analyst needs to ensure that a copy of a potentially compromised server's hard drive is acquired for analysis. Which of the following is the BEST method to ensure that the evidence is admissible in court?
Copying files from the server to an external hard drive directly
Implementing remote mirroring to another server and capturing the replication data
Creating a bit-for-bit image of the original drive using a write blocker
Taking photographs of the server and its connections for documentation