If a PDA is seized in an investigation while the device is turned on, what would be the proper procedure?

Prepare for the Computer Hacking Forensic Investigator v11 exam. Study with flashcards and multiple choice questions. Each question includes hints and explanations. Get exam-ready efficiently!

Multiple Choice

If a PDA is seized in an investigation while the device is turned on, what would be the proper procedure?

Explanation:
Preserving volatile data is crucial when a PDA is seized while it is still powered. RAM holds live information—open documents, running processes, login sessions, encryption keys, and network connections—that can disappear within moments if power is removed. Leaving the device on ensures these ephemeral data stay intact so a memory capture or live analysis can be performed, and the overall state of the device remains as close as possible to what it was at the moment of seizure. Powering down or removing power would risk destroying this volatile evidence and altering the device’s state, which could compromise the investigation. Keeping the device powered on also aligns with careful documentation and chain-of-custody practices to maintain integrity. Removing the battery or memory cards would further change the device’s state and potentially destroy data.

Preserving volatile data is crucial when a PDA is seized while it is still powered. RAM holds live information—open documents, running processes, login sessions, encryption keys, and network connections—that can disappear within moments if power is removed. Leaving the device on ensures these ephemeral data stay intact so a memory capture or live analysis can be performed, and the overall state of the device remains as close as possible to what it was at the moment of seizure. Powering down or removing power would risk destroying this volatile evidence and altering the device’s state, which could compromise the investigation. Keeping the device powered on also aligns with careful documentation and chain-of-custody practices to maintain integrity. Removing the battery or memory cards would further change the device’s state and potentially destroy data.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy