When examining a hard disk without a write-blocker, you should not start Windows because Windows will write data to the:

Prepare for the Computer Hacking Forensic Investigator v11 exam. Study with flashcards and multiple choice questions. Each question includes hints and explanations. Get exam-ready efficiently!

Multiple Choice

When examining a hard disk without a write-blocker, you should not start Windows because Windows will write data to the:

Explanation:
Starting Windows on a drive without a write blocker can change the disk’s state because the operating system performs regular write operations as it boots and runs. The place Windows will most evidently write data just by being used is the Recycle Bin, a hidden folder on each volume where deleted files are moved. When you delete something in Windows, the system creates a copy in the Recycle Bin, updates directory entries, and modifies metadata. Those actions count as writes to the disk and can alter the evidence you’re trying to preserve. BIOS is firmware stored on the motherboard, not on the hard drive, so it isn’t a target of disk writes during normal startup. MSDOS.sys is a legacy system file and isn’t the typical write target during standard Windows startup. “Case files” isn’t a standard Windows write location. So, the Recycle Bin is the correct point where Windows would write data, making it the best answer.

Starting Windows on a drive without a write blocker can change the disk’s state because the operating system performs regular write operations as it boots and runs. The place Windows will most evidently write data just by being used is the Recycle Bin, a hidden folder on each volume where deleted files are moved. When you delete something in Windows, the system creates a copy in the Recycle Bin, updates directory entries, and modifies metadata. Those actions count as writes to the disk and can alter the evidence you’re trying to preserve. BIOS is firmware stored on the motherboard, not on the hard drive, so it isn’t a target of disk writes during normal startup. MSDOS.sys is a legacy system file and isn’t the typical write target during standard Windows startup. “Case files” isn’t a standard Windows write location. So, the Recycle Bin is the correct point where Windows would write data, making it the best answer.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy