Which practice is recommended regarding antivirus scanning on a forensic workstation?

Prepare for the Computer Hacking Forensic Investigator v11 exam. Study with flashcards and multiple choice questions. Each question includes hints and explanations. Get exam-ready efficiently!

Multiple Choice

Which practice is recommended regarding antivirus scanning on a forensic workstation?

Explanation:
Ensuring a trusted, known-good environment is essential for forensic work. Running antivirus on the forensics workstation before you begin helps confirm the system is not compromised and cannot introduce malware or alter evidence during analysis. Scanning the suspect drive first can risk modifying data with quarantine actions or other changes; scanning during an investigation every few minutes is excessive and impractical; and avoiding scans on the workstation entirely would leave you blind to threats. By starting with a clean baseline, you protect the integrity of your tools and the evidence you handle throughout the case.

Ensuring a trusted, known-good environment is essential for forensic work. Running antivirus on the forensics workstation before you begin helps confirm the system is not compromised and cannot introduce malware or alter evidence during analysis. Scanning the suspect drive first can risk modifying data with quarantine actions or other changes; scanning during an investigation every few minutes is excessive and impractical; and avoiding scans on the workstation entirely would leave you blind to threats. By starting with a clean baseline, you protect the integrity of your tools and the evidence you handle throughout the case.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy