An incident response team member needs to perform a forensics examination but does not have the required
hardware. Which of the following will allow the team member to perform the examination with minimal impact to
the potential evidence?
Using a software file recovery disc
Mounting the drive in read-only mode
Imaging based on order of volatility
Hashing the image after capture
Mounting the drive in read-only mode will prevent any executable commands from being executed. This is turn
will have the least impact on potential evidence using the drive in question.