To help prevent loss of information, software vendors, including Microsoft, now provide whole disk encryption. This feature creates new challenges in examining and recovering data from drivers. What are four features offered by whole disk encryption tools that forensics examiners should be aware of?

Respuesta :

Answer and Explanation:

Information is the most significant part of an IT organization and whatever merchants they are utilizing as their customer and server operating system, they should know about the encryption given by their OS to encode the information and avoid information loss. Here are the four highlights that are being given by entire plate encryption devices which crime scene investigation specialists must know about.

  • Advanced Encryption algorithm: the AES or advanced encryption standards and the Data encryption algorithm provide your machines data encryption to a next level. The decryption key remains with the user so that they can decrypt the message to get the data.
  • Full encryption: Windows provide Bit Locker through which disk level encryption can be done on the machine and the decryption key is being stored on a different machine, without that decryption key no one can able to access the data present in the disk.
  • Pre-boot Authentication: - Tools such as BitL ocker, Symantec provides boot level authentication. Through that authentication a user can able to logon to the system, so the forensic experts must be aware of how to get into the system to collect all the forensic evidences.
  • Key management system also being used to change the password on a regular basis and also ensures that user must use complex password.