Question

Difficulty: MediumIncident Response and Chain of Custody

Following an internal investigation regarding unauthorized data exfiltration, an IT technician is tasked with transferring a seized storage drive to an external digital forensics expert. To maintain a legally defensible chain of custody during this transfer, which of the following details MUST be recorded on the evidence log?

  1. The date, time, and signatures of both the relinquishing and receiving partiesAnswer
  2. B
    The master BitLocker recovery key and file system decryption credentials
  3. C
    The structural rating and lock specifications of the facility where the evidence is kept
  4. D
    The threat vector classification and social engineering methodology identified in the attack

Answer

The date, time, and signatures of both the relinquishing and receiving parties
Maintaining an unbroken chain of custody requires logging the precise date and time of evidence transfer, along with the printed names and signatures of both the party relinquishing custody and the party accepting it. This ensures full accountability and evidence integrity for judicial proceedings.

Step-by-Step Solution

1
Identify the primary objective of chain of custody documentation
Recognize that chain of custody establishes an unbroken, documented record of evidence possession.
Legal defensibility requires proving who held the evidence at all times from collection to court presentation.
2
Determine the mandatory fields required during an evidence transfer
Identify that transfer date, transfer time, and signatures of both parties must be recorded.
Without mutual signatures and exact timestamps, accountability and evidence integrity cannot be verified.

Key Concept

Chain of Custody Evidence Transfer Protocols
Rate this question