During an internal investigation into suspicious data transfers, an IT support specialist is sent to secure a compromised workstation in an empty office suite. The specialist disconnects the workstation's network cable, powers down the system, attaches an evidence label with the serial number, and seals the unit in a container. However, before handing the equipment over to the legal forensics team the next morning, the specialist leaves the sealed container in an unlocked office cubicle overnight without logging storage location updates or transfer signatures. Which of the following best explains why this evidence may be rendered legally inadmissible?
- The specialist failed to maintain an unbroken record of physical custody and secure storage control overnight.Answer
- BPowering down the system automatically invalidates the cryptographic integrity hash of the local storage drive.
- CStandard sealed containers fail to meet physical security standards because they lack active electromagnetic pulse shielding.
- DThe incident was misclassified as an internal investigation rather than a network breach requiring immediate cloud partition isolation.
Answer
The specialist failed to maintain an unbroken record of physical custody and secure storage control overnight.
Chain of custody protocols require a continuous, verifiable, and documented record of evidence possession and secure storage from seizure until court presentation. Leaving the evidence overnight in an unlocked cubicle creates a gap in physical control and documentation, allowing opposing counsel to argue that evidence could have been tampered with or altered.
Step-by-Step Solution
Key Concept
Chain of Custody and Evidence Handling
Estimated Time:2m 0s