Question

Difficulty: MediumIncident Response and Chain of Custody

An IT technician receives a physical USB flash drive identified as the source of a malware infection on a workstation. The technician is tasked with transferring this evidence to the lead incident responder for digital forensic analysis. Which of the following details MUST be recorded on the chain of custody form during this transfer?

  1. The date, time, and signatures of both the releasing technician and the receiving responderAnswer
  2. B
    The full directory file path and file names of all executable files stored on the drive
  3. C
    The serial number of the physical security keycard scanner guarding the IT storage room
  4. D
    The exact malware threat classification and severity level assigned by endpoint security software

Answer

The date, time, and signatures of both the releasing technician and the receiving responder.
Maintaining an unbroken chain of custody requires documenting every single exchange of evidence. Every transfer entry must include the date, exact time, item description/ID, and the names and signatures of both the individual surrendering custody and the individual receiving it.

Step-by-Step Solution

1
Identify the primary purpose of a chain of custody log in incident response.
Recognize that chain of custody documentation exists to establish an unbroken, verifiable record of evidence handling so that evidence remains legally admissible.
Any gap in documentation regarding who possessed the evidence or when it was transferred can invalidate evidence in legal proceedings.
2
Evaluate the required log fields during an evidence handoff.
Confirm that every transfer requires the date, time, unique evidence tag ID, and verified signatures/names of both the handler releasing the evidence and the recipient taking custody.
This establishes clear accountability and chronological tracking for the evidence.

Key Concept

Chain of Custody Documentation Requirements
Estimated Time:1m 15s
Rate this question