A system administrator discovers that an off-site corporate laptop belonging to an executive was compromised during a business trip. Upon the executive's return to the office, the administrator immediately isolates the laptop from the network, removes the internal NVMe solid-state drive, and prepares it for handoff to a third-party digital forensics contractor. Which of the following actions is essential to establish a legally defensible chain of custody during this physical evidence transfer?
- Documenting the exact date, time, hardware serial number, and obtaining signatures from both the releasing administrator and receiving contractor on the evidence log.Answer
- BMounting the NVMe drive onto an administrative workstation to verify file system integrity and log file modification dates before handing it over.
- CStoring the NVMe drive in a locked server rack located inside an unmonitored storage room until the forensic contractor arrives.
- DCategorizing the NVMe drive as a ransomware attack vector on the transfer log based on the executive's initial verbal report.
Answer
Documenting the exact date, time, hardware serial number, and obtaining signatures from both the releasing administrator and receiving contractor on the evidence log.
The correct response highlights the core objective of chain of custody: maintaining an unbroken, verifiable log of physical possession. Recording the precise date, time, item serial number, and acquiring signatures from both the individual relinquishing evidence and the recipient ensures complete accountability.
Step-by-Step Solution
Key Concept
Chain of Custody and Evidence Transfer Protocols
Estimated Time:1m 30s