Question

Difficulty: HardIncident Response and Chain of Custody

A system administrator discovers that an off-site corporate laptop belonging to an executive was compromised during a business trip. Upon the executive's return to the office, the administrator immediately isolates the laptop from the network, removes the internal NVMe solid-state drive, and prepares it for handoff to a third-party digital forensics contractor. Which of the following actions is essential to establish a legally defensible chain of custody during this physical evidence transfer?

  1. Documenting the exact date, time, hardware serial number, and obtaining signatures from both the releasing administrator and receiving contractor on the evidence log.Answer
  2. B
    Mounting the NVMe drive onto an administrative workstation to verify file system integrity and log file modification dates before handing it over.
  3. C
    Storing the NVMe drive in a locked server rack located inside an unmonitored storage room until the forensic contractor arrives.
  4. D
    Categorizing the NVMe drive as a ransomware attack vector on the transfer log based on the executive's initial verbal report.

Answer

Documenting the exact date, time, hardware serial number, and obtaining signatures from both the releasing administrator and receiving contractor on the evidence log.
The correct response highlights the core objective of chain of custody: maintaining an unbroken, verifiable log of physical possession. Recording the precise date, time, item serial number, and acquiring signatures from both the individual relinquishing evidence and the recipient ensures complete accountability.

Step-by-Step Solution

1
Identify the primary requirement for chain of custody during evidence transfer.
Chain of custody requires continuous, verifiable tracking of physical evidence possession from collection through legal proceedings.
Any untracked gap or unverified handler invalidates the evidence in legal contexts.
2
Evaluate the necessary fields on an evidence transfer form.
Essential entries include the item description/serial number, date and time of transfer, reason for transfer, and signatures of both the releasing party and receiving party.
Dual signatures and accurate timestamps prove who maintained physical control of the item at every point in time.
3
Differentiate improper evidence handling practices.
Mounting drives alters timestamps, unmonitored storage creates custody gaps, and logging speculative threat classifications misrepresents factual physical control.
First responders must focus on evidence preservation and strict record-keeping without altering the media or guessing forensic outcomes.

Key Concept

Chain of Custody and Evidence Transfer Protocols
Estimated Time:1m 30s
Rate this question