Question

Difficulty: MediumIncident Response and Chain of Custody

A cybersecurity analyst is preparing to transfer a compromised server hard drive to an external forensic laboratory for legal analysis. The internal incident log currently includes the drive's model and serial number, the date and time of initial seizure, the acquiring technician's signature, and the secure storage room location. Which of the following details MUST be recorded on the chain-of-custody form at the moment of handoff to maintain evidence admissibility?

  1. The recipient's name, signature, and the exact date and time of the physical transferAnswer
  2. B
    A detailed file path listing of all suspicious files opened and examined on the live server
  3. C
    The physical security keycard log entries for the server room where the incident occurred
  4. D
    The specific social engineering vector classification used during the initial intrusion

Answer

The recipient's name, signature, and the exact date and time of the physical transfer
A chain of custody log must document a complete, unbroken record of every individual who takes possession of evidence. When transferring hardware to a third party, recording the recipient's full name, signature, and the exact timestamp of transfer is mandatory to prove the evidence was safeguarded and untampered with.

Step-by-Step Solution

1
Identify the purpose of a chain-of-custody document
Recognize that chain of custody establishes continuous control and tracking of digital evidence from seizure to courtroom presentation.
Any gap in documentation regarding who handled evidence or when it changed hands can invalidate the evidence in court.
2
Analyze missing elements required during evidence transfer
Determined that handing over physical media to another party requires explicit sign-off by both handler and recipient.
Without the recipient's signature, name, and transfer timestamp, custody control is broken.

Key Concept

Chain of Custody Documentation Requirements
Rate this question