Question

Difficulty: MediumIncident Response and Chain of Custody

An IT technician is preparing to transfer a physical storage drive containing compromised system evidence to a central forensics laboratory. To maintain an unbroken chain of custody during this evidence transfer, which of the following entries must be documented on the custody tracking log? (Select TWO.)

  1. The date and timestamp of the evidence handoffAnswer
  2. The names and signatures of both the releasing and receiving individualsAnswer
  3. C
    The classification of the social engineering threat vector used in the initial breach
  4. D
    The operational specifications of physical access barriers installed at the facility entrance

Answer

The correct documentation entries are the date and timestamp of the evidence handoff, along with the names and signatures of both the releasing and receiving individuals.
Chain of custody protocol requires an unbroken chronological record of everyone who collected, transferred, secured, or analyzed evidence. Recording the exact date and timestamp alongside the printed names and signatures of both the releasing handler and receiving handler establishes legal accountability and continuity of control.

Step-by-Step Solution

1
Identify the primary purpose of chain of custody documentation.
Chain of custody forms track evidence possession, transfer chronologies, and tamper integrity.
Legal defensibility requires proving who held the evidence at any given point in time.
2
Evaluate required custody log fields during an evidence transfer.
Every transfer requires recording the date/time of handoff and signatures from both parties involved.
Timestamps and dual signatures establish an unambiguous, accountable record of transfer.

Key Concept

Chain of Custody Documentation
Rate this question