A digital forensics investigator receives an external solid-state drive (SSD) delivered by a courier as part of an ongoing insider threat investigation. The drive is stored in an anti-static evidence bag with a tamper-evident seal and is accompanied by a chain of custody log detailing its initial acquisition and cryptographic hash. Which of the following steps should the investigator perform first upon receiving the physical evidence?
- Inspect the tamper-evident seal, sign the chain of custody form to document the transfer of possession, and attach the drive to a hardware write-blocker before taking verification hashes.Answer
- BConnect the drive directly to a secondary forensic workstation and mount the file system to verify that the suspect files are intact.
- CGenerate a new digital signature using the investigator's private key to guarantee non-repudiation of the original evidence collector before opening the bag.
- DPerform a bit-stream disk acquisition immediately and defer updating the chain of custody form until the full forensic analysis is finalized.
Answer
Inspect the tamper-evident seal, sign the chain of custody form to document the transfer of possession, and attach the drive to a hardware write-blocker before taking verification hashes.
The correct answer emphasizes verifying physical evidence seals, immediately logging the transfer of control on the chain of custody form, and utilizing hardware write-blocking controls prior to mounting or hashing the evidence. This ensures evidence remains untampered and legal chain of custody is strictly preserved.
Step-by-Step Solution
Key Concept
Chain of Custody and Forensic Evidence Intake
Estimated Time:1m 30s