An IT technician is tasked with securing a compromised internal storage drive and transporting it to an offsite forensic analysis team following a suspected enterprise data breach. Which of the following procedural steps are mandatory to preserve evidence integrity and maintain a valid chain of custody during this process? (Select TWO.)
- Document the exact date, time, hardware serial number, and signatures of both the relinquisher and recipient for every evidence transfer.Cevap
- BMount the drive on a local workstation to copy log files into an unencrypted shared folder before packaging the drive.
- Seal the drive in a tamper-evident anti-static bag and store it within a locked, access-controlled container prior to transport.Cevap
- DLeave the drive on a desk in a monitored open office area overnight since room-level physical security cameras are active.
Cevap
The technician must document the exact date, time, hardware serial number, and handler signatures upon transfer, and seal the drive in a tamper-evident anti-static bag within a locked storage container.
Maintaining a valid chain of custody requires logging comprehensive transfer details—such as exact timestamps, unique serial numbers, and signatures of all individuals handling the asset—as well as securing the evidence in sealed, tamper-evident anti-static packaging stored within restricted physical security containers.
Adım Adım Çözüm
Anahtar Kavram
Chain of Custody and Evidence Integrity
Tahmini Süre:2m 0s