Soru

Zorluk: KolayIncident Response and Chain of Custody

An IT technician seizes a compromised workstation computer during a security breach investigation. What is the most critical immediate step the technician must take to maintain the chain of custody for this evidence?

  1. Document the date, time, collection location, and handler details on a chain of custody form.Cevap
  2. B
    Open and browse through the suspect files on the drive to verify evidence before logging the device.
  3. C
    Install physical security bollards around the desk area to secure the perimeter.
  4. D
    Classify the security attack type in the ticketing system before securing the physical computer.

Cevap

Document the date, time, collection location, and handler details on a chain of custody form.
Chain of custody requires strict documentation tracking every transfer of evidence, including who collected it, when it was taken, where it was stored, and who handled it.

Adım Adım Çözüm

1
Identify the primary purpose of chain of custody in forensic procedure.
Chain of custody ensures that evidence is legally defensible by tracking its physical integrity and possession history.
Without clear evidence logging, proof of non-tampering cannot be established.
2
Select the action that preserves evidence tracking.
Recording timestamps, location, and handler signatures immediately establishes the first entry in the evidence log.
Proper documentation must begin the moment evidence is seized.

Anahtar Kavram

Chain of Custody Documentation
Tahmini Süre:45s
Bu soruyu puanla