Soru

Zorluk: KolayIncident Response and Chain of Custody

An IT technician secures a suspicious USB flash drive discovered plugged into a financial department computer during a security breach. After placing the flash drive in an anti-static evidence bag, which log entry detail is required on the chain of custody documentation to maintain evidence integrity?

  1. The date, timestamp, and full name with signature of the individual releasing and receiving the evidenceCevap
  2. B
    A full directory tree listing of all files and folders contained on the USB flash drive
  3. C
    The physical keycard access log entries for all personnel who entered the building during the shift
  4. D
    The threat category and malicious payload classification determined by antivirus software

Cevap

The chain of custody log must record the date, timestamp, and signatures of both the person handing over and the person receiving the evidence.
Chain of custody forms preserve legal admissibility by recording a continuous, unbroken history of who held the evidence, when it changed hands, and where it was stored. Accurate timestamps alongside signatures of both the releasing and receiving parties ensure accountability.

Adım Adım Çözüm

1
Identify the purpose of chain of custody documentation in digital forensics.
Chain of custody establishes a verifiable record showing who possessed the evidence at all times.
This prevents claims of evidence tampering or unauthorized access when presented in court or internal legal proceedings.
2
Determine the required fields on a chain of custody log.
Essential fields include item description, serial number, date/time of transfer, location, and the printed names and signatures of both the releasing and receiving handlers.
Every transfer of physical possession must be logged without gaps.

Anahtar Kavram

Chain of Custody Documentation Requirements
Bu soruyu puanla