Soru

Zorluk: OrtaDigital Forensics and Chain of Custody

A security analyst is tasked with acquiring digital evidence from a detached persistent cloud storage volume associated with a compromised virtual machine. To ensure the collected storage volume data remains legally admissible and mathematically verifiable throughout the forensic investigation, which of the following procedures must the analyst perform? (Select TWO.)

  1. Calculate and record cryptographic hash values of the storage volume immediately before and after generating the forensic copy.Cevap
  2. Maintain a detailed log recording the timestamp, handler identity, evidence control transfers, and purpose for every custody change.Cevap
  3. C
    Attach and boot the disk volume inside a temporary virtual machine to inspect running processes and modified files prior to imaging.
  4. D
    Substitute bit-stream cryptographic image hashing with cloud administrative API audit trail signatures for integrity verification.

Cevap

The correct procedures are calculating cryptographic hash values of the storage volume before and after creating the forensic copy, and maintaining a detailed log recording timestamps, handler identities, transfers, and purpose for every evidence custody change.
Generating cryptographic hash values of evidence before and after duplicate acquisition confirms bit-level data integrity. Simultaneously, maintaining an explicit chain of custody log ensures continuous accountability and legal admissibility by tracking who handled the evidence at all times.

Adım Adım Çözüm

1
Identify key requirements for digital evidence preservation and chain of custody.
Digital forensics requires proving bit-stream data integrity and maintaining an unbroken audit trail of physical/logical evidence possession.
Evidence must be verifiable and legally admissible in formal investigations.
2
Evaluate data integrity verification methods.
Generating matching cryptographic hashes (such as SHA-256) before and after copying confirms no modifications occurred during disk acquisition.
Any alteration in source or destination media results in a completely different hash output.
3
Evaluate chain of custody documentation standards.
Logging every individual who takes custody of evidence, along with exact dates, times, and transfer justifications, prevents claims of evidence tampering.
Chain of custody documentation establishes continuous legal control and accountability.

Anahtar Kavram

Digital Forensics Integrity Verification and Chain of Custody
Bu soruyu puanla