A security analyst is tasked with acquiring digital evidence from a detached persistent cloud storage volume associated with a compromised virtual machine. To ensure the collected storage volume data remains legally admissible and mathematically verifiable throughout the forensic investigation, which of the following procedures must the analyst perform? (Select TWO.)
- Calculate and record cryptographic hash values of the storage volume immediately before and after generating the forensic copy.Cevap
- Maintain a detailed log recording the timestamp, handler identity, evidence control transfers, and purpose for every custody change.Cevap
- CAttach and boot the disk volume inside a temporary virtual machine to inspect running processes and modified files prior to imaging.
- DSubstitute bit-stream cryptographic image hashing with cloud administrative API audit trail signatures for integrity verification.
Cevap
The correct procedures are calculating cryptographic hash values of the storage volume before and after creating the forensic copy, and maintaining a detailed log recording timestamps, handler identities, transfers, and purpose for every evidence custody change.
Generating cryptographic hash values of evidence before and after duplicate acquisition confirms bit-level data integrity. Simultaneously, maintaining an explicit chain of custody log ensures continuous accountability and legal admissibility by tracking who handled the evidence at all times.
Adım Adım Çözüm
Anahtar Kavram
Digital Forensics Integrity Verification and Chain of Custody