Soru

Zorluk: OrtaDigital Forensics and Chain of Custody

A cybersecurity analyst is preparing to transport a seized, powered-off desktop computer from a remote branch office to the central digital forensics laboratory. Which of the following procedures must be performed to maintain the chain of custody and preserve physical evidence integrity during transit? (Select TWO.)

  1. Record the equipment serial numbers, transfer timestamps, and signatures of both the transferring and receiving custodians on a formal tracking form.Cevap
  2. Place the hard drive in a tamper-evident anti-static bag and seal it prior to secure physical transport.Cevap
  3. C
    Power on the system at the remote office to calculate and log the baseline cryptographic hash of the primary storage partition before packing.
  4. D
    Apply full-disk encryption to the primary drive prior to shipping to protect sensitive data confidentiality during transit.

Cevap

Maintaining chain of custody and physical evidence integrity during transportation requires documenting all transfer details with custodian signatures on a formal tracking log and securing evidence inside sealed, tamper-evident anti-static packaging.
Chain of custody requires continuous tracking of evidence possession via detailed logs containing timestamps, serial numbers, and signatures. Physical evidence must also be packaged in sealed, tamper-evident, anti-static containers to guard against physical damage and tampering.

Adım Adım Çözüm

1
Identify chain of custody tracking requirements
Every physical transfer of digital evidence must record the date, time, unique identifiers (such as serial numbers), purpose of transfer, and signatures of both releasing and receiving custodians.
This establishes accountability and legally proves who had possession of the evidence at all times.
2
Identify physical evidence preservation standards
Physical components such as hard drives must be stored in tamper-evident anti-static bags to prevent electrostatic discharge damage and provide clear indicators of unauthorized access.
Ensuring physical protection prevents evidence contamination or damage during transit.
3
Evaluate prohibited modifications to original media
Actions that modify the drive contents (such as applying encryption) or boot the operating system directly (altering system logs/timestamps) corrupt original evidence.
Forensic evidence acquisition requires static bit-stream imaging using write-blocking technology in controlled lab settings, not live unblocked execution at a remote site.

Anahtar Kavram

Preserving chain of custody documentation and physical evidence integrity during transport
Bu soruyu puanla