An incident response team is performing live forensic evidence acquisition on a cloud-hosted virtual machine suspected of being compromised during a data exfiltration attempt. Which of the following actions must the team perform to preserve evidence integrity and maintain a legally defensible chain of custody? (Select TWO.)
- Calculate and record SHA-256 cryptographic hash values for all captured memory images and system log files immediately following acquisition.Cevap
- BReboot the virtual machine to clear volatile swap space before capturing the primary storage volume image.
- Document every evidence transfer, custodian handoff, timestamp, and secure storage location on a standardized evidence log.Cevap
- DEncrypt the live source storage volume using a public key certificate prior to imaging to enforce non-repudiation.
Cevap
The incident response team must record cryptographic SHA-256 hash values immediately after acquiring evidence and maintain a detailed evidence tracking log documenting every custodian handoff, date, and storage location.
Generating cryptographic hash values immediately upon evidence capture provides a verifiable baseline to prove data integrity. Concurrently, maintaining an explicit chain of custody log detailing every handler, transfer date, and storage location ensures an unbroken line of accountability required for evidence admissibility.
Adım Adım Çözüm
Anahtar Kavram
Digital Forensics Integrity Verification and Chain of Custody