Soru

Zorluk: KolayDigital Forensics and Chain of Custody

A security analyst takes possession of a physical hard drive seized during a breach investigation. Which of the following actions must the analyst take to maintain a valid chain of custody and preserve evidence integrity? (Select TWO.)

  1. Document the item serial number, acquisition timestamp, and handler details in the custody log.Cevap
  2. Calculate and record cryptographic checksums of the media immediately following acquisition.Cevap
  3. C
    Attach the drive directly to an online analysis system without a hardware write-blocker to inspect file contents.
  4. D
    Rely exclusively on a digital signature to establish data integrity without computing physical media hash values.

Cevap

The investigator must document device identification metadata and transfer history in the chain of custody log, as well as calculate and log cryptographic hash values upon acquisition.
Maintaining a complete log of evidence transfers with serial numbers and computing cryptographic hash digests upon acquisition together ensure both legal accountability and mathematical proof of evidence immutability.

Adım Adım Çözüm

1
Identify the mandatory administrative requirements for forensic evidence handling.
Chain of custody forms must track who collected the evidence, when it was acquired, item serial numbers, and all subsequent transfers.
Accurate logging ensures evidence remains legally admissible in court.
2
Identify technical controls required to prove bit-stream evidence integrity.
Cryptographic hashes (such as SHA-256) are calculated immediately upon acquisition and compared against subsequent copies.
Matching hash values demonstrate that the evidence was not modified during storage or analysis.

Anahtar Kavram

Chain of Custody and Evidence Integrity Verification
Bu soruyu puanla