Soru

Zorluk: ZorDigital Forensics and Chain of Custody

Following a high-severity alert indicating unauthorized root-level execution on a enterprise hypervisor server, a security analyst is assigned to preserve digital evidence from the active physical host. Which of the following initial steps must the analyst perform to preserve evidence integrity and adhere to forensic best practices? (Select TWO.)

  1. Capture the running system's RAM and active network connections prior to acquiring persistent storage imagesCevap
  2. Calculate cryptographic hashes for all acquired evidence immediately after capture and document them in the chain of custody logCevap
  3. C
    Perform a graceful system shutdown to freeze the state of the hypervisor swap file prior to collecting volatile memory dumps
  4. D
    Encrypt the acquired disk image using the analyst's private asymmetric key to establish non-repudiation for evidence intake

Cevap

The analyst should capture the running system's RAM and active network connections before imaging persistent storage, and calculate cryptographic hashes immediately after acquisition while recording them in the chain of custody documentation.
Preserving volatile system memory and active network connections prior to persistent storage imaging correctly adheres to the forensic Order of Volatility. Generating cryptographic hashes immediately following acquisition and logging them in the chain of custody establishes verifiable evidence integrity.

Adım Adım Çözüm

1
Identify and capture evidence according to the forensic Order of Volatility.
System RAM and active network sockets are preserved before non-volatile storage is touched.
Volatile data is lost as soon as system power state or process state changes.
2
Compute cryptographic checksums (e.g., SHA-256) for all collected memory dumps and storage images.
An baseline hash value is established for each evidence file.
Comparing hash values later verifies evidence integrity and proves no alterations occurred during transport or analysis.
3
Log all hash values, acquisition timestamps, and handler details into the chain of custody record.
A complete, legally defensible chain of custody record is maintained.
Forensic evidence requires unbroken documentation to remain admissible in legal or compliance proceedings.

Anahtar Kavram

Digital Forensics Order of Volatility and Chain of Custody Integrity Verification
Bu soruyu puanla