A digital forensics investigator receives an external solid-state drive (SSD) delivered by a courier as part of an ongoing insider threat investigation. The drive is stored in an anti-static evidence bag with a tamper-evident seal and is accompanied by a chain of custody log detailing its initial acquisition and cryptographic hash. Which of the following steps should the investigator perform first upon receiving the physical evidence?
- Inspect the tamper-evident seal, sign the chain of custody form to document the transfer of possession, and attach the drive to a hardware write-blocker before taking verification hashes.Cevap
- BConnect the drive directly to a secondary forensic workstation and mount the file system to verify that the suspect files are intact.
- CGenerate a new digital signature using the investigator's private key to guarantee non-repudiation of the original evidence collector before opening the bag.
- DPerform a bit-stream disk acquisition immediately and defer updating the chain of custody form until the full forensic analysis is finalized.
Cevap
Inspect the tamper-evident seal, sign the chain of custody form to document the transfer of possession, and attach the drive to a hardware write-blocker before taking verification hashes.
The correct answer emphasizes verifying physical evidence seals, immediately logging the transfer of control on the chain of custody form, and utilizing hardware write-blocking controls prior to mounting or hashing the evidence. This ensures evidence remains untampered and legal chain of custody is strictly preserved.
Adım Adım Çözüm
Anahtar Kavram
Chain of Custody and Forensic Evidence Intake
Tahmini Süre:1m 30s