Soru

Zorluk: OrtaDigital Forensics and Chain of Custody

A digital forensics investigator receives an external solid-state drive (SSD) delivered by a courier as part of an ongoing insider threat investigation. The drive is stored in an anti-static evidence bag with a tamper-evident seal and is accompanied by a chain of custody log detailing its initial acquisition and cryptographic hash. Which of the following steps should the investigator perform first upon receiving the physical evidence?

  1. Inspect the tamper-evident seal, sign the chain of custody form to document the transfer of possession, and attach the drive to a hardware write-blocker before taking verification hashes.Cevap
  2. B
    Connect the drive directly to a secondary forensic workstation and mount the file system to verify that the suspect files are intact.
  3. C
    Generate a new digital signature using the investigator's private key to guarantee non-repudiation of the original evidence collector before opening the bag.
  4. D
    Perform a bit-stream disk acquisition immediately and defer updating the chain of custody form until the full forensic analysis is finalized.

Cevap

Inspect the tamper-evident seal, sign the chain of custody form to document the transfer of possession, and attach the drive to a hardware write-blocker before taking verification hashes.
The correct answer emphasizes verifying physical evidence seals, immediately logging the transfer of control on the chain of custody form, and utilizing hardware write-blocking controls prior to mounting or hashing the evidence. This ensures evidence remains untampered and legal chain of custody is strictly preserved.

Adım Adım Çözüm

1
Verify physical evidence package integrity
Ensure the tamper-evident seal is undamaged and matches the seal ID listed on the accompanying documentation.
Physical integrity verification proves evidence was not modified or tampered with in transit.
2
Log custody transfer
Sign and date the chain of custody log indicating formal receipt of the storage drive from the courier.
Maintaining an unbroken chain of custody is mandatory for evidence admissibility.
3
Prepare for evidence acquisition
Connect the drive to a hardware write-blocking device prior to plugging it into the forensic workstation.
Write-blockers prevent the host operating system from writing data or updating access timestamps on the original evidence drive.

Anahtar Kavram

Chain of Custody and Forensic Evidence Intake
Tahmini Süre:1m 30s
Bu soruyu puanla