312-49 · Question #430
Which of the following should a computer forensics lab used for investigations have?
The correct answer is B. restricted access. A computer forensics lab must maintain restricted access to ensure the integrity of evidence and the security of the investigative environment.
Question
Which of the following should a computer forensics lab used for investigations have?
Options
- Aisolation
- Brestricted access
- Copen access
- Dan entry log
How the community answered
(49 responses)- A2% (1)
- B96% (47)
- D2% (1)
Why each option
A computer forensics lab must maintain restricted access to ensure the integrity of evidence and the security of the investigative environment.
While 'isolation' of networks or devices is important within an investigation, 'isolation' as a general characteristic of the lab itself is less precise than 'restricted access' for physical security.
Restricted access is crucial for a computer forensics lab to prevent unauthorized personnel from tampering with evidence, equipment, or ongoing investigations. This control ensures the integrity and chain of custody of digital evidence, which is vital for its admissibility in legal proceedings by demonstrating that the evidence has not been compromised.
'Open access' directly contradicts the fundamental security requirements for handling sensitive legal evidence and maintaining its integrity.
While 'an entry log' is a good practice for maintaining an audit trail, it is a *mechanism* to support 'restricted access' rather than the overarching requirement itself.
Concept tested: Computer forensics lab security, chain of custody
Source: https://www.nist.gov/publications/guide-forensic-examinations-digital-evidence-revision-1
Topics
Community Discussion
No community discussion yet for this question.