nerdexam
CompTIA

CAS-002 · Question #331

A high-tech company dealing with sensitive data seized the mobile device of an employee suspected of leaking company secrets to a competitive organization. Which of the following is the BEST order…

The correct answer is B. Evidence intake, device identification, preparation to identify the necessary tools, device. The correct mobile forensic extraction order begins with evidence intake to establish chain of custody, followed by device identification, tool preparation, and then data acquisition and verification.

Research and Analysis

Question

A high-tech company dealing with sensitive data seized the mobile device of an employee suspected of leaking company secrets to a competitive organization. Which of the following is the BEST order for mobile phone evidence extraction?

Options

  • ADevice isolation, evidence intake, device identification, data processing, verification of data
  • BEvidence intake, device identification, preparation to identify the necessary tools, device
  • CEvidence log, device isolation ,device identification, preparation to identify the necessary
  • DDevice identification, evidence log, preparation to identify the necessary tools, data

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    90% (18)
  • D
    5% (1)

Why each option

The correct mobile forensic extraction order begins with evidence intake to establish chain of custody, followed by device identification, tool preparation, and then data acquisition and verification.

ADevice isolation, evidence intake, device identification, data processing, verification of data

This order proceeds from device isolation directly to data processing without including a tool preparation or identification step, skipping critical pre-acquisition planning that ensures the correct acquisition method is applied.

BEvidence intake, device identification, preparation to identify the necessary tools, deviceCorrect

Per NIST SP 800-101r1 and standard digital forensics practice, evidence intake must occur first after seizure to formally document the device, record its condition, and establish an unbroken chain of custody required for legal admissibility. Device identification follows because knowing the make, model, OS version, and state of the device directly determines which forensic tools and acquisition methods are appropriate, and preparation of those tools must precede any data extraction or processing steps.

CEvidence log, device isolation ,device identification, preparation to identify the necessary

Placing the evidence log before device isolation risks allowing remote wipe commands or network-triggered changes to alter the device state before it is protected, weakening the integrity of the evidence.

DDevice identification, evidence log, preparation to identify the necessary tools, data

Beginning with device identification before completing evidence intake skips the chain of custody documentation that must be the first formal step once a device has been taken into custody, potentially invalidating the evidence in court.

Concept tested: Mobile device forensic evidence extraction process order

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-101r1.pdf

Topics

#mobile forensics#evidence handling#chain of custody#device isolation

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice