nerdexam
CompTIA

CAS-003 · Question #412

During a criminal investigation, the prosecutor submitted the original hard drive from the suspect's computer as evidence. The defense objected during the trial proceedings, and the evidence was…

The correct answer is A. Follow chain of custody best practices B. Create an identical image of the original hard drive, store the original securely, and then perform. Digital forensics evidence admissibility requires maintaining an unbroken chain of custody and performing all analysis on a verified forensic image rather than the original media to prevent tampering claims.

Enterprise Security Operations

Question

During a criminal investigation, the prosecutor submitted the original hard drive from the suspect's computer as evidence. The defense objected during the trial proceedings, and the evidence was rejected. Which of the following practices should the prosecutor's forensics team have used to ensure the suspect's data would be admissible as evidence? (Select TWO.)

Options

  • AFollow chain of custody best practices
  • BCreate an identical image of the original hard drive, store the original securely, and then perform
  • CUse forensics software on the original hard drive and present generated reports as evidence
  • DCreate a tape backup of the original hard drive and present the backup as evidence
  • ECreate an exact image of the original hard drive for forensics purposes, and then place the

How the community answered

(45 responses)
  • A
    89% (40)
  • C
    7% (3)
  • D
    2% (1)
  • E
    2% (1)

Why each option

Digital forensics evidence admissibility requires maintaining an unbroken chain of custody and performing all analysis on a verified forensic image rather than the original media to prevent tampering claims.

AFollow chain of custody best practicesCorrect

Chain of custody documentation records every person who handled the evidence, timestamps, and transfer reasons, establishing an unbroken record that proves the evidence was not substituted or tampered with between seizure and trial - courts routinely reject evidence lacking this documentation.

BCreate an identical image of the original hard drive, store the original securely, and then performCorrect

Creating a bit-for-bit forensic image with cryptographic hash verification and sealing the original drive as evidence preserves the integrity of the source media; performing all analysis on the verified copy ensures the original remains unaltered, removing any basis for a defense challenge that the investigation modified the evidence.

CUse forensics software on the original hard drive and present generated reports as evidence

Running forensics software directly on the original hard drive risks altering file system metadata, access timestamps, or slack space, which can invalidate the evidence and provides grounds for a defense to argue the data was modified.

DCreate a tape backup of the original hard drive and present the backup as evidence

A tape backup does not create a sector-by-sector identical image, may skip system areas and unallocated space, and lacks cryptographic hash verification needed to prove the copy is forensically identical to the original.

ECreate an exact image of the original hard drive for forensics purposes, and then place the

Creating a forensic image alone is necessary but insufficient without also maintaining chain of custody documentation - both practices together are required for evidence to be admissible in court.

Concept tested: Digital forensics evidence preservation and chain of custody

Source: https://csrc.nist.gov/publications/detail/sp/800-86/final

Topics

#digital forensics#chain of custody#evidence handling#hard drive imaging

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice