nerdexam
CompTIA

CAS-005 · Question #309

A local government that is investigating a data exfiltration claim was asked to review the fingerprint of the malicious user's actions. An investigator took a forensic image of the VM and downloaded…

The correct answer is C. Chain of custody. An investigator took a forensic image of a VM to investigate data exfiltration and is preparing to release the evidence on a secured USB drive to the government.

Submitted by jian89· Mar 6, 2026Security Operations

Question

A local government that is investigating a data exfiltration claim was asked to review the fingerprint of the malicious user's actions. An investigator took a forensic image of the VM and downloaded the image to a secured USB drive to share with the government. Which of the following should be taken into consideration during the process of releasing the drive to the government?

Options

  • AEncryption in transit
  • BLegal issues
  • CChain of custody
  • DOrder of volatility
  • EKey exchange

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    70% (21)
  • D
    17% (5)
  • E
    7% (2)

Why each option

An investigator took a forensic image of a VM to investigate data exfiltration and is preparing to release the evidence on a secured USB drive to the government.

AEncryption in transit

Encryption in transit primarily refers to data transmitted over a network, whereas the question describes a physical transfer via a USB drive.

BLegal issues

Legal issues are a broad consideration, but chain of custody is the specific procedural aspect directly ensuring the integrity and admissibility of evidence for legal purposes.

CChain of custodyCorrect

Chain of custody is paramount when transferring forensic evidence, as it documents every person who has had possession of the evidence, the dates and times of transfer, and the purpose, ensuring the integrity and admissibility of the evidence in legal proceedings.

DOrder of volatility

Order of volatility relates to the sequence of data collection during the *acquisition* phase of forensics, not the *release* of evidence.

EKey exchange

Key exchange is a cryptographic process for sharing encryption keys, which might be relevant for an encrypted drive, but it's secondary to the overarching chain of custody for evidence transfer.

Concept tested: Digital forensics chain of custody

Source: https://learn.microsoft.com/en-us/windows/win32/secauthn/chain-of-custody

Community Discussion

No community discussion yet for this question.

Full CAS-005 Practice