CISSP · Question #1496
What should be the FIRST action to protect the chain of evidence when a desktop computer is involved?
The correct answer is B. Make a copy of the hard drive. When preserving digital evidence from a desktop computer, the first priority is to create a forensic image of the hard drive to capture a bit-for-bit copy of volatile and stored data before anything else is done.
Question
What should be the FIRST action to protect the chain of evidence when a desktop computer is involved?
Options
- ATake the computer to a forensic lab
- BMake a copy of the hard drive
- CStart documenting
- DTurn off the computer
How the community answered
(37 responses)- A3% (1)
- B73% (27)
- C8% (3)
- D16% (6)
Why each option
When preserving digital evidence from a desktop computer, the first priority is to create a forensic image of the hard drive to capture a bit-for-bit copy of volatile and stored data before anything else is done.
Transporting the computer to a forensic lab before imaging risks physical damage, data alteration, or loss of volatile evidence that should have been captured on-site first.
Making a forensic copy (bit-for-bit image) of the hard drive is the first action because it preserves the exact state of all data, including deleted files, metadata, and unallocated space, at the moment of evidence collection. This ensures the original evidence remains unaltered and all subsequent analysis is performed on the copy, maintaining the integrity of the chain of custody. Any delay risks data loss, especially if the system is powered on and writes occur.
Documentation is critical but comes after securing the evidence itself; starting to document before imaging risks allowing data to change or be lost while time is spent writing notes.
Turning off the computer without first imaging can destroy volatile data in RAM, active processes, and network connections that are part of the evidence and cannot be recovered after power loss.
Concept tested: Digital forensics chain of evidence preservation
Source: https://www.nist.gov/system/files/documents/forensics/SP800-86.pdf
Topics
Community Discussion
No community discussion yet for this question.