nerdexam
CompTIACompTIA

CS0-003 · Question #499

CS0-003 Question #499: Real Exam Question with Answer & Explanation

The correct answer is D: Chain of custody. The chain of custody is a documented history that tracks how evidence is handled, collected, transported, and preserved at every stage of the forensic investigation. If a gap exists in the record of who transferred or accessed the evidence, it could call into question the integri

Submitted by cyberguy42· Mar 6, 2026Incident Response Management

Question

An auditor is reviewing an evidence log associated with a cyber crime. The auditor notices that a gap exists between individuals who were responsible for holding onto and transferring the evidence between individuals responsible for the investigation. Which of the following best describes the evidence handling process that was not property followed?

Options

  • AValidating data integrity
  • BPreservation
  • CLegal hold
  • DChain of custody

Explanation

The chain of custody is a documented history that tracks how evidence is handled, collected, transported, and preserved at every stage of the forensic investigation. If a gap exists in the record of who transferred or accessed the evidence, it could call into question the integrity and admissibility of the evidence.

Topics

#chain of custody#digital forensics#evidence handling#cyber crime

Community Discussion

No community discussion yet for this question.

Full CS0-003 PracticeBrowse All CS0-003 Questions