nerdexam
CompTIA

CV0-003 · Question #844

A cloud administrator has received a physical disk that was analyzed by the incident response team. Which of the following documents should the cloud administrator update?

The correct answer is A. Chain of custody. When physical evidence such as a disk changes hands, the chain of custody document must be updated to maintain a verifiable record of who possessed the evidence and when.

Security

Question

A cloud administrator has received a physical disk that was analyzed by the incident response team. Which of the following documents should the cloud administrator update?

Options

  • AChain of custody
  • BIncident taxonomy
  • CRisk register
  • DIncident playbook

How the community answered

(15 responses)
  • A
    93% (14)
  • D
    7% (1)

Why each option

When physical evidence such as a disk changes hands, the chain of custody document must be updated to maintain a verifiable record of who possessed the evidence and when.

AChain of custodyCorrect

Chain of custody is the formal record that tracks every transfer, possession, and handling of physical evidence throughout its lifecycle, including receipt from an incident response team. Updating it when the disk is returned ensures an unbroken, legally defensible audit trail. Failing to document this transfer would compromise the integrity of the evidence and any findings derived from it.

BIncident taxonomy

Incident taxonomy is used to classify and categorize incident types, not to track the physical handling or transfer of evidence.

CRisk register

A risk register documents identified organizational risks and their mitigation status, not the custody or movement of forensic evidence.

DIncident playbook

An incident playbook contains predefined response procedures and workflows, not a log of who physically possessed evidence at each point in time.

Concept tested: Chain of custody documentation for forensic evidence

Source: https://csrc.nist.gov/publications/detail/sp/800-86/final

Topics

#chain of custody#incident response#digital forensics#evidence handling

Community Discussion

No community discussion yet for this question.

Full CV0-003 Practice