CV0-003 · Question #844
A cloud administrator has received a physical disk that was analyzed by the incident response team. Which of the following documents should the cloud administrator update?
The correct answer is A. Chain of custody. When physical evidence such as a disk changes hands, the chain of custody document must be updated to maintain a verifiable record of who possessed the evidence and when.
Question
A cloud administrator has received a physical disk that was analyzed by the incident response team. Which of the following documents should the cloud administrator update?
Options
- AChain of custody
- BIncident taxonomy
- CRisk register
- DIncident playbook
How the community answered
(15 responses)- A93% (14)
- D7% (1)
Why each option
When physical evidence such as a disk changes hands, the chain of custody document must be updated to maintain a verifiable record of who possessed the evidence and when.
Chain of custody is the formal record that tracks every transfer, possession, and handling of physical evidence throughout its lifecycle, including receipt from an incident response team. Updating it when the disk is returned ensures an unbroken, legally defensible audit trail. Failing to document this transfer would compromise the integrity of the evidence and any findings derived from it.
Incident taxonomy is used to classify and categorize incident types, not to track the physical handling or transfer of evidence.
A risk register documents identified organizational risks and their mitigation status, not the custody or movement of forensic evidence.
An incident playbook contains predefined response procedures and workflows, not a log of who physically possessed evidence at each point in time.
Concept tested: Chain of custody documentation for forensic evidence
Source: https://csrc.nist.gov/publications/detail/sp/800-86/final
Topics
Community Discussion
No community discussion yet for this question.