nerdexam
GIAC

GCFA · Question #21

You company suspects an employee of sending unauthorized emails to competitors. These emails are alleged to contain confidential company data. Which of the following is the most important step for you

The correct answer is A. Preserve the email server including all logs.. In digital forensics, preserving the original email server and its logs is the most critical first step for maintaining chain of custody, as it protects the integrity and completeness of all primary evidence.

Advanced Incident Response & Digital Forensics Fundamentals

Question

You company suspects an employee of sending unauthorized emails to competitors. These emails are alleged to contain confidential company data. Which of the following is the most important step for you to take in preserving the chain of custody?

Options

  • APreserve the email server including all logs.
  • BMake copies of that employee's email.
  • CSeize the employee's PC.
  • DPlace spyware on the employee's PC to confirm these activities.

How the community answered

(55 responses)
  • A
    82% (45)
  • B
    5% (3)
  • C
    11% (6)
  • D
    2% (1)

Why each option

In digital forensics, preserving the original email server and its logs is the most critical first step for maintaining chain of custody, as it protects the integrity and completeness of all primary evidence.

APreserve the email server including all logs.Correct

The email server holds the authoritative, unaltered copies of all sent and received messages, headers, timestamps, and transport logs that constitute the primary evidence in an unauthorized disclosure case. Preserving the server ensures no data is modified, deleted, or overwritten before a forensic image is taken. This protects admissibility in legal proceedings by demonstrating the evidence was not tampered with.

BMake copies of that employee's email.

Copying only the employee's mailbox is insufficient because it omits server-side logs, metadata, and messages that may have been locally deleted but still reside on the server.

CSeize the employee's PC.

Seizing the employee's PC alone would miss server-side email artifacts and logs that are essential to proving the activity occurred.

DPlace spyware on the employee's PC to confirm these activities.

Installing spyware without proper legal authorization is itself illegal and would contaminate the chain of custody, likely rendering all gathered evidence inadmissible in court.

Concept tested: Digital forensics chain of custody for email evidence

Source: https://www.nist.gov/publications/guide-integrating-forensic-techniques-incident-response

Topics

#chain of custody#email server logs#evidence preservation#forensic integrity

Community Discussion

No community discussion yet for this question.

Full GCFA Practice