nerdexam
GIAC

GSEC · Question #91

The following three steps belong to the chain of custody for federal rules of evidence. What additional step is recommended between steps 2 and 3? STEP 1 - Take notes: who, what, where, when and…

The correct answer is D. Check the backup integrity using a checksum utility like MD5, and sign and seal each piece of. After creating a binary backup of forensic evidence, integrity must be verified with a cryptographic hash (such as MD5) and the evidence physically sealed before being handed to law enforcement.

Incident Handling, Risk, and Governance

Question

The following three steps belong to the chain of custody for federal rules of evidence. What additional step is recommended between steps 2 and 3? STEP 1 - Take notes: who, what, where, when and record serial numbers of machine(s) in question. STEP 2 - Do a binary backup if data is being collected. STEP 3 - Deliver collected evidence to law enforcement officials.

Options

  • ARebuild the original hard drive from scratch, and sign and seal the good backup in a plastic bag.
  • BConduct a forensic analysis of all evidence collected BEFORE starting the chain of custody.
  • CTake photographs of all persons who have had access to the computer.
  • DCheck the backup integrity using a checksum utility like MD5, and sign and seal each piece of

How the community answered

(57 responses)
  • A
    5% (3)
  • B
    16% (9)
  • C
    7% (4)
  • D
    72% (41)

Why each option

After creating a binary backup of forensic evidence, integrity must be verified with a cryptographic hash (such as MD5) and the evidence physically sealed before being handed to law enforcement.

ARebuild the original hard drive from scratch, and sign and seal the good backup in a plastic bag.

Rebuilding the original hard drive would alter or destroy the original evidence and is not a recognized chain-of-custody step; forensic practice requires preserving the original unmodified.

BConduct a forensic analysis of all evidence collected BEFORE starting the chain of custody.

Forensic analysis is performed on a verified copy after the chain of custody is established, not before - beginning analysis before integrity verification would compromise evidentiary value.

CTake photographs of all persons who have had access to the computer.

Photographing persons who accessed the computer is not a standard chain-of-custody step between backup creation and evidence delivery; access logs and signed documentation serve that purpose.

DCheck the backup integrity using a checksum utility like MD5, and sign and seal each piece ofCorrect

Running a checksum utility like MD5 on the backup produces a hash value that can later prove the evidence was not altered - a core requirement of chain of custody. Signing and sealing each piece of evidence in tamper-evident packaging then documents who had access and when, satisfying federal rules of evidence requirements for admissibility.

Concept tested: Digital forensics chain of custody integrity verification

Source: https://www.nist.gov/system/files/documents/2017/04/28/SP800-86.pdf

Topics

#chain of custody#digital forensics#MD5 checksum#evidence integrity

Community Discussion

No community discussion yet for this question.

Full GSEC Practice