GSEC · Question #91
The following three steps belong to the chain of custody for federal rules of evidence. What additional step is recommended between steps 2 and 3? STEP 1 - Take notes: who, what, where, when and…
The correct answer is D. Check the backup integrity using a checksum utility like MD5, and sign and seal each piece of. After creating a binary backup of forensic evidence, integrity must be verified with a cryptographic hash (such as MD5) and the evidence physically sealed before being handed to law enforcement.
Question
The following three steps belong to the chain of custody for federal rules of evidence. What additional step is recommended between steps 2 and 3? STEP 1 - Take notes: who, what, where, when and record serial numbers of machine(s) in question. STEP 2 - Do a binary backup if data is being collected. STEP 3 - Deliver collected evidence to law enforcement officials.
Options
- ARebuild the original hard drive from scratch, and sign and seal the good backup in a plastic bag.
- BConduct a forensic analysis of all evidence collected BEFORE starting the chain of custody.
- CTake photographs of all persons who have had access to the computer.
- DCheck the backup integrity using a checksum utility like MD5, and sign and seal each piece of
How the community answered
(57 responses)- A5% (3)
- B16% (9)
- C7% (4)
- D72% (41)
Why each option
After creating a binary backup of forensic evidence, integrity must be verified with a cryptographic hash (such as MD5) and the evidence physically sealed before being handed to law enforcement.
Rebuilding the original hard drive would alter or destroy the original evidence and is not a recognized chain-of-custody step; forensic practice requires preserving the original unmodified.
Forensic analysis is performed on a verified copy after the chain of custody is established, not before - beginning analysis before integrity verification would compromise evidentiary value.
Photographing persons who accessed the computer is not a standard chain-of-custody step between backup creation and evidence delivery; access logs and signed documentation serve that purpose.
Running a checksum utility like MD5 on the backup produces a hash value that can later prove the evidence was not altered - a core requirement of chain of custody. Signing and sealing each piece of evidence in tamper-evident packaging then documents who had access and when, satisfying federal rules of evidence requirements for admissibility.
Concept tested: Digital forensics chain of custody integrity verification
Source: https://www.nist.gov/system/files/documents/2017/04/28/SP800-86.pdf
Topics
Community Discussion
No community discussion yet for this question.