nerdexam
(ISC)2

SSCP · Question #1202

When gathering digital evidence it is very important to do the following: (Choose all that apply)

The correct answer is C. Document the chain of evidence by taking good notes D. Perform a bit-level back up of the data before analysis. When gathering digital evidence, it is crucial to meticulously document the chain of custody and create a bit-level backup to preserve data integrity for forensic analysis.

Submitted by carlos_mx· Apr 18, 2026Incident Response and Recovery

Question

When gathering digital evidence it is very important to do the following: (Choose all that apply)

Options

  • AShut down the compromised system to avoid further attacks
  • BReboot the victim system offline
  • CDocument the chain of evidence by taking good notes
  • DPerform a bit-level back up of the data before analysis

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    9% (3)
  • C
    89% (31)

Why each option

When gathering digital evidence, it is crucial to meticulously document the chain of custody and create a bit-level backup to preserve data integrity for forensic analysis.

AShut down the compromised system to avoid further attacks

Shutting down a compromised system destroys volatile data (like RAM contents, active network connections, running processes) that can be crucial evidence in a forensic investigation.

BReboot the victim system offline

Rebooting a system, even offline, changes the system's state and can overwrite or destroy volatile evidence, making it an improper first step in digital evidence collection.

CDocument the chain of evidence by taking good notesCorrect

Documenting the chain of evidence, including who handled the evidence, when, and where, is absolutely critical to maintain its integrity and admissibility in legal proceedings.

DPerform a bit-level back up of the data before analysisCorrect

Performing a bit-level backup (or forensic image) creates an exact, forensically sound duplicate of the original storage media, preserving all data, including deleted files and metadata, before any analysis can alter the original.

Concept tested: Digital evidence collection best practices

Source: https://csrc.nist.gov/publications/detail/sp/800-86/final

Topics

#Digital forensics#Evidence collection#Chain of custody#Forensic imaging

Community Discussion

No community discussion yet for this question.

Full SSCP Practice