SSCP · Question #1202
When gathering digital evidence it is very important to do the following: (Choose all that apply)
The correct answer is C. Document the chain of evidence by taking good notes D. Perform a bit-level back up of the data before analysis. When gathering digital evidence, it is crucial to meticulously document the chain of custody and create a bit-level backup to preserve data integrity for forensic analysis.
Question
When gathering digital evidence it is very important to do the following: (Choose all that apply)
Options
- AShut down the compromised system to avoid further attacks
- BReboot the victim system offline
- CDocument the chain of evidence by taking good notes
- DPerform a bit-level back up of the data before analysis
How the community answered
(35 responses)- A3% (1)
- B9% (3)
- C89% (31)
Why each option
When gathering digital evidence, it is crucial to meticulously document the chain of custody and create a bit-level backup to preserve data integrity for forensic analysis.
Shutting down a compromised system destroys volatile data (like RAM contents, active network connections, running processes) that can be crucial evidence in a forensic investigation.
Rebooting a system, even offline, changes the system's state and can overwrite or destroy volatile evidence, making it an improper first step in digital evidence collection.
Documenting the chain of evidence, including who handled the evidence, when, and where, is absolutely critical to maintain its integrity and admissibility in legal proceedings.
Performing a bit-level backup (or forensic image) creates an exact, forensically sound duplicate of the original storage media, preserving all data, including deleted files and metadata, before any analysis can alter the original.
Concept tested: Digital evidence collection best practices
Source: https://csrc.nist.gov/publications/detail/sp/800-86/final
Topics
Community Discussion
No community discussion yet for this question.