nerdexam
(ISC)2

SSCP · Question #922

When referring to a computer crime investigation, which of the following would be the MOST important step required in order to preserve and maintain a proper chain of custody of evidence:

The correct answer is C. Verifiable documentation indicating the who, what, when, where, and how the evidence was. Two concepts that are at the heart of dealing effectively with digital/electronic evidence, or any evidence for that matter, are the chain of custody and authenticity/integrity. The chain of custody refers to the who, what, when, where, and how the evidence was handled-- from…

Submitted by paula_co· Apr 18, 2026Incident Response and Recovery

Question

When referring to a computer crime investigation, which of the following would be the MOST important step required in order to preserve and maintain a proper chain of custody of evidence:

Options

  • AEvidence has to be collected in accordance with all laws and all legal regulations.
  • BLaw enforcement officials should be contacted for advice on how and when to collect critical
  • CVerifiable documentation indicating the who, what, when, where, and how the evidence was
  • DLog files containing information regarding an intrusion are retained for at least as long as

How the community answered

(45 responses)
  • A
    9% (4)
  • B
    2% (1)
  • C
    87% (39)
  • D
    2% (1)

Explanation

Two concepts that are at the heart of dealing effectively with digital/electronic evidence, or any evidence for that matter, are the chain of custody and authenticity/integrity. The chain of custody refers to the who, what, when, where, and how the evidence was handled-- from its identification through its entire life cycle, which ends with destruction or permanent Any break in this chain can cast doubt on the integrity of the evidence and on the professionalism of those directly involved in either the investigation or the collection and handling of the evidence. The chain of custody requires following a formal process that is well documented and forms part of a standard operating procedure that is used in all cases, no exceptions. The following are incorrect answers: Evidence has to be collected in accordance with all laws and legal regulations. Evidence would have to be collected in accordance with applicable laws and regulations but not necessarily with ALL laws and regulations. Only laws and regulations that applies would be followed. Law enforcement officials should be contacted for advice on how and when to collect critical information. It seems you failed to do your homework, once you have an incident it is a bit late to do this. Proper crime investigation as well as incident response is all about being prepared ahead of time. Obviously, you are improvising if you need to call law enforcement to find out what to do. It is a great way of contaminating your evidence by mistake if you don't have a well documented processs with clear procedures that needs to be followed. Log files containing information regarding an intrusion are retained for at least as long as normal business records, and longer in the case of an ongoing investigation. Specific legal requirements exists for log retention and they are not the same as normal business records. Laws such as Basel, HIPPAA, SOX, and others has specific requirements.

Topics

#Chain of Custody#Digital Forensics#Evidence Handling#Incident Response

Community Discussion

No community discussion yet for this question.

Full SSCP Practice