SY0-301 · Question #531
SY0-301 Question #531: Real Exam Question with Answer & Explanation
The correct answer is C: Chain of custody. Chain of custody is the documented, unbroken record of who accessed or handled evidence, when, and how. When the workstation was left unattended for several hours before imaging, there is no way to prove that the evidence was not tampered with during that window. In court, opposi
Question
Options
- AEye Witness
- BData Analysis of the hard drive
- CChain of custody
- DExpert Witness
Explanation
Chain of custody is the documented, unbroken record of who accessed or handled evidence, when, and how. When the workstation was left unattended for several hours before imaging, there is no way to prove that the evidence was not tampered with during that window. In court, opposing counsel can argue that the evidence was compromised or altered while unattended, making it inadmissible or unreliable. Maintaining chain of custody requires continuous accountability of evidence from collection through presentation. The other options - eye witness, data analysis, and expert witness - are evidentiary tools that can still be used; it is the custody gap that is the critical legal problem here.
Community Discussion
No community discussion yet for this question.