ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 549 - SY0-601 discussion

Report
Export

An incident response technician collected a mobile device during an investigation. Which of the following should the technician do to maintain chain of custody?

A.
Document the collection and require a sign-off when possession changes.
Answers
A.
Document the collection and require a sign-off when possession changes.
B.
Lock the device in a safe or other secure location to prevent theft or alteration.
Answers
B.
Lock the device in a safe or other secure location to prevent theft or alteration.
C.
Place the device in a Faraday cage to prevent corruption of the data.
Answers
C.
Place the device in a Faraday cage to prevent corruption of the data.
D.
Record the collection in a block chain-protected public ledger.
Answers
D.
Record the collection in a block chain-protected public ledger.
Suggested answer: A

Explanation:

Documenting the collection and requiring a sign-off when possession changes are essential steps for maintaining chain of custody during an investigation. Chain of custody is the process of documenting and preserving the integrity and authenticity of evidence from the time it is collected until it is presented in court. Documenting the collection involves recording information such as date, time, location, description, serial number, etc., of the evidence. Requiring a sign-off when possession changes involves obtaining signatures from every person who handles or transfers the evidence.

asked 02/10/2024
Farid Tannouch
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first