CompTIA CySA+ (CS0-003)Incident Response and ManagementEasy

A security team is investigating a data breach where sensitive customer information was exfiltrated. During the evidence collection phase, an analyst creates a forensic image of a hard drive. To ensure the integrity of the collected evidence, which of the following is the MOST crucial step after creating the image?

  1. AEncrypt the forensic image to protect its contents from unauthorized access.
  2. BGenerate a cryptographic hash of the original drive and the forensic image.
  3. CStore the image on a network-attached storage (NAS) device for easy access.
  4. DLabel the drive and image with a unique identifier and incident number.
Show answer & explanation

Correct answer: B. Generate a cryptographic hash of the original drive and the forensic image.

Generating cryptographic hashes of both the original drive and the forensic image and comparing them is crucial to verify that the image is an exact, unaltered copy of the original evidence, ensuring its integrity.

Why the other options are wrong

  • A. Encryption protects confidentiality, not integrity, although it is also a good practice for sensitive evidence.
  • C. Storing on a NAS might be convenient but doesn't primarily ensure integrity; it could also expose the evidence to more risk.
  • D. Labeling is important for chain of custody and organization but does not mathematically verify the integrity of the data itself.

Evidence Integrity

Ensuring that digital evidence remains complete, accurate, and unaltered from the moment of collection until its presentation.

  • Crucial for admissibility in legal proceedings.
  • Verified through cryptographic hashing.
  • Part of a robust chain of custody.

Memory trick: Collect, Preserve, Analyze, Present, maintain Chain of Custody and Integrity.

More Incident Response and Management questions