CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium

A security analyst is investigating a potential insider threat where an employee is suspected of exfiltrating sensitive company data. The investigation requires collecting digital evidence from the employee's workstation. To ensure the evidence is admissible in court and its integrity is maintained, a strict protocol must be followed. Which of the following actions is MOST critical to establish and maintain the integrity and authenticity of the collected digital evidence?

  1. ALabelling all storage media with the case number and date.
  2. BStoring the evidence in a locked cabinet accessible only by authorized personnel.
  3. CCreating a cryptographic hash of the evidence before and after acquisition.
  4. DDocumenting all tools and methods used for evidence acquisition.
Show answer & explanation

Correct answer: C. Creating a cryptographic hash of the evidence before and after acquisition.

Creating a cryptographic hash (e.g., MD5, SHA256) of the evidence before and after acquisition provides mathematical proof that the data has not been altered. Any change, even a single bit, would result in a different hash value, thereby demonstrating a breach of integrity.

Why the other options are wrong

  • A. Labelling is important for organization but does not prove data integrity.
  • B. Secure storage protects the evidence from unauthorized access but doesn't prove its integrity was maintained during transfer or processing.
  • D. Documentation is crucial for repeatability and transparency but doesn't directly prove the integrity of the data itself.

Evidence Integrity

The assurance that digital evidence has not been altered or tampered with from the time it was collected until it is presented in court or used for analysis.

  • Crucial for legal admissibility.
  • Often verified using cryptographic hashing.
  • Part of a robust chain of custody.

Memory trick: Hash It Before You Touch It

More Incident Response and Management questions