Cisco Certified Support Technician (CCST) CybersecurityIncident HandlingMedium
A security team is documenting an incident involving a phishing attack that led to credential compromise. They need to ensure that all evidence collected, from initial email headers to forensic images of compromised workstations, is properly handled to maintain its admissibility in a potential legal proceeding. Which incident handling concept is paramount in this context?
- AVulnerability Management
- BChain of Custody
- CIncident Communication Plan
- DThreat Intelligence Sharing
Show answer & explanationAnswer & explanation
Correct answer: B. Chain of Custody
Maintaining Chain of Custody is crucial for ensuring that evidence collected during an incident is untampered, accounted for, and legally admissible. It tracks who had access to the evidence, when, and for what purpose.
Why the other options are wrong
- A. Vulnerability Management aims to reduce attack surfaces proactively, not handle evidence post-incident.
- C. An Incident Communication Plan focuses on who to tell and how, not the evidence itself.
- D. Threat Intelligence Sharing is about disseminating information about threats, not evidence handling.
Chain of Custody
The chronological documentation or paper trail showing the seizure, custody, control, transfer, analysis, and disposition of physical or electronic evidence.
- Ensures evidence integrity and authenticity.
- Required for evidence to be admissible in legal proceedings.
- Documents every handler and action performed on the evidence.
Memory trick: Chain of Custody is like a meticulous diary for every piece of evidence.