An auditor is reviewing an evidence log associated with a cy - CompTIA CySA+ CSO-003

Question

An auditor is reviewing an evidence log associated with a cyber crime. The auditor notices that a gap exists between individuals who were responsible for holding onto and transferring the evidence between individuals responsible for the investigation. Which of the following best describes the evidence handling process that was not property followed?

Answers
  1. correct
Explanation

The correct answer is D. Chain of custody.

The chain of custody refers to the documented and traceable handling process of evidence from the time it is collected until it is presented in court or used in further investigation. This process ensures that the evidence remains in a secure, tamper-free state, and it provides a clear record of who had access to the evidence at every stage.

If there is a gap between individuals who were responsible for holding or transferring evidence, it means that the chain of custody was not properly followed. This could potentially undermine the integrity of the evidence, as it would be difficult to prove that the evidence was not tampered with during the gap.

Why the others are incorrect:

  • Validating data integrity: Validating data integrity refers to ensuring that the evidence has not been altered or corrupted, which is important but is part of the broader chain of custody. The issue described focuses on the tracking of the evidence, not data integrity.

  • Preservation: Preservation refers to maintaining the evidence in its original form to prevent alteration or degradation. While this is critical, the gap described relates specifically to the documentation of who handled the evidence, which falls under chain of custody.

  • Legal hold: A legal hold is a process used to preserve evidence in anticipation of litigation. This is more relevant when ensuring that relevant documents or materials are preserved during legal proceedings, not necessarily when tracking evidence between individuals during an investigation.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Security+ SY0-701

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered