Triage BoardGet the app

Concept · Response techniques

Chain of custody and evidence integrity

Chain of custody is the written record of who held a piece of evidence, when, and what they did with it, from collection to the courtroom. Integrity validation, usually a SHA-256 hash taken at collection and checked at every hand-off, proves the item did not change along the way. Both are evidence-gathering techniques in objective 3.3 of the CS0-004 exam objectives, listed with preservation and legal hold.

  • Exam code CS0-004
  • Tickets here 8

A log export nobody can vouch for

During a suspected data theft at a fictional manufacturer, an analyst exports a week of firewall logs, saves the file to a shared drive and messages a colleague where to find it. Three weeks later outside counsel asks for it. The file's modified time is later than the export, five people had write access to the folder, and no hash was ever taken.

The logs may be entirely accurate. As evidence they are close to worthless, because nothing shows they are the same bytes the firewall produced, or who could have changed them. An opposing expert does not need to prove tampering; the gap alone is enough to keep the file out or to shrink its weight. That is the job of a custody record: to leave no such gap.

Physical and digital items are tracked a little differently. A seized drive is an object: it moves between people, bags and safes, and every move is a line in the log. The forensic image made from it becomes a second item with its own ID and its own hash. A log export or a memory file never changes hands physically, so its custody is the access record of wherever it is stored, plus the hash that proves the bytes match.

The same discipline applies to everything collected under the order of volatility: a memory image taken in the first minutes of an incident is only useful if its custody record starts the moment it exists.

Integrity validation, two entries

shellHash at collection, hash again on receipt (fictional case IR-2611; hash values shortened)
# 2026-03-04 16:42 UTC  collected by R. Okafor (SOC)  case IR-2611  item 03$ sha256sum fw-export-0225-0303.log9c41e7d2a05b…f37a  fw-export-0225-0303.log# 2026-03-05 09:15 UTC  received by L. Varga (forensics)  case IR-2611  item 03$ sha256sum fw-export-0225-0303.log9c41e7d2a05b…f37a  fw-export-0225-0303.log# values match: item unchanged between collection and receipt

A match proves the bytes are unchanged. Who held the item in between still has to come from the custody log.

Keeping the chain unbroken

  1. Identify and label

    Give each item an ID and record where and when it was found and by whom. Photograph physical items in place.

  2. Acquire and hash

    Image drives through a write blocker so the original is never mounted for writing, and hash the image as soon as it exists.

  3. Seal and store

    Physical media goes into sealed, access-controlled storage; files go to a location with restricted write access and logging.

  4. Record every hand-off

    Date, time, the reason for the move and where the item went next. Gaps in this log are what a challenge goes after.

  5. Verify on receipt

    The receiver re-hashes and records the match before any analysis starts.

  6. Work on copies

    Examine a verified copy. The original stays sealed, so it can be re-hashed later if challenged.

The four terms objective 3.3 groups together

Chain of custody
The chronological record of possession and handling for each item of evidence.
Data integrity validation
Proof that an item is unchanged, normally by comparing cryptographic hashes such as SHA-256.
Preservation
Keeping evidence in its original state: write blockers, sealed storage, collection before volatile data disappears.
Legal hold
An instruction that suspends normal deletion and retention rules for relevant data. It collects nothing; it stops destruction.

Analysis on the originalTrap

Opening files on the original media updates access times and can write to the disk, which breaks the hash taken at collection. Examination always happens on a verified copy, and the original goes back into storage after imaging.

Custody under cross-examination

Read every custody log and transfer record here the way opposing counsel would.

Ticket 1 / 8

0 right

INC-001

Volatile evidence must be preserved for potential cross-jurisdictional legal action. Which step is required first?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: chain of custody starts at collection, with who collected the evidence, when, and a hash that later proves it has not changed; without that record, a court in any jurisdiction can challenge it.
  2. BAn unlocked locker lets anyone reach the media, so no one can prove it was not altered.
  3. CScreenshots emailed without hashes cannot be shown to be complete or unaltered, and email adds unrecorded handoffs.
  4. DShipping drives before anything is documented creates a transfer with no record of what was sent or by whom.

INC-002

What is the primary purpose of maintaining chain of custody during incident response?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ACustody documentation adds steps rather than speeding up the response.
  2. BCorrect: a documented record of who handled the evidence, when and why shows it was not altered, which is what courts require to admit it.
  3. CChain of custody adds documentation; it does not simplify it.
  4. DCustody tracking has nothing to do with storage costs.

INC-003

During a cybersecurity incident, your team is asked to preserve all communications and documents related to the breach. What is this process called?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: A

  1. ACorrect: a legal hold orders that all relevant documents and communications be preserved, with normal deletion suspended, when litigation is anticipated.
  2. BThe incident response plan is the overall playbook for handling incidents, not the specific order to preserve records.
  3. CEvidence logging records items collected during the investigation, while a legal hold covers all relevant communications and documents.
  4. DData normalization converts logs into a common format for analysis; it does not preserve records for legal purposes.

INC-004

Review the chain-of-custody log below. Which missing element renders the transfer at 14:00 legally inadmissible?

Exhibit

DateTimeReleased ByReceived ByPurpose
10/1209:00Analyst ASafe 1Storage
10/1214:00Analyst AImaging

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. AA hash proves integrity of the data, but the defect in this log is the blank receiving party on the transfer.
  2. BCorrect: the 14:00 transfer has no receiving party, and every transfer must record and be signed by both the person releasing and the person receiving the evidence.
  3. CThe imaging workstation's asset tag is useful detail, but its absence does not break custody the way an unknown recipient does.
  4. DThe room location is useful context, but custody depends on documenting who held the evidence at each handoff.

INC-005

Physical evidence is being shipped to a third-party forensic lab via a commercial courier. Which documentation precisely maintains the chain of custody across this transfer?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: D

  1. AHashes verify digital data, not a physical shipping container, and asset tags identify items without recording who held them in transit.
  2. BA courier's SLA promises a service level; it does not document who held this specific package and when.
  3. CPhotos of the seal help show tampering did not occur, but they do not record the chronological handoffs.
  4. DCorrect: waybill tracking tied to handoff times and courier signatures documents every transfer, so custody stays continuous while a third party holds the evidence.

INC-006

An IT specialist is assembling a toolkit for incident response. To ensure evidence collected from network breaches is securely transferred and stored without tampering, which of the following should be included in the toolkit?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: B

  1. ABlank USB drives can carry data, but they do nothing to show whether evidence was opened or altered in transit.
  2. BCorrect: tamper-evident bags show any attempt to open them, so evidence that is sealed, labeled and logged can be shown to be unaltered from collection to the lab.
  3. CAn incident response guide helps the team follow procedure, but it does not protect evidence during transfer or storage.
  4. DNetwork diagram templates help document the environment, not secure the physical evidence.

INC-007

A USB drive is discovered connected to a compromised workstation. Which procedure best preserves forensic admissibility?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. ACopying files first can change metadata and misses deleted or unallocated data, and hashing afterward cannot prove the original was unaltered.
  2. BRebooting with the drive attached can alter or execute its contents and destroys volatile evidence on the host.
  3. CCorrect: a write-blocked, bit-for-bit image preserves everything without modifying the drive, and hashing immediately proves the copy matches the original.
  4. DCopying files directly modifies access metadata, skips unallocated space and has no write protection.

INC-008

A security policy for a hybrid cloud environment requires the immediate physical extraction of hard drives when a compromise is detected. Why is this procedure inappropriate for IaaS assets?

Pick an option to open the notes on all of them.

Key and notes on every option

Key: C

  1. AProviders do not run destruction protocols triggered by customers; customers simply cannot physically access the hardware.
  2. BCloud volumes can be snapshotted and analyzed with standard forensic tools, so proprietary file systems are not the issue.
  3. CCorrect: IaaS customers have no physical access to the provider's multi-tenant hardware, so evidence must be collected with provider-native snapshots.
  4. DLegal process is not required every time; the customer can snapshot its own volumes directly through the provider's tools.

Shift tally

0 / 0

What a custody record lets you answer

  • What the item is and its ID
  • Where and when it was collected, and by whom
  • Its hash at collection and the algorithm used
  • Every hand-off: date, time, from whom, to whom, why
  • Where it is stored now and who can reach it
  • Every hash check since, and its result (response techniques covers the rest of objective 3.3)

Keep the queue going on your phone

Our practice app carries CySA+ questions to your phone, on iPhone and Android.