hardMultiple Choice
CS0-003 Chain of custody Practice Question
A laptop may contain evidence for a legal investigation. What should the responder document during acquisition? During post-incident improvement, which decision is most defensible?
⚠ Common exam trap
The CS0-004 exam often tests the misconception that only superficial details (like colour or job title) are sufficient for documentation, when in fact the full chain of custody—including collector identity, timestamps, hashes, and storage—is mandatory for evidence admissibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Who collected it, when, where, hash values, transfer details, and storage location
Proper chain of custody documentation is critical for evidence admissibility in legal proceedings. The responder must record who collected the evidence, the exact date and time, the physical location, cryptographic hash values (e.g., SHA-256) to verify integrity, transfer details (e.g., chain-of-custody forms), and the secure storage location. This ensures the evidence is not tampered with and can be defended in court. For the post-incident improvement phase, the most defensible decision is to formalize and enforce the same comprehensive documentation procedures based on lessons learned, thereby strengthening the overall incident response process and ensuring evidence integrity in future investigations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Only the laptop colour
Why it's wrong here
Device description alone is inadequate.
- ✗
Only the ticket priority
Why it's wrong here
Ticket priority is not chain-of-custody documentation.
- ✗
Only the user's job title
Why it's wrong here
A job title does not preserve evidence integrity.
- ✓
Who collected it, when, where, hash values, transfer details, and storage location
Why this is correct
Chain of custody records evidence handling and integrity from collection onward. In post-incident improvement, responders need action that reduces risk while preserving the investigation record.
Go deeper
Related to this question
Learn chapter
Lessons Learned and Post-Incident Activities
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.