Chain of Custody: Sealing and Documenting Evidence
Security receives a company-owned laptop connected to an insider theft investigation. Before the device is transported to the evidence locker, what is the BEST action to support chain of custody?
Quick Answer
The correct answer is to seal the device in an evidence bag and record each handoff with signatures. This is the best action because proper chain of custody evidence handling for a laptop requires both physical integrity and a documented audit trail; sealing the device prevents tampering, while signed handoffs create an unbroken record of every person who controlled the evidence. On the Security+ SY0-701 exam, this concept tests your understanding of forensic procedures and legal admissibility, often appearing in scenario-based questions where a common trap is to choose simply “label the device” or “take a photo” without securing it. Remember that chain of custody is about both containment and documentation—think of it as “bag it, tag it, and sign for every leg of the trip.” A useful mnemonic is “Seal and Sign” to lock in the two critical steps.
⚠ Common exam trap
Many candidates think a factory reset (Option A) helps investigators start clean, but it actually destroys evidence, while proper sealing and documentation (Option B) is the only method that preserves evidence integrity for legal proceedings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Seal the device in an evidence bag and record each handoff with signatures
Sealing the device in an evidence bag and recording each handoff with signatures establishes a documented, unbroken chain of custody. This ensures the integrity of the evidence by preventing tampering and providing a verifiable record of who handled the device and when, which is critical for admissibility in legal proceedings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Factory reset the laptop so investigators can start from a clean system
Why it's wrong here
A reset destroys potentially valuable evidence and breaks the integrity of the original device state.
- ✓
Seal the device in an evidence bag and record each handoff with signatures
Why this is correct
Sealing and documented handoffs create a defensible custody record and reduce the chance of tampering.
- ✗
Remove the hard drive and image it without any documentation
Why it's wrong here
Imaging may be useful, but undocumented handling weakens evidence integrity and chain-of-custody reliability.
- ✗
Leave the laptop unlocked so the next analyst can inspect it quickly
Why it's wrong here
An unlocked device is vulnerable to tampering and does not preserve a trustworthy evidence trail.
Go deeper
Related to this question
Learn chapter
Wireless Security Protocols
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 1,013 original SY0-701 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SY0-701
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Security receives a company laptop used in an insider theft investigation. A manager wants the device moved to another office for review by legal staff. Which action best supports chain of custody?
medium- A.Power on the laptop to confirm the user profile and recent activity before transport.
- ✓ B.Place it in a labeled evidence bag, record the collector, time, location, and condition, and require signatures for each transfer.
- C.Remove the drive and clone it without documenting the collection process.
- D.Email a photo of the laptop to legal and leave the original on a desk.
Why B: It follows the formal chain of custody process required for evidence handling. Placing the laptop in a labeled evidence bag with documented collector, time, location, and condition, along with requiring signatures for each transfer, ensures the integrity and admissibility of evidence by creating an unbroken audit trail. This aligns with NIST SP 800-86 and forensic best practices for maintaining custody of digital evidence.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.