After seizing a suspected insider's laptop, a responder makes a bit-for-bit image of the drive. The legal team asks what step most directly proves the image was not altered after acquisition. What should be done?
Compute and document cryptographic hashes of both the source media and the forensic image using a collision-resistant algorithm like SHA-256. The hash generated from the source device and the hash of the acquired image must match exactly, providing strong evidence that no data was altered, added, or lost. This integrity check is a foundational practice in forensic imaging and is necessary to demonstrate the evidence is authentic and admissible in court.
Why this answer
Computing and documenting cryptographic hashes (e.g., SHA-256 or MD5) of both the source media and the forensic image immediately after acquisition creates a verifiable digital fingerprint. If the hash values match, it proves that the image is an exact, unaltered copy of the original drive. This step is foundational to maintaining the chain of custody and ensuring data integrity in forensic investigations.
Exam trap
The trap here is that candidates may confuse documentation steps (like recording hostnames) with integrity verification, or think that copying files to a USB drive is a valid forensic preservation method, when only cryptographic hashing provides mathematical proof of non-alteration.
How to eliminate wrong answers
Option A is wrong because recording the hostname and last logged-in user is part of documentation but does not provide any cryptographic verification that the image was not altered after acquisition. Option C is wrong because copying the most recent files to a USB drive for quick review introduces a separate copy that is not a bit-for-bit duplicate and does not prove the integrity of the original forensic image. Option D is wrong because returning the laptop to the user after imaging violates chain of custody and could allow tampering with the original evidence, but it does not directly prove the image was unaltered.