212-89 Incident Handling Process Practice Question
While investigating a server compromise, you need to ensure the digital evidence collected from the RAID array is admissible in court. What is the most critical requirement for the chain of custody?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Maintaining a detailed log of every individual who accessed or transferred the evidence
Chain of custody requires a chronological log of who handled the evidence, where it was stored, and proof that it was not altered, typically via cryptographic hashes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deleting temporary files to prevent cross-contamination
Why it's wrong here
Deleting files would destroy evidence and compromise the integrity of the original state.
- ✗
Encrypting the collected evidence folder with AES-256
Why it's wrong here
Encryption protects confidentiality but does not track the legal chain of possession.
- ✗
Creating a bit-stream image of the disk drive
Why it's wrong here
Imaging is a technical requirement for analysis, but it does not establish the legal chain of custody documentation.
- ✓
Maintaining a detailed log of every individual who accessed or transferred the evidence
Why this is correct
A continuous, documented record of custody is essential to prove the integrity of the evidence in a legal proceeding.
Quick reference
RAID Level Comparison
| RAID Level | Min Disks | Fault Tolerance | Read | Write | Usable Capacity |
|---|---|---|---|---|---|
| RAID 0 | 2 | None | Excellent | Excellent | 100% |
| RAID 1 | 2 | 1 disk | Good | Moderate | 50% |
| RAID 5 | 3 | 1 disk | Good | Moderate | 67–94% |
| RAID 6 | 4 | 2 disks | Good | Lower | 50–88% |
| RAID 10 | 4 | 1 disk per mirror | Excellent | Good | 50% |
RAID is not a backup strategy — it protects against disk failure but not against accidental deletion, ransomware, or site-level events.
About these practice questions
Courseiva writes every 212-89 question from scratch — 206 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official EC-Council exam blueprint
This 212-89 practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 212-89 exam.