Courseiva
Incident Handling ProcesseasyMultiple ChoiceObjective-mapped

212-89 Incident Handling Process Practice Question

While investigating a server compromise, you need to ensure the digital evidence collected from the RAID array is admissible in court. What is the most critical requirement for the chain of custody?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Maintaining a detailed log of every individual who accessed or transferred the evidence

Chain of custody requires a chronological log of who handled the evidence, where it was stored, and proof that it was not altered, typically via cryptographic hashes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Deleting temporary files to prevent cross-contamination

    Why it's wrong here

    Deleting files would destroy evidence and compromise the integrity of the original state.

  • Encrypting the collected evidence folder with AES-256

    Why it's wrong here

    Encryption protects confidentiality but does not track the legal chain of possession.

  • Creating a bit-stream image of the disk drive

    Why it's wrong here

    Imaging is a technical requirement for analysis, but it does not establish the legal chain of custody documentation.

  • Maintaining a detailed log of every individual who accessed or transferred the evidence

    Why this is correct

    A continuous, documented record of custody is essential to prove the integrity of the evidence in a legal proceeding.

Quick reference

RAID Level Comparison

RAID LevelMin DisksFault ToleranceReadWriteUsable Capacity
RAID 02NoneExcellentExcellent100%
RAID 121 diskGoodModerate50%
RAID 531 diskGoodModerate67–94%
RAID 642 disksGoodLower50–88%
RAID 1041 disk per mirrorExcellentGood50%

RAID is not a backup strategy — it protects against disk failure but not against accidental deletion, ransomware, or site-level events.

About these practice questions

Courseiva writes every 212-89 question from scratch — 206 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This 212-89 practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 212-89 exam.