Courseiva

GCFA Enterprise Environment Incident Response Practice Question

An organization's incident response plan includes a requirement to maintain chain of custody for all digital evidence. A security analyst collects a USB drive from a compromised workstation. Which of the following is the MOST critical action to perform to ensure the evidence is admissible in a court of law?

⚠ Common exam trap

The trap here is focusing on technical preservation steps like imaging or secure storage, but the legal requirement for admissibility hinges on documented chain of custody.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the collection details, including date, time, location, and collector's name.

Chain of custody is a legal concept that documents the seizure, custody, control, transfer, analysis, and disposition of evidence. Proper documentation from the moment of collection is crucial to prove that the evidence has not been tampered with. This documentation includes details such as date, time, location, collector, and any transfers. Without it, the evidence may be deemed inadmissible.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Document the collection details, including date, time, location, and collector's name.

    Why this is correct

    Chain of custody documentation is essential for admissibility. It records the who, what, when, where, and why of evidence collection and transfer. Without proper documentation, the evidence can be challenged as tampered or unauthenticated. This is the most critical step to maintain integrity and admissibility.

  • ✗

    Store the USB drive in a secure, locked cabinet with limited access.

    Why it's wrong here

    Secure storage is important for preserving evidence, but it is not the most critical action for chain of custody. Without documentation of who accessed the evidence and when, secure storage alone does not prove integrity. Chain of custody requires a documented trail of possession.

  • ✗

    Create a forensic image of the USB drive using a write-blocker.

    Why it's wrong here

    Creating a forensic image is important for analysis, but it is not the most critical action for chain of custody. Chain of custody focuses on documenting who had control of the evidence and when. Imaging is part of preservation but does not alone establish the chain of custody.

  • ✗

    Analyze the USB drive immediately to identify the attacker.

    Why it's wrong here

    Immediate analysis without proper documentation and preservation can compromise the evidence. Analysis should be done on a forensic copy, and the original should remain untouched. Chain of custody must be established before analysis to ensure admissibility. Rushing to analyze can lead to challenges in court.

About these practice questions

One of 292 original GCFA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.