CISM Incident Management Practice Question
Which THREE of the following are essential elements of a forensic evidence handling procedure to ensure admissibility in court?
⚠ Common exam trap
A common misconception is that direct analysis on original systems is acceptable, but in forensic procedures, any direct manipulation of original media is prohibited to avoid altering the evidence and compromising its admissibility.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Placing a legal hold on relevant data
Option A is correct because a legal hold preserves potentially relevant data and prevents routine deletion or alteration, which is essential for demonstrating that evidence was not spoliated before collection. Option B is correct because a documented chain of custody records every transfer, access, and storage event for the evidence, allowing the court to verify its integrity and authenticity. Option E is correct because creating bit-for-bit forensic copies (forensic images) preserves the original media and allows analysis on a verified duplicate, typically validated with hash values such as MD5 or SHA-256. Option C is not correct because performing analysis directly on original systems can alter metadata, timestamps, and other artifacts, undermining admissibility. Option D is not correct because using automated tools without validation fails to establish that the tools produce reliable, repeatable results, which is necessary for forensic soundness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Placing a legal hold on relevant data
Why this is correct
A legal hold preserves relevant data and prevents routine deletion or alteration once litigation is reasonably anticipated. Issuing it early satisfies the admissibility requirement by ensuring potentially relevant evidence remains intact and available for forensic collection and court presentation.
- ✓
Maintaining a documented chain of custody
Why this is correct
A documented chain of custody records every transfer, handler and storage location of evidence from seizure to courtroom, proving the exhibits were not tampered with or substituted. This unbroken audit trail satisfies the admissibility constraint by letting the court verify integrity and continuity of possession.
- ✗
Performing analysis directly on original systems
Why it's wrong here
Analysing original systems alters metadata and destroys volatile artefacts, breaking the chain of custody and rendering evidence inadmissible. Forensic procedure requires write-blocked imaging and analysis on verified copies. Live analysis is tempting when systems cannot be taken offline, such as critical production servers, but that scenario demands documented, justified live-response methods rather than direct examination.
- ✗
Using automated tools without validation
Why it's wrong here
Unvalidated automation cannot demonstrate reliability, so opposing counsel can challenge output and the court may exclude it. Automated tools are appropriate for high-volume acquisition or hashing once validated and documented, but admissibility requires proven, tested tooling with recorded results.
- ✓
Creating bit-for-bit forensic copies of affected media
Why this is correct
Bit-for-bit imaging captures the entire raw media, including slack space, deleted files and unallocated clusters, using a write-blocker so the original remains unaltered. Analysis is performed on the verified copy, preserving the source as admissible best evidence while satisfying the forensic soundness constraint.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.