Courseiva
mediumMultiple Choice

CCSP Practice Question: A security analyst is investigating a data breach…

A security analyst is investigating a data breach in a cloud environment. The analyst needs to preserve evidence for legal proceedings. Which of the following actions is most critical to ensure the chain of custody is maintained?

⚠ Common exam trap

CCSP often tests the distinction between integrity (hashing) and chain of custody (documentation) — the trap is choosing hashing as the most critical step when the question specifically asks about chain of custody.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Begin a detailed log documenting all actions, timestamps, and personnel involved.

Maintaining a detailed log documenting all actions, timestamps, and personnel involved is the most critical action to ensure chain of custody. Chain of custody requires an unbroken record of who handled the evidence, when, and what they did, so that it is admissible in legal proceedings. While hashing, isolation, and notification are important, the log is the foundational element that ties everything together.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Calculate cryptographic hashes of all relevant files.

    Why it's wrong here

    Hashing proves integrity but does not by itself document who handled the evidence, when, and how; chain of custody requires a documented, signed transfer log. It is tempting because hashes are essential for admissibility, and hashing would be the critical action when the concern is proving the data was not altered.

  • ✗

    Isolate all affected systems from the network to prevent further data loss.

    Why it's wrong here

    Isolation contains the breach and limits further data loss, a containment action rather than a custody control. It does not record who handled evidence, when, or where it moved. A documented, signed chain-of-custody record tracking every transfer and access is the critical requirement for legal proceedings.

  • ✓

    Begin a detailed log documenting all actions, timestamps, and personnel involved.

    Why this is correct

    Documenting every action, timestamp, and person handling evidence creates the unbroken audit trail that chain of custody demands. This satisfies the stem's legal-preservation constraint by proving evidence integrity from seizure onward, which isolated technical steps alone cannot demonstrate.

  • ✗

    Immediately notify senior management and legal counsel.

    Why it's wrong here

    Notifying management and legal counsel triggers escalation and preserves privilege, but generates no record of evidence handling. Custody concerns who held each item, when, and where. A documented, signed chain-of-custody record tracking every transfer and access is the critical requirement for legal proceedings.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.