CISSP Security Operations Practice Question
During a forensic investigation, which TWO of the following are essential steps to maintain chain of custody?
⚠ Common exam trap
CISSP often tests the distinction between integrity controls (hashing) and custody controls (labeling and handling logs), causing candidates to select hashing as a chain-of-custody step when it is actually an integrity verification step.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Labeling evidence with date, time, and collector's name
Option C is correct because labeling evidence with the date, time, and collector's name creates an auditable record of when and by whom the evidence was first obtained, which is a foundational element of chain of custody. Option E is correct because documenting every person who handled the evidence establishes an unbroken, traceable custody trail that shows who had control of the evidence at all times and prevents tampering claims. Options A, B, and D do not belong: storing evidence on a shared network drive (A) compromises integrity and access control rather than preserving custody, encrypting the evidence file to prevent viewing (B) is a confidentiality measure that can hinder forensic examination and is not a chain-of-custody step, and although hashing (D) is essential for proving integrity, it is an evidence-integrity technique rather than a chain-of-custody documentation step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Storing evidence on a shared network drive
Why it's wrong here
Storing forensic evidence on a shared network drive is highly detrimental to maintaining the chain of custody. Such locations typically lack the stringent access controls necessary to prevent unauthorized viewing, modification, or deletion of critical evidence. This practice makes it nearly impossible to definitively prove that the evidence has not been tampered with, thereby compromising its admissibility in legal proceedings. Dedicated, secure, and access-controlled storage is always required.
- ✗
Encrypting the evidence file to prevent viewing
Why it's wrong here
Encrypting the evidence file primarily addresses confidentiality, preventing unauthorized viewing, and can contribute to integrity if authenticated encryption is used. However, encryption itself does not directly establish or maintain the chain of custody. The chain of custody is a meticulous record of possession and handling, documenting who had the evidence, when, and where, regardless of its encrypted state. While a good security practice, it doesn't replace the procedural documentation required for custody.
- ✓
Labeling evidence with date, time, and collector's name
Why this is correct
Labeling evidence immediately upon collection with essential details such as the date, time, and the name of the collector is a fundamental step in establishing a robust chain of custody. This initial documentation provides an irrefutable starting point for the evidence's lifecycle, clearly identifying when and by whom it was first secured. Accurate labeling ensures that each piece of evidence can be uniquely identified and tracked throughout the entire forensic process, preventing mix-ups and disputes over its origin.
- ✗
Performing a hash of the evidence immediately
Why it's wrong here
Performing a cryptographic hash of the evidence immediately after acquisition is a critical step for ensuring data integrity, creating a unique digital fingerprint that can detect any subsequent alteration. However, hashing alone does not directly maintain the chain of custody. The chain of custody is concerned with the physical and logical control of the evidence, documenting its possession and transfer, whereas hashing merely verifies that the data itself has not changed since the hash was computed. Both are crucial but serve distinct purposes.
- ✓
Documenting each person who handled the evidence
Why this is correct
Documenting every individual who handles the evidence, along with the dates, times, and reasons for transfer, is absolutely essential for maintaining an unbroken chain of custody. This meticulous record provides a complete audit trail of possession, demonstrating that the evidence has been continuously accounted for and protected from unauthorized access or alteration. It establishes accountability for every transfer, ensuring that the integrity and authenticity of the evidence can be legally upheld in court.
Go deeper
Related to this question
Learn chapter
Access Control Models and Mechanisms
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Hashing
Hashing is a one-way mathematical function that converts any input data into a fixed-length string of characters, called a hash or digest, which is used to verify data integrity and store passwords securely.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.