Courseiva

SSCP Incident Response and Recovery Practice Question

After a security incident, an organization's legal team requests documentation that shows who had possession of a hard drive at every point from seizure to analysis. Which document should the incident responder provide?

⚠ Common exam trap

The trap here is assuming that any forensic documentation, like an imaging log, satisfies a chain of custody request, when only a chain of custody form tracks every transfer of possession.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Chain of custody form

A chain of custody form is the formal record that documents the seizure, transfer, and analysis of evidence. It includes dates, times, names, and signatures of everyone who handled the evidence. This ensures that evidence has not been tampered with and is admissible in court. The legal team's request for possession history is precisely what a chain of custody form provides, so it is the correct document.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Vulnerability assessment report

    Why it's wrong here

    A vulnerability assessment report identifies weaknesses in systems and prioritizes remediation. It has no role in documenting evidence possession. The legal team's request is about chain of custody, not security weaknesses. This document is irrelevant to the scenario, making it incorrect.

  • ✗

    Incident response plan

    Why it's wrong here

    An incident response plan outlines procedures for detecting, responding to, and recovering from incidents. It does not track individual evidence possession. While it may reference evidence handling, it does not provide the detailed custody log the legal team needs. Therefore, it is not the correct document for this request.

  • ✗

    Forensic imaging log

    Why it's wrong here

    A forensic imaging log records details about the imaging process, such as hash values and tool used. It may note who performed the imaging, but it does not track every transfer of evidence possession. The legal team wants a complete custody history, which is broader than an imaging log. Thus, this is not the correct choice.

  • ✓

    Chain of custody form

    Why this is correct

    A chain of custody form records the chronological history of evidence, including who collected it, when, and every transfer of possession. It ensures evidence integrity and admissibility in legal proceedings. The legal team's request for documentation of possession at every point directly matches the purpose of a chain of custody form, making it the correct answer.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.