SSCP Incident Response and Recovery Practice Question
An incident response team is preparing to collect evidence from a compromised Linux web server. The team lead wants to ensure that the evidence will be admissible in a potential legal proceeding. Which TWO actions should the team take to maintain the integrity of the evidence? (Choose two.)
⚠ Common exam trap
The trap here is assuming that analyzing the original evidence is more accurate, when in fact it risks altering the evidence and breaking the chain of custody.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the chain of custody for each evidence item.
Maintaining evidence integrity requires documenting the chain of custody and using cryptographic hashes to verify that data has not changed. These practices ensure that evidence collected from the compromised Linux server can withstand legal scrutiny. Analyzing originals, storing evidence on the compromised system, or allowing unrestricted access all undermine integrity and admissibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Document the chain of custody for each evidence item.
Why this is correct
A chain of custody documents who handled the evidence, when, and for what purpose, which is essential for admissibility. Without it, opposing counsel can challenge whether the evidence was tampered with or altered. In this scenario, documenting custody for each item collected from the Linux server establishes an unbroken record that supports the evidence's integrity in legal proceedings.
- ✗
Analyze the original evidence directly to avoid any copy-related discrepancies.
Why it's wrong here
Analyzing original evidence risks altering or destroying it, which undermines integrity and admissibility. Forensic best practice is to work from verified copies while preserving the original in a secure location. In this scenario, analyzing the original Linux server evidence directly could modify timestamps or data, making it impossible to prove the evidence was not tampered with.
- ✓
Compute and record cryptographic hashes of the evidence before and after analysis.
Why this is correct
Cryptographic hashes such as SHA-256 provide a verifiable fingerprint of the evidence. Recording hashes before and after analysis demonstrates that the data was not altered during examination. For the compromised Linux server, hashing images and log files ensures that any changes can be detected, which strengthens the evidence's admissibility and rebuts claims of tampering.
- ✗
Allow all team members to access the evidence freely for efficiency.
Why it's wrong here
Unrestricted access to evidence compromises the chain of custody and creates opportunities for accidental or intentional alteration. Access should be limited to authorized personnel, and every access should be documented. In this scenario, allowing all team members free access to the Linux server evidence would weaken its integrity and admissibility in legal proceedings.
- ✗
Store evidence on the compromised server to maintain original context.
Why it's wrong here
Storing evidence on the compromised server exposes it to modification or destruction by the attacker or malware. Evidence should be stored on separate, secure media with restricted access. Keeping evidence on the compromised Linux server would violate integrity requirements and make it difficult to demonstrate that the evidence was not altered after collection.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.