SSCP Incident Response and Recovery Practice Question
During a post-incident review of a data breach, the incident response team is evaluating the chain of custody for forensic evidence. Which THREE practices demonstrate proper evidence handling? (Choose three.)
⚠ Common exam trap
A common trap in this question is the misconception that hashing can be done at any point during the investigation, but integrity verification must occur before analysis begins to establish a baseline, not after the fact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A write blocker was used when creating a forensic image of the disk.
Option B is correct because a hardware or software write blocker prevents any modification to the original disk during imaging, preserving its integrity and admissibility as evidence. Option D is correct because comparing the hash (e.g., MD5 or SHA-256) of the forensic image to the hash of the original disk proves the image is a bit-for-bit duplicate and has not been altered. Option E is correct because maintaining an unbroken chain of custody requires every handler to record their name, date, time, and purpose of access, ensuring accountability and traceability. Option A is wrong because analyzing the original drive directly risks altering metadata and destroying evidence; instead, a forensic image should be analyzed. Option C is wrong because hashes must be computed immediately upon acquisition (before analysis) to establish a baseline for integrity verification, not only afterward.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The original hard drive was used directly for analysis to avoid delays.
Why it's wrong here
Analysing the original drive directly alters its contents, destroying the evidence's integrity; forensic work requires a write-blocked image, with the original preserved. It is tempting because imaging takes time during an active breach, and using the original would be acceptable only when no legal or disciplinary proceeding depends on the evidence.
- ✓
A write blocker was used when creating a forensic image of the disk.
Why this is correct
Using a hardware or software write blocker prevents any modification to the source disk during imaging, preserving its integrity as evidence. This directly satisfies the chain-of-custody requirement that forensic copies be bit-for-bit accurate and unaltered, ensuring the image remains admissible and defensible during the post-incident review.
- ✗
MD5 hashes were computed only after the analysis was complete.
Why it's wrong here
Hashes must be computed at seizure and re-verified throughout, so hashing only after analysis leaves the entire examination window unverified and any tampering undetectable. It is tempting because hashing does confirm integrity at some point, and it would be correct if the hash were captured immediately on acquisition and compared afterwards.
- ✓
The forensic image was verified by comparing its hash to the hash of the original disk.
Why this is correct
Hash comparison proves the forensic image is a bit-for-bit replica of the original disk, satisfying the integrity requirement of chain of custody. Any alteration during acquisition changes the hash, so a matching value confirms the copy is admissible and unmodified. This directly demonstrates proper evidence handling during the post-incident review.
- ✓
Each person who handled the evidence documented their name, date, time, and purpose.
Why this is correct
Documenting handler name, date, time and purpose creates an unbroken chain of custody, proving who possessed the evidence and why at every transfer. This satisfies the review's requirement to demonstrate proper evidence handling and defends the evidence's admissibility against tampering claims.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. What is the primary purpose of establishing a chain of custody for digital evidence?
easy- A.To reduce the size of evidence for storage
- B.To encrypt evidence for secure transmission
- ✓ C.To maintain evidence integrity and track handling
- D.To prioritize which evidence to analyze first
Why C: The primary purpose of establishing a chain of custody for digital evidence is to maintain evidence integrity and track every person who handled the evidence from collection through presentation in court. This process ensures that the evidence has not been tampered with, altered, or corrupted, which is critical for admissibility under legal standards such as the Federal Rules of Evidence (FRE) Rule 901. By documenting each transfer with timestamps, signatures, and hash values (e.g., MD5 or SHA-256), the chain of custody provides a verifiable audit trail that supports the evidence's authenticity and reliability.
Variation 2. Which of the following is the primary purpose of a chain of custody form in digital forensics?
easy- ✓ A.To track the possession and handling of evidence from collection to presentation
- B.To document the steps taken to contain an incident
- C.To record the hash values of forensic images
- D.To provide a list of approved forensic tools
Why A: A chain of custody form is used to document the chronological sequence of custody, control, transfer, analysis, and disposition of evidence. Its primary purpose is to track who had possession of the evidence and what was done with it from the moment of collection through to presentation in court. This ensures the evidence is admissible and has not been tampered with.
Variation 3. Which of the following is the PRIMARY purpose of establishing a chain of custody when handling digital evidence?
medium- A.To determine the priority of the incident
- B.To ensure that evidence is stored in a secure location
- ✓ C.To prove that evidence has not been altered or tampered with from collection to presentation
- D.To identify which forensic tools were used during analysis
Why C: The primary purpose of chain of custody is to create a documented, unbroken record of every person who handled the evidence, from collection through presentation in court. This documentation is critical to demonstrate that the digital evidence has not been altered, tampered with, or corrupted, thereby preserving its integrity and admissibility. Without a proper chain of custody, the opposing party can successfully challenge the evidence as unreliable or compromised.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.