How to Ensure Cyber Crime Computer Evidence Is Admissible in Court?
An IS auditor finds a computer that is suspected to have been involved in a cyber crime. Which of the following activities is MOST critical to ensure data collected is admissible in a court of law?
Community Votes
50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests understanding of digital evidence admissibility requirements, where candidates often mistakenly prioritize immediate hardware preservation over legally mandated documentation of evidence handling.
Maintaining a strict chain of custody is essential for ensuring digital evidence remains admissible in legal proceedings. Community consensus strongly confirms that tracking possession (Option B) outweighs immediate preservation steps like powering off the device.
Option D (Power off the computer) is frequently chosen because preserving volatile memory seems logical, but without documented proof of who handled the device and when, courts will exclude the evidence regardless of its technical state.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Maintaining a documented chain of custody is the absolute prerequisite for any digital evidence to be admitted in judicial proceedings. By tracking possession (Option B), the auditor creates a verifiable paper trail that proves the computer was not tampered with after discovery. This continuous documentation satisfies legal standards for evidence authenticity and prevents defense attorneys from successfully challenging the data integrity.Why the Other Options Are Wrong
Notifying law enforcement (Option A) initiates an investigation but does not inherently protect the specific evidence already found by the auditor. Collecting audit logs (Option C) gathers valuable technical data, yet those logs become worthless if the underlying storage media lacks proper custody documentation. Powering off the system (Option D) may seem protective but actually destroys volatile memory containing crucial forensic artifacts while failing to address the legal documentation requirement.Community Comment Notes
Community feedback consistently highlights the legal priority over technical preservation, with multiple users correctly identifying that tracking possession establishes the necessary chain of custody. Comment [2] explicitly notes that court usage fundamentally requires this documentation to prevent evidence exclusion. While Comment [1] advocates for immediate shutdown to preserve data, it overlooks the fact that admissibility hinges on procedural legality rather than temporary hardware states. Comment [5] raises valid points about law enforcement roles, but auditors must secure custody records before handing over devices to external agencies.Official Reference
Exam Strategy
When answering digital forensics questions, always prioritize legal admissibility frameworks like chain of custody over purely technical actions. Remember that auditors must follow established legal protocols first, even if immediate technical preservation seems more urgent.
Frequently Asked Questions
Why is powering off the computer not the most critical step?
Immediate shutdown risks losing volatile RAM data and does not establish legal admissibility. Courts require documented chain of custody rather than just physical preservation.
Does notifying law enforcement replace chain of custody procedures?
Law enforcement handles investigations, but the auditor must still document every handover. Without tracked possession, evidence becomes inadmissible regardless of police involvement.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →