How to Ensure Cyber Crime Computer Evidence Is Admissible in Court?

Digital Forensics & Evidence Handling
Answer Correct answer: B — Track possession of the computer to maintain an unbroken chain of custody required for legal admissibility.

An IS auditor finds a computer that is suspected to have been involved in a cyber crime. Which of the following activities is MOST critical to ensure data collected is admissible in a court of law?

  1. Notify law enforcement upon detection.
  2. Track possession of the computer. Correct Answer
  3. Collect audit logs from the affected computer.
  4. Power off the computer to ensure data is not changed.

Community Votes

B
50%
A
33%
C
17%

50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of digital evidence admissibility requirements, where candidates often mistakenly prioritize immediate hardware preservation over legally mandated documentation of evidence handling.

Maintaining a strict chain of custody is essential for ensuring digital evidence remains admissible in legal proceedings. Community consensus strongly confirms that tracking possession (Option B) outweighs immediate preservation steps like powering off the device.

Option D (Power off the computer) is frequently chosen because preserving volatile memory seems logical, but without documented proof of who handled the device and when, courts will exclude the evidence regardless of its technical state.

Community Discussion (7 comments)

blehbleh 👍 1 Selected: B
This is B. It has to be used in court eventually. If it has to be used in court you need to have a chain of custody otherwise it can't be used.
PurpleParrot 👍 1 Selected: B
Option B: track possession here implies maintain chain of custody
a84n 👍 1 Selected: C
Answer C
joehong 👍 1 Selected: B
Track possession of the computer ensure Chain of Custody
marc4354345 👍 1 Selected: A
Should be A. Suspected crime means law enforcement must be notified. They will run the forensic procedures. Powering down the computer will delete "data in use".
Sibsankar 👍 2
It may be D. Prioritizing the preservation of evidence by powering down the computer immediately ensures the data remains intact and maximizes its admissibility in court. It's important to emphasize the importance of following established forensic procedures and consulting with legal counsel to ensure proper handling and collection of digital evidence.
Rachy 👍 1 Selected: A
What about A?

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Maintaining a documented chain of custody is the absolute prerequisite for any digital evidence to be admitted in judicial proceedings. By tracking possession (Option B), the auditor creates a verifiable paper trail that proves the computer was not tampered with after discovery. This continuous documentation satisfies legal standards for evidence authenticity and prevents defense attorneys from successfully challenging the data integrity.

Why the Other Options Are Wrong

Notifying law enforcement (Option A) initiates an investigation but does not inherently protect the specific evidence already found by the auditor. Collecting audit logs (Option C) gathers valuable technical data, yet those logs become worthless if the underlying storage media lacks proper custody documentation. Powering off the system (Option D) may seem protective but actually destroys volatile memory containing crucial forensic artifacts while failing to address the legal documentation requirement.

Community Comment Notes

Community feedback consistently highlights the legal priority over technical preservation, with multiple users correctly identifying that tracking possession establishes the necessary chain of custody. Comment [2] explicitly notes that court usage fundamentally requires this documentation to prevent evidence exclusion. While Comment [1] advocates for immediate shutdown to preserve data, it overlooks the fact that admissibility hinges on procedural legality rather than temporary hardware states. Comment [5] raises valid points about law enforcement roles, but auditors must secure custody records before handing over devices to external agencies.

Official Reference

Exam Strategy

When answering digital forensics questions, always prioritize legal admissibility frameworks like chain of custody over purely technical actions. Remember that auditors must follow established legal protocols first, even if immediate technical preservation seems more urgent.

Frequently Asked Questions

Why is powering off the computer not the most critical step?

Immediate shutdown risks losing volatile RAM data and does not establish legal admissibility. Courts require documented chain of custody rather than just physical preservation.

Does notifying law enforcement replace chain of custody procedures?

Law enforcement handles investigations, but the auditor must still document every handover. Without tracked possession, evidence becomes inadmissible regardless of police involvement.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide