Which Process Best Ensures Forensic Data Integrity?

Digital Forensics & Audit Evidence
Answer Correct answer: D — Maintain a strict chain of custody to document every transfer and access point, ensuring forensic data remains untampered and legally admissible.

Following a security incident, which of the following BEST enables the integrity of the data captured during a forensic investigation?

  1. An expert presenting the results of forensic analysis
  2. Comparison of the hash of data files in storage
  3. Comparison of the data with printouts from the investigation
  4. Maintenance of chain of custody Correct Answer

Community Votes

D
83%
B
17%

83% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the distinction between technical integrity verification (hashing) and procedural evidence handling, with candidates often mistaking hashing for the ultimate safeguard over chain of custody.

Maintaining a chain of custody is the most effective method for preserving forensic data integrity and legal admissibility, a consensus strongly reflected in CISA exam discussions and voting trends.

Option B is frequently chosen because hashing technically verifies file alterations, but it fails to account for the procedural accountability and legal admissibility required by auditors.

Community Discussion (4 comments)

blehbleh 👍 2 Selected: D
This is D. Literally for almost any exam ever if you see something about a forensic investigation you can immediately look for chain of custody as an answer and 9/10 that is the right choice. It has been explained below why it is correct but just for a heads up taking any other exam if it says forensic investigation look for chain of custody
1e71ed5 👍 3 Selected: D
It should be D. In forensic investigations, maintaining a chain of custody is more comprehensive because it covers the entire lifecycle of the evidence and ensures its integrity throughout the investigation process. While hash comparison is a part of this process, chain of custody provides the broader context needed for data integrity and legal admissibility.
Swallows 👍 1 Selected: B
Hash comparison is a common technique for verifying data integrity. By calculating hash values of files in storage that hold data captured during a forensic investigation and comparing those hash values, it is possible to verify whether the data has been altered. On the other hand, maintaining a chain of custody is important to ensure the continuity and reliability of evidence, but it is not a method to directly verify data integrity. A chain of custody is used to properly manage the handling of evidence and prevent tampering or unintentional changes, but it is not a means of verifying changes to the content of specific data. Therefore, comparing the hashes of data files in storage is the most effective way to verify the integrity of data captured after a security incident.
Sibsankar 👍 1
Hashing creates a unique digital fingerprint of data, which can be used to verify that the data has not been altered. By comparing the hash values of the data files at different stages (e.g., when they were first captured and later during analysis), investigators can confirm that the data remains unchanged, ensuring its integrity. This method is widely recognized and used in forensic investigations to maintain the authenticity and reliability of digital evidence. Right answer is B

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Chain of custody documents every individual who handled the evidence, when, and why, creating an unbroken audit trail. This procedural framework is explicitly designed to prevent tampering, loss, or contamination, directly satisfying ISACA’s requirements for evidence integrity and court admissibility. Without it, even technically sound forensic data may be dismissed in legal proceedings.

Why the Other Options Are Wrong

Hash comparison (Option B) only validates that a specific file hasn’t changed at a single point in time; it does not track who accessed it or how it was transported. Expert presentations (Option A) and printout comparisons (Option C) are analytical outputs rather than preservation controls, meaning they cannot inherently protect the underlying data from compromise.

Community Comment Notes

Multiple voters emphasize that chain of custody covers the entire evidence lifecycle, noting it provides the necessary legal context beyond mere technical checks. One contributor highlights a reliable exam heuristic: whenever “forensic investigation” appears, “chain of custody” is overwhelmingly the correct choice due to ISACA’s heavy focus on audit trails and compliance.

Official Reference

Exam Strategy

Always prioritize procedural controls and legal admissibility over technical tools when CISA questions ask about forensic evidence handling. If an option describes an audit trail, documentation, or accountability mechanism, it typically trumps isolated technical verification steps.

Frequently Asked Questions

Why isn't hashing the best answer for forensic data integrity?

Hashing only verifies file alterations at a specific moment, whereas chain of custody tracks the entire evidence lifecycle and proves legal admissibility to auditors.

When should I choose chain of custody over technical controls on CISA?

Prioritize chain of custody whenever the question emphasizes evidence handling, legal compliance, or audit trails, as ISACA values procedural accountability over isolated tools.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide