Essential Practices for Forensic Investigation Workstations

Digital Forensics & Incident Response
Answer Correct answer: B — Restricting workstation access to authorized forensics personnel prevents evidence contamination and maintains investigation integrity.

Which of the following is an essential practice for workstations used to conduct a forensic investigation?

  1. A documented chain of custody log is kept for the workstations
  2. The workstations are only accessed by members of the forensics team Correct Answer
  3. Only forensics-related software is installed on the workstations
  4. The workstations are backed up and hardened on a regular basis

Community Votes

B
60%
A
40%

60% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the distinction between evidence tracking procedures and tool environment security, where restricted access prevents tampering rather than documentation.

Maintaining strict access controls on forensic workstations prevents evidence contamination and ensures investigation integrity, a consensus heavily supported by CISM candidates and security professionals.

Candidates frequently select chain of custody logs because they associate them with court admissibility, overlooking that chain of custody tracks physical evidence, not the analysis workstation itself.

Community Discussion (3 comments)

HN2025 👍 2 Selected: B
The answer is B, the chain of custody is not essential for the machine that is used for conducting the forensic investigation. The chain of custody applies to the evidence you're handling. Therefore, controlling access to the workstation is more important and ensure security and integrity
Josef4CISM 👍 2 Selected: A
Chain of custody is needed to have court ready material.
202da28 👍 1 Selected: B
Unauthorized access could lead to contamination of evidence, tampering with files, or accidental alteration of data, which could compromise the investigation.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Restricting workstation access to authorized forensics team members is fundamental to preserving the integrity of the investigation environment. Unauthorized personnel could inadvertently introduce malware, alter system configurations, or tamper with case files, compromising all subsequent findings. ISACA emphasizes that maintaining a trusted computing base for digital evidence analysis requires strict access governance.

Why the Other Options Are Wrong

Chain of custody logs track physical and logical possession of evidence items, not the tools used to analyze them. Limiting software installations is operationally impractical, as forensic systems require OS patches, network utilities, and licensed applications. Regular backups and hardening are standard IT hygiene but do not address the immediate security requirement during active forensic examinations.

Community Comment Notes

Many candidates initially debate between access control and chain of custody due to overlapping terminology in legal contexts. As noted in top-voted discussions, restricting access directly prevents data contamination and accidental file alteration. Contributors correctly highlight that while documentation is vital for court, environmental security takes precedence for the analysis machine itself.

Official Reference

Exam Strategy

When evaluating forensic infrastructure questions, distinguish between evidence handling procedures and tool environment security requirements. Always prioritize controls that directly prevent data contamination or unauthorized modification during the analysis phase.

Frequently Asked Questions

Why isn't chain of custody applied to the forensic workstation?

Chain of custody tracks physical and logical possession of evidence items, not the analysis tools themselves. Workstations require environmental security instead.

Does limiting installed software ensure forensic workstation integrity?

No, because forensic systems need OS updates, network utilities, and licensed applications. Strict access control is more practical and effective.

Related Analysis

Practice All CISM Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISM Practice Test →

← Back to CISM Study Guide