Which practice best describes the proper handling and documentation of evidence to maintain its integrity?

Study for the EC-Council Certified Ethical Hacker (CEH) v13 Exam. Utilize flashcards and multiple-choice questions with helpful hints and detailed explanations. Excel in your exam preparation!

Multiple Choice

Which practice best describes the proper handling and documentation of evidence to maintain its integrity?

Explanation:
Preserving evidence integrity comes from handling it properly and keeping thorough documentation that creates an unbroken, auditable trail. This means following established procedures for collection, transfer, storage, and analysis, and recording every step in a chain of custody log with who touched the evidence, when, where, and why. In digital cases, it also involves verifying the data with hashes, using write blockers, and securing evidence to prevent tampering, so its state can be proven unchanged at any point in time. When these practices are in place, the evidence remains verifiable and admissible, because there is a clear, defendable record of its lifecycle. Other options describe important but narrower concepts: a chain of command governs who has authority to act, a data retention policy dictates how long data is kept, and evidence tagging helps organize items. None of these alone guarantees the full integrity and traceability that proper handling and documentation provide.

Preserving evidence integrity comes from handling it properly and keeping thorough documentation that creates an unbroken, auditable trail. This means following established procedures for collection, transfer, storage, and analysis, and recording every step in a chain of custody log with who touched the evidence, when, where, and why. In digital cases, it also involves verifying the data with hashes, using write blockers, and securing evidence to prevent tampering, so its state can be proven unchanged at any point in time. When these practices are in place, the evidence remains verifiable and admissible, because there is a clear, defendable record of its lifecycle.

Other options describe important but narrower concepts: a chain of command governs who has authority to act, a data retention policy dictates how long data is kept, and evidence tagging helps organize items. None of these alone guarantees the full integrity and traceability that proper handling and documentation provide.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy