CompTIA CySA+ (CS0-002) — Question 301

Some hard disks need to be taken as evidence for further analysis during an incident response. Which of the following procedures must be completed FIRST for this type of evidence acquisition?

Answer options

Correct answer: B

Explanation

The correct answer is B because establishing a chain-of-custody is essential to maintain the integrity and authenticity of the evidence collected. Options A, C, and D are incorrect as they involve actions taken after the initial documentation of the evidence, which is critical for legal and investigative processes.