ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
During an incident investigation, a security analyst creates an encrypted Amazon EBS snapshot of a compromised EC2 instance and writes the details to the team's evidence log. The snapshot will later be exported to an S3 bucket for offline analysis by a different team. Which information must be recorded each time the snapshot changes custody to preserve a legally defensible chain-of-custody record?
The AWS Region and S3 bucket name to which the snapshot export is written.
The AWS KMS key ID used to encrypt the snapshot when it is copied or downloaded.
The full name and signature (or validated digital equivalent) of the individual assuming responsibility, along with the precise date and time of the transfer.
The SHA-256 hash of the snapshot's manifest file generated immediately after the export completes.
A valid chain of custody documents a continuous, unbroken history of who had control of the evidence. Every transfer must note - the date and time of the hand-off and - the identity (name, title, or unique identifier) of the person accepting and releasing the evidence. Without this information, it is impossible to prove that the evidence was not altered while under someone else's control. Recording only technical details such as AWS Region, KMS key IDs, or cryptographic hash values is useful for integrity verification but does not, by itself, establish who was responsible for the evidence at each point in time.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the chain of custody in relation to digital evidence?
Open an interactive chat with Bash
Why are timestamps important in maintaining a chain of custody?
Open an interactive chat with Bash
How do tools like AWS support chain-of-custody processes in cloud environments?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Incident Response and Recovery
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .