200-201 Question 204
Single answerDuring a forensic investigation of a security breach, an analyst collects several types of evidence from the compromised system. Which of the following types of evidence is considered 'best evidence' in accordance with cybersecurity operations best practices?
- A
A detailed written account of events provided by an eyewitness.
- B
A copy of the system logs exported from the compromised server.
- C
The original hard drive from the compromised server, stored securely.
- D
Screenshots of critical error messages displayed during the incident.
Show answer and explanation
Correct answer: C
Explanation
In digital forensics, 'best evidence' refers to the original, unaltered data or artifact that is directly related to the incident under investigation. The original hard drive from the compromised server is considered the best evidence because it contains the primary data in its original state. Proper chain-of-custody procedures must be followed to ensure its admissibility in legal proceedings.
- A. Incorrect.
Although an eyewitness account may provide valuable context, it is considered hearsay and not the most reliable or admissible form of evidence in a forensic investigation.
- B. Incorrect.
A copy of system logs is secondary evidence since it is a duplicate of the original data and may not be admissible in court unless specific procedures are followed to prove its integrity.
- C. Correct.
The original hard drive from the compromised server is considered 'best evidence' as it is the primary source of data. It is the most reliable and admissible form of evidence in forensic investigations, provided it is handled properly to maintain integrity.
- D. Incorrect.
Screenshots may be useful for visualization or documentation purposes but are not considered 'best evidence' as they can be easily altered or manipulated.