Skip to content

CMA Final · Cost and Management Audit · Forensic Audit

A forensic auditor must preserve electronic evidence from a suspect executive's laptop for possible use in legal proceedings. Which action best protects the admissibility and integrity of that evidence?

The best action is to create a forensic bit-stream image using a write blocker and record its hash value. This preserves the original data unaltered, captures deleted material, and lets the hash prove integrity later, supporting chain of custody and admissibility in legal proceedings.

  1. ACopy key files to a pen drive after logging into the laptop
  2. BCreate a forensic bit-stream image using a write blocker and record its hash valueCorrect
  3. CPrint the emails and discard the device
  4. DAsk the executive to forward relevant files by email

Explanation

A bit-stream image taken through a write blocker preserves all data, including deleted files, without altering the original. The hash value shows later that the copy is unchanged, and a chain of custody record supports admissibility. Logging in and copying files alters metadata, and printing or forwarding loses integrity and the suspect controls the process.

Did you get it right without looking?

One question tells you little. A timed set on Forensic Audit shows your real accuracy, how long you take and where you lose marks.

More Forensic Audit questions