Skip to content

CS Professional · Internal and Forensic Audit · Audit and Investigations

In a forensic review of Lakshya Foods Ltd, the auditor collects a hard disk from a suspected employee's computer for analysis. Which step best protects the admissibility and integrity of the digital evidence?

The best step is to make a bit-by-bit forensic image verified by a hash value, analyse only the copy, and keep a chain of custody record. This keeps the original unaltered and demonstrates integrity, supporting admissibility, unlike browsing, deleting or selectively copying files.

  1. ABrowse the original disk directly to find files quickly
  2. BCreate a forensic image (bit-by-bit copy) with a hash value, work on the copy, and maintain a chain of custody recordCorrect
  3. CDelete irrelevant files from the disk to reduce its size
  4. DCopy only the files the auditor considers relevant to a pen drive

Explanation

Integrity is preserved by taking a bit-by-bit image, verifying it with a hash value so any change can be detected, analysing the copy and documenting who handled the original. Browsing the original alters metadata, deleting files destroys evidence, and selective copying to a pen drive loses deleted data and cannot be verified as complete.

Did you get it right without looking?

One question tells you little. A timed set on Audit and Investigations shows your real accuracy, how long you take and where you lose marks.

More Audit and Investigations questions