Skip to content

CMA Final · Cost and Management Audit · Forensic Audit

In digital forensic evidence handling during an investigation, which practice best preserves the admissibility of electronic evidence collected from an employee's laptop?

The best practice is to take a bit-by-bit forensic image using a write blocker, record a hash value to prove integrity, and maintain a documented chain of custody. This shows the evidence was not altered and was handled only by authorised persons, which supports its admissibility.

  1. ACreate a forensic bit-by-bit image using a write blocker, record a hash value and maintain a chain of custodyCorrect
  2. BCopy only the relevant files to a pen drive and delete the originals to avoid duplication
  3. CLet the employee's IT team browse the laptop to identify the files before imaging
  4. DTake screenshots of selected emails and discard the device

Explanation

A write-blocked bit-by-bit image with a hash value proves that the copy is identical to the original and was not altered, and a chain of custody log shows who handled it. Browsing the original or deleting files alters metadata and weakens integrity. Screenshots alone cannot be authenticated as fully as an image.

Did you get it right without looking?

One question tells you little. A timed set on Forensic Audit shows your real accuracy, how long you take and where you lose marks.

More Forensic Audit questions