法医学捜査官のソフィアは、重大な企業データ窃盗事件を担当している。容疑者はIT部門の従業員で、数百もの機密ファイルを自分のノートパソコンにダウンロードした後、突然退職したとされている。
ソフィアは捜索差押令状を取得し、執行中に容疑者のノートパソコン、デスクトップコンピュータ、および複数の記憶装置を発見しました。証拠品の保管管理の連鎖を維持し、ACPO(米国検察庁)のデジタル証拠に関する原則を遵守するために、彼女は次にどのような行動をとるべきでしょうか?
正解:D
Option D is the best answer because CHFI v11 places strong emphasis on search and seizure , preserving evidence , chain of custody , and best practices for handling digital evidence . Once lawful authority exists and multiple potentially relevant devices are found, the proper next step is to seize the devices in a controlled manner , document them carefully, and move them to a forensic environment for structured analysis.
Analyzing devices on-site can increase the risk of contamination, incomplete documentation, or unintended alteration. Asking for passwords may be considered in some cases, but it is not the primary next step being tested here. Seizing only the laptop would be too narrow if the warrant and circumstances support collection of other relevant storage devices tied to the offense.
This approach aligns with CHFI's legal and procedural objectives because it preserves evidence integrity, supports a proper chain of custody, and ensures later analysis occurs in a controlled forensic lab environment.
Therefore, the correct action is to seize all relevant devices and send them to the forensic lab for examination .