Worth 24% of the CompTIA CySA+ (CS0-004) exam. CertClue has 72 questions on this objective.
What this objective covers
Order of Volatility and Digital Forensic Evidence Handling
Digital evidence degrades or disappears at different rates depending on where it lives. Forensic collection follows the order of volatility so the most fragile evidence is captured before it is lost, and every step is documented so the evidence remains admissible.
Exam tip. If a scenario asks what to collect first from a running compromised system, the answer is always the most volatile item available, typically memory, not the disk.
The Incident Response Lifecycle and Chain of Custody
Incident response follows a repeatable lifecycle so nothing is skipped under pressure. Evidence handling runs alongside every phase of that lifecycle, since a poorly documented chain of custody can undermine an otherwise well-run response.
Exam tip. A question describing skipped documentation or an unbroken chain of custody question is almost always testing whether evidence can survive legal scrutiny, not the technical response itself.
Practice questions
Free, with the answer and the reasoning. No account needed.
1. Which phase of the incident response lifecycle involves actively limiting the spread and impact of an ongoing security incident, such as isolating an infected host from the network?
A. Identification
B. Containmentcorrect
C. Lessons learned
D. Preparation
Containment is the phase focused on limiting the spread and impact of an active incident, such as isolating a compromised host, which matches the scenario directly. Preparation happens before an incident occurs to build readiness, lessons learned happens after the incident closes to improve future response, and identification is the earlier phase of confirming that an incident is actually occurring, before containment actions begin.
2. During an incident at Stonebridge Municipal that may result in litigation, an analyst images a compromised laptop's hard drive and stores the forensic image on a shared network drive accessible to the entire IT department, without logging who accessed it afterward. Which forensic principle was most directly violated by this handling?
A. Order of volatility, since the laptop's hard drive was not the most volatile evidence source
B. Data minimization, since more evidence was collected than necessary for the investigation
C. Chain of custody, since the evidence was not access-controlled or logged after collection, undermining its integrity and admissibilitycorrect
D. Least privilege, since the analyst who created the image had more access than necessary
Chain of custody requires documenting and controlling every access to evidence from collection through storage, so that its integrity can be proven later, storing a forensic image on a broadly accessible share with no access logging breaks that chain and can make the evidence inadmissible or its integrity questionable. Order of volatility, data minimization, and least privilege describe different concepts not directly at issue here.
Work the whole objective
The full CompTIA CySA+ bank, the study notes behind these summaries, and a readiness score that tells you which objective to revise next. Free, no paid tier.