A recent computer breach has resulted in the incident response team needing to perform a
forensics examination. Upon examination, the forensics examiner determines that they cannot tell
which captured hard drive was from the device in question. Which of the following would have
prevented the confusion experienced during this examination?
A.
Perform routine audit
B.
Chain of custody
C.
Evidence labeling
D.
Hashing the evidence