CSI Evidence Collection & Chain of Custody 2 — Questions and Answers
Question 1: What information must be recorded on an evidence tag at the time of collection?
- Date, time, location, description, and collector's name (Correct answer)
- Suspect's name, case number, and anticipated court date
- Evidence weight, color, and estimated monetary value
- Witness names and their contact information only
Correct answer: Date, time, location, description, and collector's name
An evidence tag must capture the essential facts of collection — who, what, where, and when — to establish and maintain chain of custody.
Question 2: Which of the following best describes 'locard's exchange principle' and its relevance to evidence collection?
- Every contact leaves a trace, meaning physical evidence is often transferred between a subject and a scene (Correct answer)
- Evidence must be exchanged between jurisdictions when multiple agencies are involved
- Investigators must exchange findings with defense counsel before proceedings
- Physical contact with evidence must be minimized to prevent trace loss
Correct answer: Every contact leaves a trace, meaning physical evidence is often transferred between a subject and a scene
Locard's Exchange Principle holds that any physical interaction leaves microscopic evidence behind, forming the scientific basis for trace evidence collection.
Question 3: When transferring evidence to another investigator or storage facility, what document must accompany it?
- An evidence transfer log signed by both the releasing and receiving parties (Correct answer)
- A sworn affidavit from the original collector only
- A duplicate copy of the original incident report
- A property receipt signed by the facility manager alone
Correct answer: An evidence transfer log signed by both the releasing and receiving parties
A transfer log with signatures from both parties creates a documented, unbroken chain of custody during handoffs.
Question 4: What is the correct procedure when a security investigator discovers that evidence has been tampered with during storage?
- Document the discovery, notify supervisors, and preserve the compromised evidence as a new finding (Correct answer)
- Discard the compromised evidence to avoid legal complications
- Re-collect replacement evidence from the original scene
- Correct the chain of custody log retroactively to show no break
Correct answer: Document the discovery, notify supervisors, and preserve the compromised evidence as a new finding
Tampering must be documented immediately and reported; the compromised evidence itself becomes relevant to the investigation of the tampering.
Question 5: For how long should a security investigator generally retain evidence after a case is closed?
- According to the organization's retention policy and applicable legal requirements (Correct answer)
- For a minimum of 30 days regardless of case type
- Until the investigator's employment ends
- Only until the final report is submitted
Correct answer: According to the organization's retention policy and applicable legal requirements
Retention periods vary by jurisdiction, type of case, and organizational policy, and may extend for years if appeals or litigation are possible.
Question 6: Which method is used to preserve digital evidence found on a computer without altering the original data?
- Creating a forensic bit-for-bit image of the storage media (Correct answer)
- Copying files to a USB drive for analysis
- Printing all documents found on the device
- Rebooting the computer and capturing startup logs
Correct answer: Creating a forensic bit-for-bit image of the storage media
A forensic image duplicates every bit of the storage media, preserving all data including deleted files and metadata without modifying the original.
What information must be recorded on an evidence tag at the time of collection?