Document everything and minimize handling. Record who collected what, from where, at what time and with which tool; hash the evidence at acquisition and verify that hash after every transfer; work only on copies; store originals with restricted, logged access; and record every custody change. Keep contemporaneous timestamped notes, and use write blocking or forensically sound acquisition so you can prove you did not alter the source.
Why interviewers ask this
Even a purely internal incident can end up in an employment case, an insurance claim or a regulatory filing. The interviewer wants to see that you build defensible habits by default rather than deciding retrospectively that a case matters. Hashing at acquisition, working on copies and maintaining a custody log are the specific practices they listen for, plus knowing the point where legal must be involved.
How to structure your answer
- Explain that you treat every case as if it may become legal.
- Describe acquisition: tooling, hashing and write protection.
- Describe custody: storage, access control and the transfer log.
- Mention contemporaneous notes and when legal gets involved.
Example answer
I work on the assumption that any case can turn into an employment matter or an insurance claim, because you never know at hour one. At acquisition I record the source system, the time in UTC, the tool and version, and who is doing it, then hash the image straight away and record that hash in the case notes. I work on a copy, never the original, and I verify the hash again after any transfer so I can show it did not change in my hands. The original goes into restricted storage where access is logged, and every time it moves the custody log gets a line: who, when, why. My notes are contemporaneous, written as I go and timestamped, and I do not tidy them up afterward, because a clean rewritten narrative is worth less than messy real time notes. If there is any hint of criminal activity or regulated data, I stop and bring legal in before I touch anything else.
Walking into this interview soon? GhostPilot listens to your live call, spots the question the moment it is asked, and puts a structured answer on your screen in real time. Try it on your next mock, or grab a $29 Session Pass, no subscription, for the real thing.
See how it worksFollow-up questions to expect
- How does this work for cloud evidence you cannot physically hold?
- What do you do if you realize you handled something incorrectly?
- How long do you retain evidence after a case closes?
Related cybersecurity analyst questions
Your interviewer will ask their own version of this. Paste your actual job description into the free Question Predictor and get the 20 questions that role is most likely to ask, with what each one is really probing.
Predict my questions