200-201 Security Policies and Procedures Practice Question
A security analyst is investigating a potential data breach. They need to preserve evidence for legal proceedings. Which action should the analyst take to ensure the integrity of the data?
⚠ Common exam trap
The trap is thinking that any copy of data is sufficient for forensics; candidates underestimate how even read operations can alter metadata, and they may choose antivirus scanning or deletion as 'containment' steps that actually destroy evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a write blocker when creating a forensic image
A write blocker is a hardware or software tool that prevents any write operations to the storage device while a forensic image is being created, preserving the original evidence and ensuring the image is a bit-for-bit copy. This maintains the integrity and admissibility of evidence in legal proceedings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run antivirus scans on the affected system
Why it's wrong here
Antivirus scans modify file metadata, timestamps and quarantined content, contaminating evidence. Scanning is tempting because it identifies malware quickly during triage, but that belongs in live response; legal preservation demands a write-blocked forensic image taken before any remediation.
- ✓
Use a write blocker when creating a forensic image
Why this is correct
A write blocker enforces a hardware or software read-only mount, preventing any modification to the source drive during imaging. This preserves bit-for-bit integrity and maintains the chain of custody, satisfying the legal requirement that evidence remain unaltered and admissible in proceedings.
- ✗
Delete suspicious files to contain the threat
Why it's wrong here
Deleting suspicious files destroys the evidence needed for legal proceedings and cannot be undone. Containment by deletion is tempting when stopping active malware spread, but forensic preservation requires capturing a write-blocked image first; eradication happens only after evidence is secured.
- ✗
Copy files to a network share without write protection
Why it's wrong here
Copying to a network share without write protection lets the destination overwrite or alter files, destroying evidential integrity. Network shares are tempting for convenient centralised storage, but forensic preservation requires a write-blocked image with verified hashes, not a mutable copy.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.