Courseiva

200-201 Security Policies and Procedures Practice Question

A security analyst is investigating a potential data breach. They need to preserve evidence for legal proceedings. Which action should the analyst take to ensure the integrity of the data?

⚠ Common exam trap

The trap is thinking that any copy of data is sufficient for forensics; candidates underestimate how even read operations can alter metadata, and they may choose antivirus scanning or deletion as 'containment' steps that actually destroy evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a write blocker when creating a forensic image

A write blocker is a hardware or software tool that prevents any write operations to the storage device while a forensic image is being created, preserving the original evidence and ensuring the image is a bit-for-bit copy. This maintains the integrity and admissibility of evidence in legal proceedings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run antivirus scans on the affected system

    Why it's wrong here

    Antivirus scans modify file metadata, timestamps and quarantined content, contaminating evidence. Scanning is tempting because it identifies malware quickly during triage, but that belongs in live response; legal preservation demands a write-blocked forensic image taken before any remediation.

  • ✓

    Use a write blocker when creating a forensic image

    Why this is correct

    A write blocker enforces a hardware or software read-only mount, preventing any modification to the source drive during imaging. This preserves bit-for-bit integrity and maintains the chain of custody, satisfying the legal requirement that evidence remain unaltered and admissible in proceedings.

  • ✗

    Delete suspicious files to contain the threat

    Why it's wrong here

    Deleting suspicious files destroys the evidence needed for legal proceedings and cannot be undone. Containment by deletion is tempting when stopping active malware spread, but forensic preservation requires capturing a write-blocked image first; eradication happens only after evidence is secured.

  • ✗

    Copy files to a network share without write protection

    Why it's wrong here

    Copying to a network share without write protection lets the destination overwrite or alter files, destroying evidential integrity. Network shares are tempting for convenient centralised storage, but forensic preservation requires a write-blocked image with verified hashes, not a mutable copy.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.