Courseiva

200-201 Security Policies and Procedures Practice Question

A security analyst is reviewing an incident response policy that requires the team to preserve evidence for potential legal action. The analyst notices that the policy does not address how to handle evidence when a compromised system must be rebooted to restore services. What should the analyst recommend to balance evidence preservation with operational recovery?

⚠ Common exam trap

The trap here is assuming that rebooting first and collecting evidence later is acceptable, when volatile data such as RAM contents would be permanently lost.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture volatile memory and disk images before rebooting, and document the sequence of actions

When a compromised system must be rebooted, capturing volatile memory and disk images beforehand preserves evidence that would otherwise be lost. Documenting each action maintains chain of custody and supports legal admissibility. This balanced approach allows services to be restored without sacrificing the integrity of the investigation, addressing the gap in the current policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Shut down the system and store it in a secure room without further analysis

    Why it's wrong here

    This is incorrect because shutting down also loses volatile evidence and does not restore services, leaving the organization inoperable. While isolation is important, simply storing the system does not address the operational recovery requirement. The scenario explicitly states the system must be rebooted to restore services, so this option fails to balance both needs.

  • ✗

    Continue running the compromised system indefinitely to observe attacker behavior

    Why it's wrong here

    This is incorrect because allowing a compromised system to run indefinitely risks further damage, data exfiltration, and lateral movement. While monitoring can be valuable, it is not appropriate when services must be restored and legal evidence preserved. The scenario calls for a balanced approach, and indefinite observation ignores operational and legal priorities.

  • ✓

    Capture volatile memory and disk images before rebooting, and document the sequence of actions

    Why this is correct

    This is correct because volatile data such as RAM contents and running processes are lost on reboot, so capturing memory and disk images first preserves critical evidence. Documenting the sequence maintains chain of custody. This approach balances the need to restore services with the legal requirement to preserve evidence, which the current policy fails to address.

  • ✗

    Reboot immediately to restore services and collect evidence afterward from backups

    Why it's wrong here

    This is incorrect because rebooting destroys volatile evidence such as memory-resident malware and network connections, which may be essential for legal proceedings. Backups may not contain the compromised state or may have been affected by the same incident. The scenario asks how to balance both needs, and immediate reboot sacrifices evidence preservation.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.