200-201 Security Policies and Procedures Practice Question
A SOC analyst is investigating a potential malware outbreak. Which THREE actions should the analyst take to preserve evidence? (Select three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Calculate a hash of the original drive before imaging
Option A is correct because calculating a cryptographic hash (e.g., MD5 or SHA-256) of the original drive before imaging establishes a verifiable baseline that proves the forensic image is an exact, unaltered copy, which is essential for evidence integrity and admissibility. Option C is correct because documenting the chain of custody records who handled, accessed, and transferred the evidence, and when, ensuring the evidence's integrity can be attested in legal or disciplinary proceedings. Option D is correct because using a hardware or software write blocker prevents any writes to the source drive while creating a forensic image, preserving the original evidence in an unmodified state. Option B is not correct because rebooting the system destroys volatile memory (RAM) contents such as running processes, network connections, and encryption keys, which are valuable evidence. Option E is not correct because running a full antivirus scan can modify or delete files and alter system state, contaminating the evidence rather than preserving it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Calculate a hash of the original drive before imaging
Why this is correct
Hashing the original drive before imaging establishes integrity verification, proving the source was unaltered. This satisfies evidence preservation by enabling later comparison of the forensic image against the original hash, demonstrating the copy is forensically sound and unmodified.
- ✗
Reboot the system to clear memory
Why it's wrong here
Rebooting clears volatile memory, erasing running processes, network connections and injected code that cannot be recovered afterwards. Rebooting is tempting because it often stops active malware quickly, and it would be appropriate during containment after memory has been captured and disk images preserved for analysis.
- ✓
Document the chain of custody
Why this is correct
Documenting chain of custody records every transfer, handler and storage location of evidence. This satisfies preservation requirements by proving the evidence remained unaltered and accounted for, keeping it admissible and defensible throughout the malware investigation.
- ✓
Use a write blocker to create a forensic image
Why this is correct
A write blocker prevents any modification to the source drive while a forensic image is captured. This satisfies evidence preservation by ensuring the original media remains untouched, so the resulting image is a defensible, bit-for-bit copy suitable for analysis.
- ✗
Run a full antivirus scan to remove malware
Why it's wrong here
Running a scan modifies or deletes the malware and alters file metadata, destroying the artefacts an investigation needs. Scanning is tempting because eradication is the eventual goal, and it would be the right action during remediation once forensic images and memory captures have been secured and the evidence chain documented.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.