200-201 Security Policies and Procedures Practice Question
A SOC analyst is investigating a suspected data exfiltration. The analyst needs to preserve evidence from a compromised workstation. Which of the following is the CORRECT procedure to ensure evidence integrity?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a write-blocker, compute hash of original disk, create image, compute hash of image, and compare hashes.
Proper evidence preservation requires hashing the original disk before imaging and then hashing the image to verify integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use a write-blocker, compute hash of original disk, create image, compute hash of image, and compare hashes.
Why this is correct
A write-blocker prevents modification of the source disk during acquisition, and hashing before and after imaging proves the copy is bit-for-bit identical. Comparing the two hashes verifies integrity, satisfying the requirement to preserve admissible evidence from the compromised workstation.
- ✗
Create a forensic image without write-blocking, then hash the image.
Why it's wrong here
Imaging without a write-blocker lets the host operating system write to the source disk, changing its contents before hashing; the hash then proves only the altered copy. A write-blocker must sit between source and target. Hashing is tempting because it verifies the image, but it cannot undo writes made during acquisition.
- ✗
Copy all files to an external drive without hashing.
Why it's wrong here
Copying files without hashing gives no verification that the copies match the originals, and copying through a running OS modifies source metadata. Hashing plus write-blocking establishes integrity. Bulk copying is tempting for speed and simplicity, but it suits ordinary backups, not evidence preservation where chain of custody and verifiable integrity are required.
- ✗
Disconnect the hard drive and boot from a live CD to collect data.
Why it's wrong here
Booting from a live CD still mounts the drive and writes to it, altering metadata and timestamps, so integrity is not preserved. Write-blocking or a hardware imager is required before reading. Live CDs are tempting for malware-safe collection, but they suit triage, not forensically sound acquisition of a suspect disk.
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.