mediumMultiple Choice
200-201 Practice Question: During a security incident, an analyst needs to…
During a security incident, an analyst needs to preserve network evidence for forensic analysis. Which action should be taken first?
⚠ Common exam trap
Cisco often tests the order of volatility (RFC 3227) and the misconception that isolating or shutting down the system is the safest first step, when in fact it destroys the most volatile evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Capture the contents of volatile memory from affected systems.
During a security incident, the first priority is to capture volatile memory (RAM) because it contains critical evidence such as running processes, network connections, and encryption keys that will be lost when the system is powered off. Option D is correct because volatile data is ephemeral and must be collected before any action that could alter the system state, such as shutdown or isolation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Isolate the affected systems from the network.
Why it's wrong here
Isolating systems alters network state and can destroy volatile evidence such as active connections and memory-resident artefacts before capture, so it is not the first preservation step. Isolation is correct once evidence has been captured and containment is the priority.
- ✗
Create a forensic image of all hard drives.
Why it's wrong here
Imaging hard drives captures disk contents but omits volatile network evidence such as active sessions, ARP caches and packet flows, which are lost on shutdown. Disk imaging is correct when the required evidence resides on persistent storage rather than in live network state.
- ✗
Shut down the affected systems to prevent further damage.
Why it's wrong here
Powering off destroys volatile evidence such as ARP caches, active sessions and running processes, and may trigger encrypted container lockout, so it cannot precede capture. It is tempting because shutting systems down genuinely contains an active threat, which is the right instinct in eradication or containment scenarios rather than forensic preservation.
- ✓
Capture the contents of volatile memory from affected systems.
Why this is correct
Volatile memory such as RAM and running processes is lost on shutdown or reboot, so capturing it first preserves evidence that cannot be recovered later. This satisfies the stem's ordering requirement, preceding disk imaging and other less perishable collection steps.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.