Courseiva
mediumMultiple Choice

200-201 Practice Question: During a security incident, an analyst needs to…

During a security incident, an analyst needs to preserve network evidence for forensic analysis. Which action should be taken first?

⚠ Common exam trap

Cisco often tests the order of volatility (RFC 3227) and the misconception that isolating or shutting down the system is the safest first step, when in fact it destroys the most volatile evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Capture the contents of volatile memory from affected systems.

During a security incident, the first priority is to capture volatile memory (RAM) because it contains critical evidence such as running processes, network connections, and encryption keys that will be lost when the system is powered off. Option D is correct because volatile data is ephemeral and must be collected before any action that could alter the system state, such as shutdown or isolation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Isolate the affected systems from the network.

    Why it's wrong here

    Isolating systems alters network state and can destroy volatile evidence such as active connections and memory-resident artefacts before capture, so it is not the first preservation step. Isolation is correct once evidence has been captured and containment is the priority.

  • ✗

    Create a forensic image of all hard drives.

    Why it's wrong here

    Imaging hard drives captures disk contents but omits volatile network evidence such as active sessions, ARP caches and packet flows, which are lost on shutdown. Disk imaging is correct when the required evidence resides on persistent storage rather than in live network state.

  • ✗

    Shut down the affected systems to prevent further damage.

    Why it's wrong here

    Powering off destroys volatile evidence such as ARP caches, active sessions and running processes, and may trigger encrypted container lockout, so it cannot precede capture. It is tempting because shutting systems down genuinely contains an active threat, which is the right instinct in eradication or containment scenarios rather than forensic preservation.

  • ✓

    Capture the contents of volatile memory from affected systems.

    Why this is correct

    Volatile memory such as RAM and running processes is lost on shutdown or reboot, so capturing it first preserves evidence that cannot be recovered later. This satisfies the stem's ordering requirement, preceding disk imaging and other less perishable collection steps.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.