200-201 Security Policies and Procedures Practice Question
During an incident, a forensic analyst needs to preserve evidence from a compromised hard drive. Which of the following steps is essential to maintain the chain of custody?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Documenting the date, time, and person handling the evidence
Chain of custody requires documenting each transfer, including who handled evidence and when. Write-blocking prevents alteration, and hashing verifies integrity. Documentation of transfers is key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deleting unnecessary files to reduce data volume
Why it's wrong here
Deleting files alters the original evidence, destroying its integrity and admissibility; chain of custody requires write-blocked imaging that leaves the source untouched. Reducing volume is tempting when storage or transfer time is constrained, but that is a capacity concern, not an evidence-preservation one.
- ✗
Storing the hard drive in a standard office drawer
Why it's wrong here
Chain of custody requires evidence stored in a secured, access-controlled location with documented transfers. An office drawer offers no lock, environmental control or audit trail, so it would be the choice only for non-evidentiary media awaiting disposal.
- ✓
Documenting the date, time, and person handling the evidence
Why this is correct
Chain of custody requires an unbroken record proving who held the evidence, when, and for what purpose. Documenting date, time, and handler creates this auditable trail, ensuring the drive's integrity can be attested in court and any tampering or gaps are detectable.
- ✗
Creating a bit-for-bit copy without write-blocking
Why it's wrong here
Write-blocking must precede imaging so the source disk is never altered; copying without it risks modifying timestamps and metadata, undermining evidentiary integrity. A bit-for-bit copy is correct only when made through a hardware or software write blocker.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.