Courseiva

200-201 Security Policies and Procedures Practice Question

During the containment phase of an incident, the IR team decides to power off a compromised server to prevent further damage. However, they later realize that this action may have destroyed volatile evidence. According to best practices, what should the team have done instead?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform a live forensic image of the server's memory before powering off

Short-term containment should preserve evidence; live imaging captures volatile data before power-off.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disconnect the server from the network but leave it running

    Why it's wrong here

    Disconnecting the network cable preserves volatile memory, running processes and open sockets for forensic capture, whereas powering off destroys them. This is the standard containment step when live analysis is required, but it fails here because the team had already powered the server off, so the evidence is gone.

  • ✓

    Perform a live forensic image of the server's memory before powering off

    Why this is correct

    Memory contents — running processes, network connections, encryption keys — are volatile and lost on power-off. Capturing a live memory image preserves that evidence for analysis, whereas shutting the server down destroys it irrecoverably, so imaging should precede containment.

  • ✗

    Immediately power off the server without any imaging

    Why it's wrong here

    Powering off without imaging destroys volatile evidence such as RAM contents, running processes and network connections, which are lost on shutdown. The team should have captured a memory image and live forensic data first. Powering off is only acceptable when imminent harm outweighs evidence preservation.

  • ✗

    Skip evidence collection and focus solely on containment

    Why it's wrong here

    Abandoning evidence collection forfeits the forensic record needed for root-cause analysis, scope assessment and any legal or regulatory follow-up. It is tempting under time pressure when stopping the attacker feels paramount, yet containment and preservation are performed together, not traded against each other.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.