Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A security analyst is investigating a compromised workstation that is suspected of having a kernel-level rootkit. The workstation is currently running and the analyst needs to preserve evidence for forensic analysis. Which of the following actions should the analyst take FIRST?

⚠ Common exam trap

Test-takers frequently confuse 'preserving evidence' with 'immediate containment'—they choose to power off (Option A) thinking it freezes the system, not realizing that memory-resident malware and volatile data are lost forever on shutdown.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a memory dump of the running system

A kernel-level rootkit operates at the operating system's core, making it invisible to file system scans and live analysis. Creating a memory dump preserves volatile data (e.g., running processes, network connections, loaded kernel modules) that would be lost on shutdown, allowing forensic tools like Volatility to analyze the rootkit's artifacts in memory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Power off the workstation immediately

    Why it's wrong here

    Powering off the workstation is the wrong first step because it destroys volatile memory (RAM), which is where live rootkit components, injected code, and encryption keys reside. A hard shutdown also triggers the operating system's shutdown hooks, which a kernel-mode rootkit can intercept to delete traces or even re-encrypt evidence. The forensic principle of order of volatility dictates capturing RAM before any power loss, so this action is irreversible evidence loss, not preservation.

  • ✗

    Run a full antivirus scan on the workstation

    Why it's wrong here

    Running a full antivirus scan is counterproductive because it changes the system state by creating logs, updating signatures, and reading files, which can modify timestamps and unallocated space. Moreover, a sophisticated rootkit hooks kernel APIs, so an antivirus scanner running through the OS sees only the fake 'clean' view and may fail to detect the malware—or worse, the scan's activity can trigger the rootkit to become more evasive or corrupt forensic evidence. Proper incident response requires memory acquisition before executing any analysis tools on the live system.

  • ✓

    Create a memory dump of the running system

    Why this is correct

    Creating a memory dump is the correct first step because it captures the exact volatile state of the compromised system, including rootkit code that exists only in RAM, running processes, network connections, and any in-memory decryption keys. This follows the order of volatility, preserving the most fragile evidence first before any disk-level or interaction-based steps. Tools like WinPmem or volatility-compatible dump files let investigators later analyze the rootkit without risk of the malware detecting the forensic activity.

  • ✗

    Remove the hard drive and create a forensic image

    Why it's wrong here

    Removing the hard drive and creating a forensic image is a sound later step, but doing it first is wrong because it typically requires shutting down or disconnecting power, which destroys volatile memory. Even with hot-swap capability on some SATA systems, pulling the drive changes the live state and may cause a rootkit to notice that the storage it expects is gone, potentially triggering data destruction. The correct sequence is memory acquisition first—only after RAM is secured should the forensic imaging of non-volatile storage proceed.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.