220-1102 Security Practice Question
A security analyst is investigating a potential data breach. The analyst has identified that an employee's workstation was infected with a keylogger that captured credentials. The analyst has already isolated the workstation from the network and created a forensic image. The analyst needs to determine exactly what data was exfiltrated. Which of the following is the BEST next step?
⚠ Common exam trap
Test-takers frequently think a forensic image alone contains all necessary evidence, but network logs are essential for tracking data in motion, which is not captured in a static disk image.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analyze network logs to identify outbound connections from the workstation.
B is correct because network logs contain records of outbound connections, including destination IP addresses, ports, and data transfer volumes. By analyzing these logs, the analyst can identify which external systems the workstation communicated with after the keylogger captured credentials, revealing the exfiltration destination and potentially the scope of data stolen. This is the most direct method to determine what data was exfiltrated, as the forensic image alone may not show real-time network activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan on the forensic image.
Why it's wrong here
Running an antivirus scan against the forensic image may confirm the presence of malware such as a keylogger, but antivirus signatures rarely cover custom or polymorphic threats. More critically, even a positive detection cannot reconstruct the exfiltrated data, the destination IP, or the timing and volume of the transfer. The scan is a supplemental step, not the primary investigative technique for determining data loss.
- ✓
Analyze network logs to identify outbound connections from the workstation.
Why this is correct
Network logs — including firewall, proxy, DNS, and DHCP logs — are the authoritative source for reconstructing outbound activity from the workstation. By correlating timestamps with the malware's execution, an analyst can identify the destination IPs and domains, the protocol used (e.g., HTTPS, FTP, or DNS tunneling), and the byte counts of each egress connection, which directly reveals what was sent and to whom. Full packet capture or proxy records may even allow reassembly of the specific payload. This is the only option that provides concrete external evidence of the breach.
- ✗
Reinstall the operating system on the workstation and monitor for recurrence.
Why it's wrong here
Reinstalling the operating system is a remediation action, not an investigative one; it will overwrite the very artifacts needed to forensically reconstruct the incident. Any volatile data, logs, or residual malware would be destroyed, breaking chain of custody and potentially compromising legal admissibility. Monitoring for recurrence after reinstall only tells you if the same activity continues, but it cannot answer whether data already left the network or how much was taken.
- ✗
Interview the employee about their activities.
Why it's wrong here
Interviewing the employee is a human-intelligence step that may provide context on unusual system behavior or phishing susceptibility, but it is unreliable as technical evidence. The exfiltration could be automated, performed via a remote attacker, or the employee may be entirely unaware that malware sent data. Even a truthful employee cannot know what the process actually transmitted over the network; only packet-level and connection-level analysis can prove that.
Go deeper
Related to this question
Learn chapter
Data Destruction and Disposal
Key term
Image
An image is a complete snapshot of a system's operating system, applications, and settings, used to deploy or restore computing environments quickly.
Key term
Keylogger
A keylogger is a type of surveillance software or hardware that records every keystroke you type on your keyboard, often used without your knowledge to steal passwords and other sensitive information.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.