220-1102 Security Practice Question
A security analyst is investigating a workstation that is suspected of being compromised. The analyst has disconnected the network cable and created a forensic image of the hard drive using a write-blocker. Which of the following should the analyst do NEXT to preserve evidence integrity?
⚠ Common exam trap
Candidates often think reconnecting to the network is necessary to gather live evidence, but CompTIA emphasizes that preserving the integrity of the forensic image through hash verification is the immediate priority after acquisition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify the hash of the forensic image against the original drive
After creating a forensic image with a write-blocker, the next critical step is to verify the integrity of the image by comparing its hash value (e.g., MD5 or SHA-256) against the hash of the original drive. This ensures that the image is an exact, bit-for-bit copy and that no data has been altered during acquisition, which is essential for maintaining the chain of custody and admissibility in legal proceedings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reconnect the workstation to the network to check for active connections
Why it's wrong here
Reconnecting the workstation to the network is a live acquisition action that violates the order of volatility. It will change volatile system state, generate new network artifacts (e.g., ARP cache entries, DHCP lease updates, firewall logs), and could allow a dormant malware payload to phone home or propagate laterally to other hosts on the network. This permanently alters the evidence and may break the chain of custody. All analysis should be performed on a static forensic image without network connectivity.
- ✓
Verify the hash of the forensic image against the original drive
Why this is correct
Verifying the hash of the forensic image against the original drive confirms that the image is an exact bit-for-bit copy. A cryptographic hash such as SHA-256 is computed from the original drive (usually via a write blocker) and then computed again from the image; a match proves the image's integrity and admissibility as evidence. This step is foundational in forensic procedures because any subsequent analysis is only valid if the image faithfully represents the original media. It also protects against accidental corruption or incomplete acquisition.
- ✗
Run antivirus software on the original drive
Why it's wrong here
Running antivirus software on the original drive is unsafe for evidence preservation. Although a scan appears read-only, it can update file access times, last-write times, and filesystem journal metadata, thereby altering the original evidence. Moreover, if the workstation is infected with a live or polymorphic threat, the act of scanning could trigger the malware to execute, delete artifacts, or further modify the system. Forensic best practice requires making a verified image and performing all scanning and analysis on that image, never on the original drive.
- ✗
Delete any suspicious files found on the image
Why it's wrong here
Deleting suspicious files from the forensic image destroys potential evidence and is an act of spoliation. The image is a bit-for-bit replica of the original evidence, so any deletion changes the data and invalidates its hash, breaking the chain of custody and making the evidence inadmissible in court. Forensic analysis must be non-destructive: suspicious files should be quarantined, copied, or analyzed in place, but never removed from the evidence image. If isolation is needed, analysts should work on a separate working copy of the image instead.
Go deeper
Related to this question
Learn chapter
Data Sanitization: Wipe, Degauss, Shred, Incinerate
Key term
Chain of custody
Chain of custody is a documented process that tracks the handling, transfer, and possession of evidence or digital assets from the moment they are collected until they are presented in court or used in an investigation.
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.