Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A security analyst is investigating a workstation that is suspected of being compromised. The analyst has disconnected the network cable and created a forensic image of the hard drive using a write-blocker. Which of the following should the analyst do NEXT to preserve evidence integrity?

⚠ Common exam trap

Candidates often think reconnecting to the network is necessary to gather live evidence, but CompTIA emphasizes that preserving the integrity of the forensic image through hash verification is the immediate priority after acquisition.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify the hash of the forensic image against the original drive

After creating a forensic image with a write-blocker, the next critical step is to verify the integrity of the image by comparing its hash value (e.g., MD5 or SHA-256) against the hash of the original drive. This ensures that the image is an exact, bit-for-bit copy and that no data has been altered during acquisition, which is essential for maintaining the chain of custody and admissibility in legal proceedings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reconnect the workstation to the network to check for active connections

    Why it's wrong here

    Reconnecting the workstation to the network is a live acquisition action that violates the order of volatility. It will change volatile system state, generate new network artifacts (e.g., ARP cache entries, DHCP lease updates, firewall logs), and could allow a dormant malware payload to phone home or propagate laterally to other hosts on the network. This permanently alters the evidence and may break the chain of custody. All analysis should be performed on a static forensic image without network connectivity.

  • ✓

    Verify the hash of the forensic image against the original drive

    Why this is correct

    Verifying the hash of the forensic image against the original drive confirms that the image is an exact bit-for-bit copy. A cryptographic hash such as SHA-256 is computed from the original drive (usually via a write blocker) and then computed again from the image; a match proves the image's integrity and admissibility as evidence. This step is foundational in forensic procedures because any subsequent analysis is only valid if the image faithfully represents the original media. It also protects against accidental corruption or incomplete acquisition.

  • ✗

    Run antivirus software on the original drive

    Why it's wrong here

    Running antivirus software on the original drive is unsafe for evidence preservation. Although a scan appears read-only, it can update file access times, last-write times, and filesystem journal metadata, thereby altering the original evidence. Moreover, if the workstation is infected with a live or polymorphic threat, the act of scanning could trigger the malware to execute, delete artifacts, or further modify the system. Forensic best practice requires making a verified image and performing all scanning and analysis on that image, never on the original drive.

  • ✗

    Delete any suspicious files found on the image

    Why it's wrong here

    Deleting suspicious files from the forensic image destroys potential evidence and is an act of spoliation. The image is a bit-for-bit replica of the original evidence, so any deletion changes the data and invalidates its hash, breaking the chain of custody and making the evidence inadmissible in court. Forensic analysis must be non-destructive: suspicious files should be quarantined, copied, or analyzed in place, but never removed from the evidence image. If isolation is needed, analysts should work on a separate working copy of the image instead.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.