Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A security analyst suspects that a user's workstation is infected with a rootkit that has compromised the kernel. The workstation is still operational, and the analyst needs to capture forensic evidence. Which of the following actions should the analyst take FIRST to preserve the integrity of the evidence?

⚠ Common exam trap

The trap here is that candidates mistakenly believe Safe Mode bypasses rootkits, but Safe Mode still loads the compromised kernel, and rebooting destroys volatile evidence; the correct first step is always to capture memory before any system state changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform a memory dump using a trusted tool on a USB drive

When a rootkit has compromised the kernel, the operating system itself cannot be trusted to provide accurate data or execute commands without interference. Performing a memory dump using a trusted tool on a USB drive captures volatile data (RAM) before any system changes occur, preserving the evidence in its most pristine state for forensic analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a full antivirus scan in normal mode

    Why it's wrong here

    A normal-mode antivirus scan modifies files, timestamps and memory, and a kernel rootkit can hide from it anyway. It is tempting because scanning is the usual malware response, but that is remediation; forensic integrity requires capturing volatile data and an image before any scanning occurs.

  • ✓

    Perform a memory dump using a trusted tool on a USB drive

    Why this is correct

    A rootkit compromising the kernel can hide malicious activity from tools running within the live operating system. Capturing memory first with a trusted tool on write-protected removable media preserves volatile evidence before any shutdown or remediation destroys it.

  • ✗

    Reboot the system into Safe Mode and run rootkit removal tools

    Why it's wrong here

    Booting into Safe Mode alters the running kernel and memory state, destroying volatile evidence before capture. It is tempting because Safe Mode isolates malware for removal, but that is remediation, not forensic preservation; the analyst must first capture memory and disk images from the live system.

  • ✗

    Disconnect the workstation from the network and power it off immediately

    Why it's wrong here

    Powering off clears RAM, losing volatile artefacts such as running processes and network connections that a kernel rootkit hides in. It is tempting because isolation limits spread, but disconnecting from the network suffices; powering down destroys the evidence the analyst needs to capture first.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security analyst suspects that a workstation is infected with a kernel-level rootkit. The workstation is currently running and the analyst needs to preserve evidence for forensic analysis. Which of the following actions should the analyst take FIRST?

medium
  • A.Disconnect the workstation from the network
  • ✓ B.Create a forensic image of the hard drive
  • C.Run a rootkit removal tool
  • D.Power off the workstation

Why B: The first priority when dealing with a suspected kernel-level rootkit is to preserve non-volatile evidence before any actions that could alter the system. Creating a forensic image of the hard drive captures the current state of disk artifacts without modifying data. Volatile memory (RAM) should ideally be captured first, but since that is not an option, imaging the hard drive is the best choice. Disconnecting from the network or running removal tools could trigger the rootkit to destroy evidence, and powering off would lose volatile data and potentially alter disk evidence. Thus, creating a disk image is the safest first step among the given options.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.