220-1102 Security Practice Question
A security analyst suspects that a user's workstation is infected with a rootkit that has compromised the kernel. The workstation is still operational, and the analyst needs to capture forensic evidence. Which of the following actions should the analyst take FIRST to preserve the integrity of the evidence?
⚠ Common exam trap
The trap here is that candidates mistakenly believe Safe Mode bypasses rootkits, but Safe Mode still loads the compromised kernel, and rebooting destroys volatile evidence; the correct first step is always to capture memory before any system state changes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a memory dump using a trusted tool on a USB drive
When a rootkit has compromised the kernel, the operating system itself cannot be trusted to provide accurate data or execute commands without interference. Performing a memory dump using a trusted tool on a USB drive captures volatile data (RAM) before any system changes occur, preserving the evidence in its most pristine state for forensic analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run a full antivirus scan in normal mode
Why it's wrong here
A normal-mode antivirus scan modifies files, timestamps and memory, and a kernel rootkit can hide from it anyway. It is tempting because scanning is the usual malware response, but that is remediation; forensic integrity requires capturing volatile data and an image before any scanning occurs.
- ✓
Perform a memory dump using a trusted tool on a USB drive
Why this is correct
A rootkit compromising the kernel can hide malicious activity from tools running within the live operating system. Capturing memory first with a trusted tool on write-protected removable media preserves volatile evidence before any shutdown or remediation destroys it.
- ✗
Reboot the system into Safe Mode and run rootkit removal tools
Why it's wrong here
Booting into Safe Mode alters the running kernel and memory state, destroying volatile evidence before capture. It is tempting because Safe Mode isolates malware for removal, but that is remediation, not forensic preservation; the analyst must first capture memory and disk images from the live system.
- ✗
Disconnect the workstation from the network and power it off immediately
Why it's wrong here
Powering off clears RAM, losing volatile artefacts such as running processes and network connections that a kernel rootkit hides in. It is tempting because isolation limits spread, but disconnecting from the network suffices; powering down destroys the evidence the analyst needs to capture first.
Go deeper
Related to this question
Learn chapter
Data Sanitization: Wipe, Degauss, Shred, Incinerate
Key term
Kernel
The kernel is the core program of an operating system that manages hardware resources and provides essential services for all other software to run.
Key term
Rootkit
A rootkit is a type of malware that hides its presence and the presence of other malicious software on a computer, often by modifying the operating system itself.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security analyst suspects that a workstation is infected with a kernel-level rootkit. The workstation is currently running and the analyst needs to preserve evidence for forensic analysis. Which of the following actions should the analyst take FIRST?
medium- A.Disconnect the workstation from the network
- ✓ B.Create a forensic image of the hard drive
- C.Run a rootkit removal tool
- D.Power off the workstation
Why B: The first priority when dealing with a suspected kernel-level rootkit is to preserve non-volatile evidence before any actions that could alter the system. Creating a forensic image of the hard drive captures the current state of disk artifacts without modifying data. Volatile memory (RAM) should ideally be captured first, but since that is not an option, imaging the hard drive is the best choice. Disconnecting from the network or running removal tools could trigger the rootkit to destroy evidence, and powering off would lose volatile data and potentially alter disk evidence. Thus, creating a disk image is the safest first step among the given options.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.