220-1102 Security Practice Question
A security analyst suspects that a workstation is infected with a kernel-level rootkit. The workstation is currently running and the analyst needs to preserve evidence for forensic analysis. Which of the following actions should the analyst take FIRST?
⚠ Common exam trap
Test-takers frequently confuse incident response containment (disconnect from network) with forensic preservation, failing to recognize that imaging must occur first to avoid evidence spoliation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a forensic image of the hard drive
The first priority when dealing with a suspected kernel-level rootkit is to preserve non-volatile evidence before any actions that could alter the system. Creating a forensic image of the hard drive captures the current state of disk artifacts without modifying data. Volatile memory (RAM) should ideally be captured first, but since that is not an option, imaging the hard drive is the best choice. Disconnecting from the network or running removal tools could trigger the rootkit to destroy evidence, and powering off would lose volatile data and potentially alter disk evidence. Thus, creating a disk image is the safest first step among the given options.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disconnect the workstation from the network
Why it's wrong here
Disconnecting from the network is important to prevent further damage or data exfiltration, but preserving the forensic image first ensures that volatile evidence (e.g., memory contents, running processes) is captured before any network disconnection might alter the system state.
- ✓
Create a forensic image of the hard drive
Why this is correct
Creating a forensic image preserves the exact state of the hard drive, including the rootkit and any evidence in memory (if a live acquisition tool is used). This is the first and most critical step in forensic analysis.
- ✗
Run a rootkit removal tool
Why it's wrong here
Running a rootkit removal tool on a live, compromised system is dangerous because the tool relies on the very operating system that the rootkit has subverted, so it may fail to detect the threat or be actively deceived. Furthermore, any tool execution alters system state, overwriting critical artifacts such as timestamps, memory blocks, and file metadata that are essential for a subsequent forensic investigation. The only sound approach is to first create a bit-for-bit forensic image of the hard drive and preserve volatile memory, then perform analysis and remediation in a controlled lab environment.
- ✗
Power off the workstation
Why it's wrong here
Powering off the workstation is the antithesis of forensic preservation because it destroys volatile data—RAM contents, running processes, network connections, and encryption keys—that can be critical for identifying a memory-resident rootkit. In addition, many sophisticated rootkits include anti-forensic triggers that execute during shutdown sequences to wipe or corrupt logs, and a hard shutdown can leave the file system in an inconsistent state. The investigator should perform a live acquisition of memory and, if possible, the hard drive before any power transition, following the order of volatility.
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
Dual In-line Memory Module
A Dual In-line Memory Module (DIMM) is a small circuit board that holds memory chips and plugs into a computer's motherboard to provide Random Access Memory (RAM).
Key term
Image
An image is a complete snapshot of a system's operating system, applications, and settings, used to deploy or restore computing environments quickly.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.