Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A security analyst suspects that a workstation is infected with a kernel-level rootkit. The workstation is currently running and the analyst needs to preserve evidence for forensic analysis. Which of the following actions should the analyst take FIRST?

⚠ Common exam trap

Test-takers frequently confuse incident response containment (disconnect from network) with forensic preservation, failing to recognize that imaging must occur first to avoid evidence spoliation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a forensic image of the hard drive

The first priority when dealing with a suspected kernel-level rootkit is to preserve non-volatile evidence before any actions that could alter the system. Creating a forensic image of the hard drive captures the current state of disk artifacts without modifying data. Volatile memory (RAM) should ideally be captured first, but since that is not an option, imaging the hard drive is the best choice. Disconnecting from the network or running removal tools could trigger the rootkit to destroy evidence, and powering off would lose volatile data and potentially alter disk evidence. Thus, creating a disk image is the safest first step among the given options.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disconnect the workstation from the network

    Why it's wrong here

    Disconnecting from the network is important to prevent further damage or data exfiltration, but preserving the forensic image first ensures that volatile evidence (e.g., memory contents, running processes) is captured before any network disconnection might alter the system state.

  • ✓

    Create a forensic image of the hard drive

    Why this is correct

    Creating a forensic image preserves the exact state of the hard drive, including the rootkit and any evidence in memory (if a live acquisition tool is used). This is the first and most critical step in forensic analysis.

  • ✗

    Run a rootkit removal tool

    Why it's wrong here

    Running a rootkit removal tool on a live, compromised system is dangerous because the tool relies on the very operating system that the rootkit has subverted, so it may fail to detect the threat or be actively deceived. Furthermore, any tool execution alters system state, overwriting critical artifacts such as timestamps, memory blocks, and file metadata that are essential for a subsequent forensic investigation. The only sound approach is to first create a bit-for-bit forensic image of the hard drive and preserve volatile memory, then perform analysis and remediation in a controlled lab environment.

  • ✗

    Power off the workstation

    Why it's wrong here

    Powering off the workstation is the antithesis of forensic preservation because it destroys volatile data—RAM contents, running processes, network connections, and encryption keys—that can be critical for identifying a memory-resident rootkit. In addition, many sophisticated rootkits include anti-forensic triggers that execute during shutdown sequences to wipe or corrupt logs, and a hard shutdown can leave the file system in an inconsistent state. The investigator should perform a live acquisition of memory and, if possible, the hard drive before any power transition, following the order of volatility.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.