Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A security technician confirms that a user's workstation is infected with malware that is making outbound connections to a known command-and-control server. The technician has already isolated the workstation from the network. According to standard incident response procedures, what should the technician do NEXT?

⚠ Common exam trap

Many candidates confuse the order of incident response steps, thinking that eradication (reimaging) or reporting should come immediately after containment, but CompTIA emphasizes that evidence preservation must occur before any destructive or investigative actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Preserve evidence by creating a forensic image of the hard drive

After isolating the infected workstation, the next step in standard incident response procedures is to preserve evidence by creating a forensic image of the hard drive. This ensures that volatile and non-volatile data is captured before any further actions (like reimaging or scanning) could alter or destroy evidence needed for analysis, legal proceedings, or understanding the malware's behavior. The technician must follow the order of containment, evidence collection, analysis, and eradication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reimage the workstation with a clean OS

    Why it's wrong here

    Reimaging the workstation is a remediation step that erases all data by overwriting the entire disk with a clean OS image. This destroys the original file system, unallocated space, user artifacts, and any remnants of the malware, making later forensic analysis impossible. In a confirmed security incident, reimaging should never occur before evidence collection because it breaks the chain of custody and eliminates the ability to determine the scope and cause of the breach. Even a quick reimage forfeits the only chance to preserve volatile and persistent evidence for legal or disciplinary action.

  • ✓

    Preserve evidence by creating a forensic image of the hard drive

    Why this is correct

    Preserving evidence through a forensic image is the correct immediate step because it creates a bit-for-bit copy of the entire hard drive, including deleted files, slack space, and unallocated clusters, using a write blocker to prevent any alteration. The image is verified with cryptographic hashes such as SHA-256 to ensure it matches the original evidence, maintaining chain of custody. This allows investigators to analyze the system in depth without changing the original state, while the organization can later remediate using that preserved copy. All other actions, including scans or reporting, should follow this preservation step.

  • ✗

    Run a full antivirus scan

    Why it's wrong here

    Running a full antivirus scan is not the right first step because the scan itself modifies the system state: it updates signature databases, writes log entries, quarantines or deletes files, and changes file access times. These modifications can destroy volatile evidence or alter timestamps critical for reconstructing the attack timeline. Additionally, antivirus tools rely on known signatures and may miss advanced or zero-day malware, so a clean scan does not prove the system is trustworthy. In incident response, the cardinal rule is to preserve evidence before any tool that may write to the disk is executed.

  • ✗

    Report the incident to management

    Why it's wrong here

    Reporting the incident to management is important for escalation, but it is a communication and coordination action, not a technical evidence-preservation action. If performed before gathering forensic data, it risks prompting hasty containment measures—like a manager ordering an immediate wipe or disconnect—that could destroy evidence. Effective reporting should be based on accurate findings, which requires the analysis that a forensic image enables. Thus, while notification is necessary, it must follow evidence preservation to ensure the report contains verified details and to avoid spoliation.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.