220-1102 Operational Procedures Practice Question
A technician is called to investigate a potential data breach involving client PII. The technician has identified the affected systems and has taken screenshots of the current state. According to proper incident response procedures, what should the technician do NEXT?
⚠ Common exam trap
Watch out — candidates often confuse the urgency of containment (e.g., wiping malware) with the forensic requirement to preserve evidence first, or they mistakenly think notifying authorities is the immediate next step without following the incident response order: identification, preservation, containment, eradication, recovery, and lessons learned.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Preserve the evidence by creating forensic images of the hard drives.
In incident response, after identifying affected systems and documenting the current state (e.g., screenshots), the next critical step is to preserve volatile data and create forensic images of the hard drives. This ensures evidence integrity using write-blockers and hashing (e.g., SHA-256) to maintain a chain of custody, which is essential for legal or regulatory proceedings. Wiping or notifying authorities prematurely could destroy evidence or violate proper escalation protocols.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wipe the affected systems to remove any malware.
Why it's wrong here
Wiping the affected systems to remove malware is a destructive remediation step that destroys the very evidence needed to determine how the breach occurred. In incident response, preservation of digital evidence takes priority over immediate cleanup, because forensic analysis requires an unaltered copy of the original data. Even if malware is the suspected cause, wiping eliminates the artifacts — such as malicious binaries, logs, and registry entries — that would reveal the attacker's methods and scope. Remediation like wiping is only appropriate after evidence has been legally preserved and documented.
- ✗
Notify the relevant authorities immediately.
Why it's wrong here
While law enforcement or regulatory bodies may eventually need to be contacted, notifying them at the outset is premature because the immediate priority is to preserve volatile and non-volatile evidence before it is lost or altered. Incident response best practices follow a sequence: identification, containment, evidence preservation, and only then notification to authorities, unless a specific law mandates immediate reporting. Premature notification without a forensic image or documented evidence can compromise the investigation and lead to inaccurate conclusions. The correct first step is to create a defensible forensic copy of the data, then escalate internally and externally as required.
- ✓
Preserve the evidence by creating forensic images of the hard drives.
Why this is correct
Creating forensic images of the hard drives is the correct first response because it produces an exact bit-for-bit copy of the storage media while leaving the original untouched, typically using a hardware write blocker to prevent any accidental modifications. This image allows investigators to perform thorough analysis without risking damage to the evidence, and cryptographic hashes (e.g., SHA-256) are computed before and after the copy to verify integrity, establishing a clear chain of custody. This step aligns with the incident response phase of identification and preservation, ensuring that all data — including deleted files, unallocated space, and malware artifacts — is preserved for later examination. It is the only option that secures the evidence and supports a legally admissible investigation.
- ✗
Reinstall the operating system from scratch.
Why it's wrong here
Reinstalling the operating system from scratch overwrites the storage device, including areas that may contain remnants of the breach, such as malicious executables, timestamps, and user activity logs, making forensic recovery impossible. This is a recovery or eradication action that belongs after evidence preservation and analysis, not before. Furthermore, a clean installation does not necessarily eliminate rootkits or firmware-level infections, so without initial forensic imaging you may miss critical indicators of compromise. Destroying the original environment through reinstallation forfeits all opportunities for root-cause analysis and legal recourse.
Go deeper
Related to this question
Learn chapter
Escalation Procedures
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
Key term
Chain of custody
Chain of custody is a documented process that tracks the handling, transfer, and possession of evidence or digital assets from the moment they are collected until they are presented in court or used in an investigation.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.