220-1102 Operational Procedures Practice Question
A technician is documenting a security incident involving a potential data breach. The technician has collected logs, taken screenshots, and created a forensic image of the affected hard drive. The company's incident response policy requires that a formal report be submitted to management. Which of the following is the MOST critical element to include in the report?
⚠ Common exam trap
Many candidates confuse operational recovery steps (Option D) with the legal documentation required for evidence integrity, but the CompTIA 220-1102 exam emphasizes that chain of custody is paramount for any incident report that may face scrutiny.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The chain of custody for all evidence
The chain of custody is the most critical element because it documents the chronological handling of evidence, ensuring its admissibility and integrity in legal or regulatory proceedings. Without a proper chain of custody, logs, screenshots, and forensic images could be challenged as tampered or unreliable, undermining the entire incident response. This directly supports the formal report's purpose of providing a defensible, factual account of the breach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The names of all employees who accessed the system
Why it's wrong here
Although access logs can reveal which employees interacted with the affected system, simply listing names does not protect the integrity of the evidence or make the incident legally defensible. A formal security incident report prioritizes how evidence was collected and preserved, with employee attribution typically treated as part of the investigative findings rather than the central documentation. Prematurely focusing on names can also introduce privacy or data protection concerns that distract from the chain of custody, which is the true legal safeguard.
- ✗
The estimated financial impact of the breach
Why it's wrong here
An estimated financial impact is commonly calculated later for executive dashboards, insurance claims, or cost-benefit analyses, but it is not a foundational element of a formal incident report. Financial figures are inherently estimates and can change as the investigation matures, so they do not help prove what happened or how evidence was secured. The immediate priority is documenting the factual trail of evidence handling, since that supports legal defensibility and regulatory compliance far more than a dollar value.
- ✓
The chain of custody for all evidence
Why this is correct
Chain of custody is a documented chronological record of every time evidence was collected, moved, analyzed, or stored, including the names of handlers and the exact dates and times. This documentation proves that the evidence has not been altered or tampered with, which is essential for admissibility in court and for satisfying regulatory requirements. Without a strict chain of custody, the credibility of the entire investigation can be challenged, regardless of how compelling the underlying data may be.
- ✗
The steps taken to restore the system to normal operation
Why it's wrong here
System restoration steps, such as reimaging a compromised host or applying patches, are part of the remediation phase and are typically tracked in change management or incident response checklists rather than the formal incident report. More critically, restoration often destroys volatile evidence, so it should only occur after forensic collection is complete; documenting these steps as the primary content of the report would incorrectly suggest that operational recovery takes precedence over evidence preservation. The formal report must first establish the chain of custody and evidence integrity, while restoration details remain separate operational records.
Go deeper
Related to this question
Learn chapter
Certificate Management for A+
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
Key term
Image
An image is a complete snapshot of a system's operating system, applications, and settings, used to deploy or restore computing environments quickly.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.