Courseiva
Operational Procedures →hardMultiple Choice

220-1102 Operational Procedures Practice Question

A technician is documenting a security incident involving a potential data breach. The technician has collected logs, taken screenshots, and created a forensic image of the affected hard drive. The company's incident response policy requires that a formal report be submitted to management. Which of the following is the MOST critical element to include in the report?

⚠ Common exam trap

Many candidates confuse operational recovery steps (Option D) with the legal documentation required for evidence integrity, but the CompTIA 220-1102 exam emphasizes that chain of custody is paramount for any incident report that may face scrutiny.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The chain of custody for all evidence

The chain of custody is the most critical element because it documents the chronological handling of evidence, ensuring its admissibility and integrity in legal or regulatory proceedings. Without a proper chain of custody, logs, screenshots, and forensic images could be challenged as tampered or unreliable, undermining the entire incident response. This directly supports the formal report's purpose of providing a defensible, factual account of the breach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The names of all employees who accessed the system

    Why it's wrong here

    Although access logs can reveal which employees interacted with the affected system, simply listing names does not protect the integrity of the evidence or make the incident legally defensible. A formal security incident report prioritizes how evidence was collected and preserved, with employee attribution typically treated as part of the investigative findings rather than the central documentation. Prematurely focusing on names can also introduce privacy or data protection concerns that distract from the chain of custody, which is the true legal safeguard.

  • ✗

    The estimated financial impact of the breach

    Why it's wrong here

    An estimated financial impact is commonly calculated later for executive dashboards, insurance claims, or cost-benefit analyses, but it is not a foundational element of a formal incident report. Financial figures are inherently estimates and can change as the investigation matures, so they do not help prove what happened or how evidence was secured. The immediate priority is documenting the factual trail of evidence handling, since that supports legal defensibility and regulatory compliance far more than a dollar value.

  • ✓

    The chain of custody for all evidence

    Why this is correct

    Chain of custody is a documented chronological record of every time evidence was collected, moved, analyzed, or stored, including the names of handlers and the exact dates and times. This documentation proves that the evidence has not been altered or tampered with, which is essential for admissibility in court and for satisfying regulatory requirements. Without a strict chain of custody, the credibility of the entire investigation can be challenged, regardless of how compelling the underlying data may be.

  • ✗

    The steps taken to restore the system to normal operation

    Why it's wrong here

    System restoration steps, such as reimaging a compromised host or applying patches, are part of the remediation phase and are typically tracked in change management or incident response checklists rather than the formal incident report. More critically, restoration often destroys volatile evidence, so it should only occur after forensic collection is complete; documenting these steps as the primary content of the report would incorrectly suggest that operational recovery takes precedence over evidence preservation. The formal report must first establish the chain of custody and evidence integrity, while restoration details remain separate operational records.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.