220-1102 Operational Procedures Practice Question
A technician is supporting a field engineer tablet. The immediate goal is to handle a device that may contain evidence. Which tool, control, or procedure is the best fit?
⚠ Common exam trap
Watch out — candidates often confuse tools for investigating or recovering a device (like Event Viewer or System Restore) with the procedural requirement to preserve evidence integrity, leading them to overlook the critical legal and forensic need for chain of custody documentation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
chain of custody documentation
Chain of custody documentation is the correct choice because it is the formal process used to maintain the integrity of evidence from the moment it is collected until it is presented in court. When a tablet may contain evidence, the technician must document every transfer of custody, including who handled the device, when, and for what purpose, to ensure the evidence is admissible and has not been tampered with. This aligns with legal and forensic best practices for handling potential evidence in an operational procedures context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Local Users and Groups
Why it's wrong here
The Local Users and Groups snap-in manages user accounts, group memberships, and password policies on the Windows tablet. While this could be used to restrict access or reset credentials, it does not record who handled the tablet or preserve the device's state as evidence. User management is an administrative control, not a forensic or evidentiary documentation step, so it cannot achieve the immediate goal of establishing chain of custody.
- ✗
System Restore
Why it's wrong here
System Restore rolls back the operating system to an earlier restore point, changing registry keys, system files, and drivers. This process actively rewrites the current system state, which can destroy volatile forensic data and alter file timestamps and access logs. In a field environment where the tablet may need to be evidence, using System Restore would compromise data integrity and break the chain of custody rather than support it.
- ✓
chain of custody documentation
Why this is correct
Chain of custody documentation is a formal, continuous record of every person who possessed the tablet, the times of transfer, and the reasons for each handoff. The immediate goal in supporting a field engineer tablet is to preserve potential evidence with provable integrity, and this documentation is what demonstrates the tablet was not tampered with or swapped. Without a proper chain of custody, any data later recovered could be deemed inadmissible in court.
- ✗
Event Viewer
Why it's wrong here
Event Viewer is a Windows tool for reading application, security, and system logs after events have occurred. Although these logs can provide useful context about tablet activity, they cannot document a human's physical possession of the device or the purpose of each transfer. Logs are complementary artifacts, not a substitute for the explicit, signed records required for chain of custody in an investigation.
Go deeper
Related to this question
Learn chapter
Safety Procedures and Environmental Controls
Key term
Chain of custody
Chain of custody is a documented process that tracks the handling, transfer, and possession of evidence or digital assets from the moment they are collected until they are presented in court or used in an investigation.
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.