CS0-003 Incident Response and Management Practice Question
A CSIRT is following its incident response plan during a confirmed data breach. The team lead needs to ensure that all evidence collected is admissible in a future legal proceeding. Which of the following should the team lead implement FIRST?
⚠ Common exam trap
Test-takers frequently confuse the order of operations: collecting evidence without first establishing a chain of custody can render even technically perfect forensic images inadmissible.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establish a chain of custody log for all evidence items.
A chain of custody log is the first legal safeguard because it documents the who, what, when, and why of evidence handling. Without it, any forensic image or log can be challenged as tampered or unauthenticated. Other actions like imaging or interviews are important but do not by themselves ensure admissibility. The team lead should initiate the chain of custody before or during the first evidence collection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notify law enforcement and await their instructions before collecting any evidence.
Why it's wrong here
Notifying law enforcement is prudent, but waiting for their instructions can delay containment and evidence preservation. The CSIRT should begin collecting and documenting evidence immediately, following its own plan, while coordinating with law enforcement. The chain of custody must be started regardless. Delaying collection risks losing volatile data and allows the attacker to continue. The team lead should not wait to establish the chain of custody.
- ✓
Establish a chain of custody log for all evidence items.
Why this is correct
A chain of custody log documents every person who handled evidence, when, and why. It is the foundational requirement for evidence integrity and admissibility. Without it, even properly collected evidence can be challenged in court. The log should be started at the beginning of evidence collection and maintained throughout the incident. This is the first step to ensure legal defensibility.
- ✗
Create a full forensic image of every affected system's hard drive.
Why it's wrong here
Creating forensic images is important, but without a chain of custody, the images may be deemed inadmissible. The chain of custody must be established before or at the time of collection to document who had access. Imaging is a collection technique, not the first legal safeguard. The team lead must prioritize the procedural framework that validates all subsequent evidence handling.
- ✗
Interview all employees who have access to the affected systems.
Why it's wrong here
Interviews can provide valuable information, but they are not the first step to ensure evidence admissibility. In fact, interviews should be conducted after evidence is preserved to avoid influencing witnesses or contaminating their recollections. The legal foundation is the chain of custody, which tracks the evidence itself. Interviews are part of the investigation, not the admissibility safeguard.
Go deeper
Related to this question
Learn chapter
Incident Categories and Severity
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.