Courseiva

CS0-003 Incident Response and Management Practice Question

A CSIRT is following its incident response plan during a confirmed data breach. The team lead needs to ensure that all evidence collected is admissible in a future legal proceeding. Which of the following should the team lead implement FIRST?

⚠ Common exam trap

Test-takers frequently confuse the order of operations: collecting evidence without first establishing a chain of custody can render even technically perfect forensic images inadmissible.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establish a chain of custody log for all evidence items.

A chain of custody log is the first legal safeguard because it documents the who, what, when, and why of evidence handling. Without it, any forensic image or log can be challenged as tampered or unauthenticated. Other actions like imaging or interviews are important but do not by themselves ensure admissibility. The team lead should initiate the chain of custody before or during the first evidence collection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Notify law enforcement and await their instructions before collecting any evidence.

    Why it's wrong here

    Notifying law enforcement is prudent, but waiting for their instructions can delay containment and evidence preservation. The CSIRT should begin collecting and documenting evidence immediately, following its own plan, while coordinating with law enforcement. The chain of custody must be started regardless. Delaying collection risks losing volatile data and allows the attacker to continue. The team lead should not wait to establish the chain of custody.

  • ✓

    Establish a chain of custody log for all evidence items.

    Why this is correct

    A chain of custody log documents every person who handled evidence, when, and why. It is the foundational requirement for evidence integrity and admissibility. Without it, even properly collected evidence can be challenged in court. The log should be started at the beginning of evidence collection and maintained throughout the incident. This is the first step to ensure legal defensibility.

  • ✗

    Create a full forensic image of every affected system's hard drive.

    Why it's wrong here

    Creating forensic images is important, but without a chain of custody, the images may be deemed inadmissible. The chain of custody must be established before or at the time of collection to document who had access. Imaging is a collection technique, not the first legal safeguard. The team lead must prioritize the procedural framework that validates all subsequent evidence handling.

  • ✗

    Interview all employees who have access to the affected systems.

    Why it's wrong here

    Interviews can provide valuable information, but they are not the first step to ensure evidence admissibility. In fact, interviews should be conducted after evidence is preserved to avoid influencing witnesses or contaminating their recollections. The legal foundation is the chain of custody, which tracks the evidence itself. Interviews are part of the investigation, not the admissibility safeguard.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.