Courseiva

CS0-003 Incident Response and Management Practice Question

A security analyst is investigating a potential data breach. The analyst needs to collect digital evidence while preserving its integrity. Which TWO actions should the analyst take? (Choose TWO.)

⚠ Common exam trap

CS0-004 often tests the misconception that antivirus scanning or deleting malware is part of evidence collection — candidates must recognize that any action that modifies the system destroys evidence integrity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify the hash of the acquired image against the original.

Option C is correct because verifying the hash (e.g., MD5 or SHA-256) of the acquired forensic image against the original source confirms that the copy is bit-for-bit identical and has not been altered, which is essential for maintaining evidence integrity and admissibility. Option D is correct because using a hardware or software write blocker when imaging the hard drive prevents any write operations to the suspect drive, ensuring the original evidence remains unmodified during acquisition. Option A is incorrect because running a full antivirus scan modifies system state, timestamps, and potentially quarantines or alters files, which contaminates evidence. Option B is incorrect because deleting malicious files destroys evidence and violates chain-of-custody and preservation principles. Option E is incorrect because connecting a suspect drive without a write blocker allows the forensic workstation's OS to write to the drive, altering metadata and compromising evidentiary integrity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Run a full antivirus scan on the system.

    Why it's wrong here

    Running an antivirus scan on the live system installs kernel drivers, updates signature databases, and writes temporary quarantine files, all of which modify the target's filesystem metadata (e.g., MAC times) and contaminate the evidentiary value of the drive. In forensic process, the system must be imaged first to preserve the state; scanning after imaging is safe, but scanning the live original violates the order of volatility.

  • ✗

    Delete any malicious files found during the investigation.

    Why it's wrong here

    Deleting suspected malware during the investigation is a spoliation of evidence that destroys the very artifacts needed for attribution and malware analysis, and it also updates the filesystem journal and parent-directory timestamps, making later discovery of the incident incomplete. The correct response is to document the file's existence, preserve the original in an image, and only then analyze it in an isolated sandbox.

  • ✓

    Verify the hash of the acquired image against the original.

    Why this is correct

    Computing a one-way cryptographic hash (such as SHA-256) of the original drive before acquisition and of the forensic image after, then comparing the two digests, is the definitive test that the image is a bit-for-bit clone with no changes introduced during capture. A matching hash validates the image for court admissibility and provides a baseline for later re-verification as part of the chain of custody.

  • ✓

    Use a write blocker when imaging the hard drive.

    Why this is correct

    A write blocker is deployed in the data path between the suspect storage device and the forensic workstation so that every write command from the host operating system is intercepted and rejected at the SATA/IDE/USB controller level, guaranteeing the original source remains untouched. This is a mandatory practice because simply mounting the drive in a read-only mode can still allow kernel-level journal writes or hibernation-file updates, and without it the evidence is not forensically sound.

  • ✗

    Connect the suspect drive to a forensic workstation without a write blocker.

    Why it's wrong here

    Plugging a suspect drive directly into a forensic workstation's internal controller gives the operating system unrestricted read/write access, which will mount the filesystem, update the last-accessed timestamps, and potentially write to volume shadow copies or page files, thus altering the original media's state. Unlike with a write blocker, there is no hardware-level barrier to prevent these modifications, so any data later recovered becomes suspect and challengeable in court.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.