CS0-003 Incident Response and Management Practice Question
A security analyst is investigating a potential insider threat where a user is suspected of exfiltrating sensitive data via USB drives. The analyst needs to gather evidence while preserving the chain of custody. Which THREE actions should the analyst perform? (Choose THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Creating a forensic image of the USB drive using a write blocker
Forensic sound procedures include imaging the drive, hashing to verify integrity, and documenting the chain of custody. Disabling the account is containment, and interviewing is not part of evidence collection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Creating a forensic image of the USB drive using a write blocker
Why this is correct
This captures the drive data without alteration.
- ✗
Disabling the user's network account immediately
Why it's wrong here
This is a containment step, not evidence preservation.
- ✗
Interviewing the user about their activities
Why it's wrong here
Interviews are part of investigation but not evidence preservation.
- ✓
Documenting the chain of custody for the USB drive
Why this is correct
Chain of custody documentation is critical for admissibility of evidence.
- ✓
Computing a hash of the original USB drive and the forensic image
Why this is correct
Hash verification ensures the image is an exact copy.
Go deeper
Related to this question
Learn chapter
Threat Intelligence and Threat Hunting
Key term
Containment
Containment is the incident response phase where security teams isolate a compromised system or network to prevent the threat from spreading further while preserving evidence.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 236 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.