CS0-003 Incident Response and Management Practice Question
A security analyst is performing forensic analysis of a compromised system. The analyst needs to acquire disk evidence in a forensically sound manner. Which TWO actions should the analyst take to ensure the integrity of the evidence? (Choose TWO.)
⚠ Common exam trap
A common mix-up: candidates confuse 'speed' or 'cleanup' actions (disabling write blocker, rebooting, running AV) with integrity-preserving actions — candidates who prioritize convenience over forensic soundness pick the wrong options.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Calculate a hash of the original drive before imaging
Option A is correct because calculating a cryptographic hash (e.g., MD5 or SHA-256) of the original drive before imaging establishes a baseline value that can later be compared to the hash of the forensic image, proving the data was not altered. Option C is correct because a hardware or software write blocker prevents any write operations to the source drive during acquisition, preserving the original evidence in an unmodified state as required for forensic soundness. Option B is incorrect because disabling the write blocker would allow the forensic workstation to write to the source drive, contaminating or altering the evidence. Option D is incorrect because powering on the system and running an antivirus scan modifies file system metadata, timestamps, and potentially deletes or quarantines files, destroying evidence integrity. Option E is incorrect because rebooting the system alters volatile data and can modify file system artifacts such as temporary files, log entries, and timestamps, which compromises the evidence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Calculate a hash of the original drive before imaging
Why this is correct
Computing a cryptographic hash (e.g., SHA-256) of the original drive before imaging establishes a baseline integrity value. This baseline lets the examiner later hash the acquired image and confirm it is bit-for-bit identical to the source, proving the imaging process did not alter or omit data. Recording the hash in chain-of-custody documentation also provides legal defensibility.
- ✗
Disable the write blocker to speed up the imaging process
Why it's wrong here
Disabling the write blocker to speed up imaging directly violates forensic best practice. Without hardware write protection, the operating system or imaging tool may issue write commands—such as file system journal updates, prefetch, or pagefile access—that modify timestamps, metadata, or data on the source drive. Any such change compromises the evidence and could make the acquisition inadmissible; speed is never worth losing evidentiary integrity.
- ✓
Use a write blocker when connecting the source drive
Why this is correct
A write blocker is essential when connecting a source drive to a forensic workstation because it intentionally prevents the OS from sending any write commands to the drive. This ensures that mounting the filesystem, reading metadata, or even the act of attaching the device cannot alter the source. Forensically sound acquisition always requires hardware-level write blocking to guarantee that the evidence remains in its original state.
- ✗
Power on the system and run a full antivirus scan before imaging
Why it's wrong here
Powering on the system to run a full antivirus scan is not forensically sound because the boot process itself changes the system state: it writes to logs, updates atime (access time) on files, mounts filesystems, and loads drivers that alter volatile memory. Antivirus scans may also create quarantine files, update history logs, or modify registry keys, all of which modify evidence. Dead acquisition—imaging without booting the original system—is the correct approach.
- ✗
Reboot the system to clear any temporary files
Why it's wrong here
Rebooting the system to clear temporary files destroys volatile data (e.g., RAM contents, network connections) that may be crucial evidence, and the shutdown/startup sequence triggers writes to disks—including pagefile changes, prefetch updates, and registry hive modifications. This violates the order of volatility, which requires capturing the most volatile data first (memory, processes) before any power cycling. A forensic examiner should either perform live memory acquisition or power down cleanly and use a write-blocked imaging workflow, never reboot.
Go deeper
Related to this question
Learn chapter
Mobile Device Forensics and MDM Evidence
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.