CS0-003 Incident Response and Management Practice Question
A security analyst is performing memory acquisition on a compromised Linux server using LiME. The analyst needs to capture the memory image with minimal impact on the system. Which of the following parameters should the analyst use to ensure the output is forensically sound?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the output path is on a write-blocked device
Using a write blocker ensures the memory capture does not alter the storage media, preserving forensic integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the --digest option to calculate a SHA256 hash during acquisition
Why it's wrong here
Calculating a hash during acquisition is a useful step for verification, but it does not inherently protect the destination media from accidental modification or corruption. Forensic integrity relies first and foremost on ensuring the target storage medium is physically or logically write-blocked to prevent any alteration of the captured data.
- ✗
Specify a format that compresses the output to reduce size
Why it's wrong here
Compressing the memory dump file can save storage space and speed up transfer times, but it is not a fundamental requirement for maintaining forensic soundness. In fact, some forensic tools or analysis suites may struggle to parse compressed raw memory formats directly, potentially complicating the subsequent investigation.
- ✓
Ensure the output path is on a write-blocked device
Why this is correct
Directing the acquired memory image to a write-blocked destination device is a critical forensic practice that prevents accidental overwriting, modification, or contamination of the evidence. This ensures that the captured volatile data remains in an untampered state from the exact moment of acquisition through the entire chain of custody.
- ✗
Use the --reload option to reload the original kernel module after acquisition
Why it's wrong here
Attempting to reload kernel modules post-acquisition is unnecessary for preserving the integrity of the captured memory image and introduces a high risk of system instability or kernel panics. In a live forensic scenario, minimizing changes to the host's running state is paramount, and reloading modules unnecessarily alters the system's volatile footprint.
Go deeper
Related to this question
Learn chapter
Infrastructure-as-Code Security Scanning
Key term
Memory capture
Memory capture is the process of preserving the contents of a computer's volatile memory (RAM) for forensic analysis during incident response.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.