CS0-003 Incident Response and Management Practice Question
An analyst is examining a disk image acquired from a compromised Linux server. The analyst needs to verify that the image is an exact bit-for-bit copy of the original drive. Which forensic sound procedure should the analyst perform?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compare the hash of the image to the hash of the original drive.
Hash verification ensures the image matches the original by comparing cryptographic hashes (e.g., MD5, SHA-256) generated during acquisition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Compare the hash of the image to the hash of the original drive.
Why this is correct
To verify the integrity of a forensic acquisition, the analyst must calculate a cryptographic hash (such as MD5, SHA-1, or SHA-256) of both the source media and the destination image. Matching hash values mathematically prove that no data was altered, added, or lost during the imaging process, establishing a verifiable chain of custody.
- ✗
Use a write blocker when acquiring the image.
Why it's wrong here
While hardware or software write blockers are critical during the acquisition phase to prevent the host operating system from writing metadata or files to the evidence drive, they do not perform post-acquisition verification. A write blocker ensures the source remains pristine, but it cannot verify if the resulting image file was corrupted during transfer.
- ✗
Mount the image in read-only mode.
Why it's wrong here
Mounting an acquired image in read-only mode is a standard practice during analysis to prevent accidental modifications to the evidence. However, this action only protects the image from future changes; it does not validate whether the image was captured accurately or matches the original source drive.
- ✗
Analyze the image with a hex editor.
Why it's wrong here
Utilizing a hex editor allows an analyst to inspect raw binary data, file headers, and unallocated space on the disk image. Although useful for deep-dive forensic analysis and carving out hidden files, a hex editor does not provide a mechanism to mathematically verify the overall integrity of the acquired image against the original media.
Go deeper
Related to this question
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.