CS0-003 Incident Response and Management Practice Question
During a forensic investigation, an analyst must acquire digital evidence while maintaining forensic soundness. Which THREE practices should the analyst follow? (Choose three.)
⚠ Common exam trap
CompTIA often tests the misconception that capturing volatile data by powering on the system is always good practice — candidates must recognise that in dead-box acquisition, powering on destroys forensic soundness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify the hash of the image against the original
Option C is correct because hashing the acquired image (e.g., with MD5 or SHA-256) and comparing it to the hash of the original source proves the copy is a bit-for-bit duplicate and has not been altered, which is essential to forensic soundness and admissibility. Option D is correct because a hardware or software write blocker prevents any write operations from reaching the suspect drive during imaging, preserving the integrity of the original evidence. Option E is correct because maintaining a detailed chain of custody and documenting every action (tools, timestamps, hashes, personnel) ensures the acquisition is reproducible, defensible, and legally admissible. Option A is not appropriate because using the suspect's operating system can modify file metadata (MAC times) and alter the evidence, violating forensic soundness. Option B is not appropriate as a general acquisition practice because powering on the system can change volatile and non-volatile data; volatile data should only be captured under a documented, justified order of volatility when necessary, not as a blanket first step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the suspect's operating system to copy files
Why it's wrong here
Using the suspect's operating system to copy files is forensically unsound because the OS may update file access timestamps and other metadata while reading, and it does not preserve deleted files, slack space, or unallocated clusters. This approach also risks triggering malicious software or anti-forensics mechanisms on the suspect system. Proper acquisition requires booting from a trusted forensic environment and using a hardware write blocker to ensure the original data remains undisturbed.
- ✗
Power on the system to capture volatile data first
Why it's wrong here
Powering on a system to capture volatile data is flawed because the boot process itself changes the system state—writing to swap files, logs, and modifying metadata—and any volatile data (e.g., RAM, running processes, network connections) that existed before power-on is lost. Volatile data must be collected from a system that is already running, before it is shut down, using a live forensic toolkit. If the system is off, powering it on may degrade evidence; instead, you should preserve the drive for non-volatile acquisition and document that volatile data was already lost.
- ✓
Verify the hash of the image against the original
Why this is correct
Verifying the hash of the acquired image against the original evidence is a critical step because it provides cryptographic proof that the image is an exact bit-for-bit replica. Using algorithms like SHA-256, any change to even a single bit in the image produces a completely different hash, so the match confirms no data was altered during acquisition. This verification is recorded and matched against the hash of the original, establishing the integrity and authenticity of the evidence for the chain of custody and courtroom admissibility.
- ✓
Use a write blocker when imaging the hard drive
Why this is correct
Using a write blocker when imaging the hard drive is essential because it prevents the acquisition workstation from sending any write commands to the suspect drive, guaranteeing that the original evidence remains byte-for-byte unchanged. A hardware write blocker physically intercepts and blocks writes, while a software write blocker does the same at the driver level; both allow read-only access to the source. This safeguards the evidence from accidental modifications, OS artifacts, or malware, ensuring the image is a true and admissible copy of the original.
- ✓
Document every action taken during the acquisition
Why this is correct
Documenting every action taken during the acquisition is essential because it creates a complete, auditable chain of custody that allows another examiner to independently reproduce the process. Detailed notes on the tools used, timestamps, commands issued, and any anomalies observed establish the evidence's integrity and demonstrate that proper forensic protocols were followed. Without this documentation, the opposing counsel can successfully challenge the evidence's reliability, even if the technical acquisition was flawless.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Identity-Based Attack Patterns: Pass-the-Hash, Kerberoasting
Key term
Hashing
Hashing is a one-way mathematical function that converts any input data into a fixed-length string of characters, called a hash or digest, which is used to verify data integrity and store passwords securely.
Key term
Metadata
Metadata is data that describes other data, providing context such as when a file was created, who created it, or its size.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.