Courseiva
Security OperationsmediumMultiple SelectObjective-mapped

SY0-701 Security Operations Practice Question

A company-owned laptop is being transferred from the incident site to the evidence locker for a theft investigation. Which two actions best support chain of custody during transport? Select two.

⚠ Common exam trap

Test-takers frequently think booting the laptop is necessary to verify data presence, but this action actually violates forensic preservation principles by altering the system state and potentially destroying evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Place the device in a tamper-evident evidence bag or seal

Placing the device in a tamper-evident evidence bag or seal provides a physical barrier that immediately reveals any unauthorized access during transport. This is a foundational chain-of-custody control that preserves the integrity of the evidence by making tampering detectable, which is critical for admissibility in legal proceedings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Place the device in a tamper-evident evidence bag or seal

    Why this is correct

    Place the device in a tamper-evident evidence bag or seal. A tamper-evident seal or bag provides a physical barrier that visibly records any unauthorized opening, and the seal's unique serial number allows the package to be tracked. Sealing the laptop prevents accidental changes to data and preserves the device's state for forensic examination, which is essential for maintaining the evidence's integrity from the scene to the lab. Without such a seal, there is an unbroken opportunity for undetected tampering, undermining the legal admissibility of the evidence.

  • Document the device serial number, date, time, collector, and each handoff

    Why this is correct

    Document the device serial number, date, time, collector, and each handoff. This creates a formal chain-of-custody record that tracks who had control of the laptop at every stage, from initial collection to final storage. A complete log ensures that every transfer, analysis, or movement is fully auditable, preventing disputes about whether the evidence was altered or accessed. Incomplete or illegal custody documentation can break the chain, causing the evidence to be ruled inadmissible in court.

  • Leave the device unsealed so legal staff can inspect it quickly

    Why it's wrong here

    Leaving the device unsealed breaks the chain of custody because it creates an unbroken opportunity for undetected tampering or data alteration between the incident site and the evidence locker, which the correct action—sealing the device in a tamper-evident bag—prevents by providing a physical integrity check at handover. This option is tempting because in a non-investigative context, such as a routine hardware refresh, unsealed access allows legal staff to perform a quick inspection for data classification without delaying asset disposal.

  • Boot the laptop to confirm the user’s files are still present

    Why it's wrong here

    Booting the laptop to confirm the user's files are still present. Booting the laptop makes system changes, including updating file access times, writing temporary files, and possibly loading full-disk encryption keys into memory, which alters the original evidentiary data. Even a 'quick check' can destroy critical metadata needed for the investigation and contaminate volatile data. The correct method is to create a bit-for-bit forensic image of the storage device and perform all verification on the image copy, leaving the original untouched.

  • Use a personal note app instead of formal transfer documentation

    Why it's wrong here

    Use a personal note app instead of formal transfer documentation. Personal notes lack the integrity and authenticity of formal chain-of-custody records, are easily edited or deleted, and provide no tamper-evident mechanism to prove that the device's history is complete. A defensible evidence-handling process requires a standardized, chronological, and independently verifiable log, which a note app cannot deliver. This deficiency can be exploited in court to question the evidence's authenticity and admissibility.

About these practice questions

This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.