Courseiva
Security OperationsmediumMultiple ChoiceObjective-mapped

SY0-701 Security Operations Practice Question

A manager asks the security team to let Human Resources inspect the files on a laptop suspected of containing stolen customer data before IT touches it. What is the best response?

⚠ Common exam trap

Many exam-takers think HR needs immediate access to confirm sensitivity, but they overlook the forensic requirement to preserve the original state of the evidence before any access or analysis occurs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a forensic image of the device, document the handoff, and maintain chain of custody before any analysis.

The first priority in any investigation involving potential evidence is to preserve the data in its original state. Creating a forensic image (bit-for-bit copy) ensures that the original media is not altered, and documenting the handoff with a chain of custody form provides a verifiable audit trail. This process adheres to forensic best practices and legal requirements, preventing spoliation of evidence before any analysis begins.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Let HR browse the files first so they can confirm whether the data is sensitive.

    Why it's wrong here

    Allowing HR to browse the device before any forensic preservation is performed risks altering file metadata, such as last-accessed timestamps, and can inadvertently modify or destroy evidence. This unsupervised review also fails to establish a documented chain of custody, making it impossible to prove that the data was not changed or tampered with during the examination. Additionally, HR personnel are not typically trained in forensic handling procedures, so the integrity of the evidence is compromised from the start.

  • Create a forensic image of the device, document the handoff, and maintain chain of custody before any analysis.

    Why this is correct

    When a device may contain evidence, the priority is to preserve it in a way that supports later analysis and legal defensibility. Creating a forensic image captures the data without modifying the original device, and documenting each transfer maintains chain of custody. This approach protects evidence integrity and allows authorized investigators to review the copy instead of the live system. It is the correct response before HR or others inspect the contents.

  • Copy the files to a shared drive so multiple departments can review them quickly.

    Why it's wrong here

    Copying files to a shared drive is not a forensically sound acquisition method because it does not capture the entire device image, including deleted files, unallocated space, and file system metadata. This casual copying also changes file hashes and timestamps, and it leaves extra copies of sensitive data on a network share, expanding the attack surface and making it harder to control access. Critically, the process lacks a documented chain of custody, as there is no verifiable record of who accessed, copied, or placed the files onto the share.

  • Factory reset the laptop immediately to prevent further leakage of customer data.

    Why it's wrong here

    A factory reset permanently destroys all data on the device, including the very evidence needed to determine the scope of the leak and identify the responsible party. This action violates the fundamental forensic principle of preserving the original evidence before any remediation, and it could make the organization legally liable for spoliation in subsequent litigation. While containing the leak is important, the correct approach would be to disconnect the device from the network and create a forensic image before considering any cleanup or restoration.

About these practice questions

Courseiva writes every SY0-701 question from scratch — 1,013 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.